Scan identity
Evidence summary
No MCP configuration evidence was observed in the selected bounded scan. Observed evidence classes: Shell / command execution, Download / install, Agent permissions / behavior, CI/CD automation, Supply-chain / dependencies. Evidence observations are review signals, not a safe/unsafe verdict.
Evidence categories
Shell / command execution
FoundSelected evidence was observed. This does not prove a vulnerability, malicious behavior or unsafe operation.
README.mdpowershellsetup-hermes.shsudoscripts/check-windows-footguns.pypowershell
Download / install
FoundSelected evidence was observed. This does not prove a vulnerability, malicious behavior or unsafe operation.
README.mdcurl, pip install, dockersetup-hermes.shinstall/setup script · curl, pip installpackage.jsonnpm install · install lifecycle: postinstallpyproject.tomlcurl, pip install, docker
MCP configuration
Not found in scanned scopeNo matching evidence was observed in the selected bounded scan scope. This is not proof of absence elsewhere.
Agent permissions / behavior
FoundSelected evidence was observed. This does not prove a vulnerability, malicious behavior or unsafe operation.
AGENTS.mdagent instruction/config file · tools / permissions, hooks, agent instructions, model configscripts/aa_quality_sync.pymodel configscripts/build_model_catalog.pyagent instructions, model configscripts/build_skills_index.pytools / permissionsscripts/check-windows-footguns.pytools / permissions, agent instructionsscripts/check_profile_scope_patterns.pytools / permissions, agent instructions
CI/CD automation
FoundSelected evidence was observed. This does not prove a vulnerability, malicious behavior or unsafe operation.
.github/workflows35 direct workflow files
Supply-chain / dependencies
FoundSelected evidence was observed. This does not prove a vulnerability, malicious behavior or unsafe operation.
package-lock.jsondependency manifest observed · too large to readpackage.jsonparsed package manifest · 6 declared dependency entriespyproject.tomlparsed pyproject manifest · 7 selected dependency entries
Scope and limitations
Scan mode: BOUNDED_ROOT_AND_SELECTED_DEPTH1. General recursive crawl: NO.
- Public, selected and bounded repository evidence only.
- FOUND means evidence observed, not risk or malicious behavior proven.
- NOT_FOUND_IN_SCANNED_SCOPE is not proof of absence outside the bounded scan.
- Trust/community metadata is descriptive context, not a security guarantee.
- Zero selected dependency evidence does not mean zero dependencies.
- No repository clone or target-code execution.
- No raw source-file bodies or secret/token values are included in this report.
- No general recursive crawl.
- No CVE lookup, package reputation lookup or package registry lookup.
- No numeric security score and no safe/unsafe verdict.
Repository context
Trust/community metadata is descriptive context only; it is not a security guarantee.