About this project

Cybermes is an offensive security assistant and automation framework designed for authorized bug bounty hunting, reconnaissance, vulnerability research, and structured reporting. It provides two operational workflows: an autonomous Hermes CLI mode for terminal or headless execution, and a Model Context Protocol (MCP) server mode that exposes security tools to AI coding environments such as Cursor, Claude Desktop, Windsurf, and VS Code/Cline. The project combines native Go utilities with Python tooling. Core Go binaries include smart_pipe for stream filtering and token optimization, secret_scan for credential leak detection, search_knowledge for offline exploit and payload lookup, aggregate_reports for findings compilation, and cybermes-mcp as the MCP server. The framework integrates external reconnaissance and testing tools including subfinder, httpx, katana, ffuf, nuclei, and sqlmap. Cybermes includes over 200 offensive security playbooks covering API security issues such as IDOR/BOLA, JWT, and BPLA, web vulnerabilities like SSRF, XSS, SQLi, and race conditions, and cloud misconfigurations. It enforces a deterministic proof-of-concept validation gate requiring standalone Python scripts and raw HTTP evidence before findings are logged. Each target assessment creates isolated workspace directories under reports/ and recon/. Deliverables include SUMMARY.md, metadata.json, an interactive HTML report, a print-ready PDF, confirmed vulnerability writeups, PoC scripts, and raw evidence. The framework supports Windows, Linux, macOS, and Docker, with setup scripts, a Docker Compose configuration, and a doctor.py health check and repair utility. The project is licensed under Apache 2.0 and is intended exclusively for authorized security testing, legitimate bug bounty research, and academic security education.