Cybermes
Zyrexnn/Cybermes
Security assistant framework for authorized bug bounty work, with an MCP server and Hermes Agent support
Cybermes is a security assistant and automation framework for authorized bug bounty hunting, reconnaissance, vulnerability research and structured reporting. The repository description says it is powered by Hermes Agent, and it ships an MCP server that installs into Hermes among other AI clients.
What Cybermes does
Cybermes combines native Go utilities, 200+ modular playbooks, token-optimized streaming pipelines and Model Context Protocol support. You can use it through an AI assistant over MCP, or run it as a standalone CLI or pipeline, including in headless CI/CD. The README frames it as a tool for authorized work and structured reporting.
The cybermes-mcp server is written in Go and exposes 10+ tools and context providers to clients such as Cursor, Claude Desktop, Claude Code, Hermes and Codex, with an auto-installer that detects the clients you have. The standalone path offers setup scripts for Windows, Linux and macOS and a Docker Compose option, plus a doctor script that checks dependencies. Settings and API keys go in a .env file. A mock application in the examples folder is provided for local testing.
Key features
- Native Go MCP server, cybermes-mcp, exposing 10+ tools and context providers
- One-command installer that detects installed AI clients, including Hermes
- Standalone CLI and pipeline for terminal or CI/CD use
- Docker Compose deployment option
- Environment health check with a doctor script that can repair missing components
- Mock application in examples/ for local testing
When to use it
- Adding structured security-assessment tooling to Hermes Agent over MCP for authorized bug bounty work
- Running a standalone assessment pipeline from a terminal or CI job against targets you are authorized to test
- Verifying an installation's dependencies with the doctor script
Who it is for: Security researchers and bug bounty hunters who work on authorized targets and use AI assistants.
How it fits with Hermes Agent
Described as powered by Hermes Agent, and its MCP server installs into Hermes among many other AI clients. It can also run standalone.
How to install Cybermes
These commands are copied from the project's README. Check the repository for the latest steps before you run them.
npx -y cybermes-mcp install
npm install -g cybermes-mcp
cybermes-mcp install --globalRequirements: Node.js for the npx and npm install; API keys set in a .env file for standalone use; Docker is optional
Note: The README states Cybermes is designed for authorized bug bounty hunting and security testing.
FAQ
What is Cybermes?
Cybermes is a security assistant and automation framework designed for authorized bug bounty hunting, reconnaissance, vulnerability research and structured reporting. It can run over MCP inside an AI assistant or as a standalone CLI.
Does Cybermes work with Hermes Agent?
Yes, the repository description says it is powered by Hermes Agent, and Hermes is among the AI clients the cybermes-mcp installer configures. It also supports clients such as Cursor, Claude Desktop and Codex.
How do I install Cybermes?
Run npx -y cybermes-mcp install to auto-detect and configure your AI clients, or npm install -g cybermes-mcp followed by cybermes-mcp install --global. A standalone CLI install uses setup.sh on Linux and macOS or setup_windows.ps1 on Windows.
Similar security for Hermes Agent
All securityHTTP credential proxy and vault that keeps real API keys away from AI agents such as Hermes
kenryu42 CC Safety NetGuard that blocks destructive Git and file commands and secret access before a coding agent runs them
prompt-security ClawSecSecurity skill suite with signed advisories and drift detection for OpenClaw, Hermes and related agents
SafeAI-Lab-X ClawKeeperHost-agnostic safety middleware that blocks risky agent tool calls and redacts sensitive tool results
EXboys EvotownSelf-hosted control plane for governing OpenClaw, Hermes and SkillLite agents across a company
vivekchand ClawMetryLocal dashboard that reads agent session files to show timelines, tool calls and token costs
Related guides: How to run Hermes Agent securely