CanopiiCanopiiAll serversEnterprise →
io.github.hermoso-ai/hermoso

io.github.hermoso-ai/hermoso v0.1.142

Security Trust Score
Grade F · Serious issues
Tier 1 · Public sourceHigh confidence · 99%
Declared MCP capabilities
ResourcesPrompts

This server scored F. Run it behind runtime policy enforcement so one bad tool call can't become an incident.

3 issues capping this score
  • highTool descriptions free of injection markers2 marker(s) across 2 tool(s)
  • highNo risky post-publish tool changes (rug-pull)2 risky tool-definition change(s) in version history (0.1.15 → 0.1.25)
  • mediumNo over-broad / destructive tools13 over-broad tool(s)
Reputation0stars1forks6.0kdownloads/mo2open issues8d agolast commit<1yage

Security controls

Deterministic, evidence-backed. Score earned from passing controls; a failed guard caps it.

Model–MCP Runtime Guardrails

  • Fail
    Indirect Prompt Injection (IPI) Defensesguard2 marker(s) across 2 tool(s)

    Tool/prompt/resource text is free of hidden instructions that could hijack the agent. How many servers fail this?

    update_pinterest_board — pre-action injectionmoderate_youtube_comment — conceal-from-user directive

    Fix: Remove hidden directives, HTML/comment instructions, and override phrasing from descriptions.

  • Fail
    Tool Definition Integrityguard2 risky tool-definition change(s) in version history (0.1.15 → 0.1.25)

    Every consecutive version pair is diffed for new injection markers or destructive scope — a risky diff anywhere in history is a rug-pull (fail, durable); benign description drift warns. How many servers fail this?

    post_to_metamake_template_ad

    Fix: Never add hidden directives or destructive scope to an already-published tool; document description changes in release notes.

  • Fail
    User-in-the-Loop / Approval Scopeguard13 over-broad tool(s)

    No over-broad or destructive tools (arbitrary shell, bulk-delete) that warrant human approval. How many servers fail this?

    create_branddelete_brandpost_to_metapost_to_pinterest

    Fix: Scope tools narrowly; avoid arbitrary command execution and destructive defaults.

  • Warn
    Strict JSON Schema Enforcementschemas not strict

    Tool inputs are constrained (additionalProperties:false), so unexpected arguments can't be smuggled in.

    Fix: Set additionalProperties:false and require explicit parameters on every tool.

Application Security Checks

  • Warn
    No path traversalguard5 occurrences

    Naive path checks let tools read/write outside intended directories (EscapeRoute-class).

    bin/hermoso.mjs:45bin/hermoso.mjs:48bin/hermoso.mjs:98mcp/http.mjs:174

    Fix: Resolve to a canonical path and verify containment; reject ../ and symlinks.

  • Warn
    No SSRF sinksguard10 occurrences

    Fetching tool-supplied URLs can pivot into internal networks and metadata services.

    bin/hermoso.mjs:172mcp/client.mjs:81mcp/client.mjs:102mcp/client.mjs:107

    Fix: Allow-list destinations; reject arbitrary/loopback/link-local URLs.

  • Warn
    Dependencies pinned (lockfile)no lockfile found

    A lockfile makes installs reproducible and resistant to silent dependency swaps.

    Fix: Commit a lockfile (package-lock.json / pnpm-lock.yaml / poetry.lock).

  • Warn
    Published with provenanceno provenance attestation

    Build provenance attests the artifact was built from the claimed source by CI.

    Fix: Publish with npm provenance (--provenance) from a trusted CI.

  • Warn
    Established maintainersingle maintainer

    Brand-new / single anonymous maintainers raise takeover and malware risk.

    Fix: Publish under an established account/org; add multiple maintainers.

  • Warn
    Has a security policyno security policy

    A SECURITY.md gives a private path to report vulnerabilities.

    Fix: Add SECURITY.md with a disclosure contact and process.

  • Pass
    No command-injection sinksguardno sinks found

    Untrusted tool input reaching a shell yields remote code execution.

  • Pass
    No dynamic code executionguardno sinks found

    eval()/exec()/Function() on tool-derived strings allows arbitrary code execution.

  • Pass
    No unsafe deserializationguardno sinks found

    pickle/yaml.load/etc. on untrusted data can execute code.

  • Pass
    No committed secretsguardno secrets found

    Hardcoded keys/tokens in published source are live credentials an attacker can use.

  • Pass
    Credentials sourced from environmentreads credentials from environment

    Reading secrets from env/secret stores avoids hardcoding them.

  • Pass
    No known-vulnerable dependencies1 runtime deps, no known CVEs

    Runtime dependencies (parsed from the lockfile) are scanned against OSV.dev for published CVEs. Advisory: flagged dependencies lower the score but don't hard-cap it, since transitive reachability is unproven.

  • Pass
    No install/post-install scriptsguardno install scripts

    install hooks run arbitrary code on every consumer at install time.

  • Pass
    Package name not typosquattingguarddistinct package name

    Names mimicking popular packages are a common malware delivery vector.

  • Pass
    Actively maintainedrecent commits

    Unmaintained servers don't receive security fixes.

  • Pass
    Repository not archivedguardactive

    Archived repositories will never be patched.

  • Pass
    Declares a licenseMIT

    A clear license is required for legal enterprise use.

  • Pass
    Adoption & popularityestablished adoption

    A small, capped nudge from stars/downloads — widely-used servers get more eyes on bugs. It can never offset a real security failure.

  • Not checked
    Signed releasesnot evaluated

    Signed releases let consumers verify artifacts weren't tampered with.

Transport & Trust Model

  • Warn
    Execution Sandboxingruns natively (no container image)

    A container/sandbox image limits blast radius; a server that runs natively has full host access.

    Fix: Ship a Dockerfile/Containerfile (or document a sandboxed run) so the server runs isolated.

  • Pass
    Transport Encryption (TLS)guardall remotes use HTTPS

    Plaintext HTTP exposes traffic and bearer tokens to interception.

  • Pass
    IAM / Authentication ScopingOAuth / PRM handling detected

    OAuth 2.1 / Protected Resource Metadata gates who can invoke tools.

  • Pass
    Network Exposureno bind-all detected

    Binding 0.0.0.0 or exposing debug inspectors widens the attack surface.

  • N/A
    Live Endpoint Reachablenot dynamically scanned

    A dynamic scan connected to the declared remote endpoint and it responded — verified live, not a dead URL.

  • N/A
    Authentication Enforced (live)not dynamically scanned

    If the server declares auth is required, it must actually reject anonymous clients. Serving tools to unauthenticated callers is a real exposure.

Tools (269)

forgetget_jobplan_adfix_beatread_docrememberscore_adset_roledub_videoget_brandget_skilllist_jobslist_teampost_editpost_to_xrender_adstore_getuse_brandclip_videocreate_docedit_videolist_hookslist_inboxread_sheetreport_bugsave_skillupdate_docx_mentionsbuy_creditsdraft_brandfetch_assetlist_brandslist_errorslist_memorylist_skillsmine_anglesupload_filechange_voicecreate_brandcreate_sheetdelete_branddelete_skillenable_toolserror_detailfinish_videoformat_sheetget_settingslist_librarypost_to_metaremix_staticresearch_adssave_creatorstitch_videoupdate_brandupdate_sheetupgrade_plananalyze_videoappend_to_docdelete_threaddelete_x_postgenerate_textinvite_memberlist_creatorsrecast_motionreframe_videoremove_memberrepost_threadsave_playbooksave_to_driveschedule_postsearch_redditsearch_tiktokupscale_videobackfill_postsbilling_statusdelete_creatordiagnose_postsgenerate_imagegenerate_videogenerate_voiceget_drive_filelist_playbookslist_scheduledlist_swipefilemake_explainermake_thumbnailpost_to_redditpost_to_tiktokproduct_sizzlesearch_threadssearch_youtubetiktok_accountx_post_metricsappend_to_sheetcheck_ad_policydelete_playbookgenerate_avatarget_post_refillhermoso_creditsleave_connectorlist_connectorslist_meta_pageslist_meta_postslist_sheet_tabsplan_variationspost_to_blueskypost_to_youtuberead_bluesky_dmreply_to_threadrequest_featurereschedule_postretry_scheduledrun_post_refillsearch_meta_adssend_bluesky_dmset_auto_reloadset_post_refillupdate_settingsx_post_insightsyoutube_channelcancel_schedulededit_reddit_postfind_competitorslist_drive_filesmake_template_admanage_meta_postpost_performancepost_to_linkedinpost_to_telegramsave_to_onedrivesearch_instagramthreads_insightsclear_sheet_rangedelete_drive_filefetch_app_screensget_onedrive_filehide_thread_replylist_reddit_postsmanage_sheet_tabspost_to_pinterestreddit_post_statssave_to_swipefilesearch_google_adsset_product_imageupdate_drive_filedelete_reddit_postget_tiktok_mentioninstagram_insightslist_bluesky_postslist_meta_commentslist_threads_postslist_tiktok_videosmeta_page_insightsmeta_post_insightssave_pinterest_pincompetitor_teardowncreate_drive_folderdelete_bluesky_postduplicate_scheduledlist_bluesky_convoslist_linkedin_pageslist_onedrive_fileslist_pinterest_pinslist_product_photoslist_telegram_chatslist_watch_findingslist_youtube_videospinterest_analyticspull_competitor_adsreply_to_inbox_itemsearch_linkedin_adstiktok_creator_infoyoutube_bulk_reportbluesky_post_metricscollect_post_metricsdelete_onedrive_filedelete_pinterest_pindelete_youtube_videodisconnect_connectorhermoso_capabilitieslist_instagram_medialist_published_postslist_reddit_commentslist_threads_replieslist_tiktok_commentslist_tiktok_mentionsmanage_linkedin_postscrapecreators_fetchset_competitor_watchupdate_onedrive_fileupdate_pinterest_pinupdate_youtube_videoconvert_onedrive_fileexport_swipefile_deckget_business_locationlist_pinterest_boardslist_shopify_productslist_threads_mentionslist_youtube_captionslist_youtube_commentsmoderate_meta_commentpost_to_linkedin_pagereply_to_meta_commentset_youtube_thumbnailset_youtube_watermarktiktok_account_statuscreate_onedrive_foldercreate_pinterest_boarddelete_pinterest_boardlist_youtube_playlistsmanage_youtube_captionsearch_threads_keywordset_connector_accountsupdate_pinterest_boardupdate_youtube_channelyoutube_channel_reportyoutube_video_insightscomment_on_tiktok_videodelete_telegram_messagegoogle_business_accountinstagram_collaboratorslinkedin_page_analyticslist_business_locationslist_connector_accountslist_youtube_categoriesmanage_youtube_playlistmark_bluesky_convo_readmoderate_tiktok_commentpost_to_google_businessreply_to_reddit_commentreply_to_tiktok_commenttiktok_account_insightsgoogle_business_insightslist_youtube_report_jobslist_youtube_video_statsmoderate_youtube_commentreply_to_youtube_commentsearch_threads_locationsthreads_publishing_limittiktok_mention_top_termsupdate_business_locationdelete_youtube_report_jobtiktok_category_benchmarklist_google_business_postslist_tiktok_brand_hashtagspinterest_ads_async_reportpublish_to_shopify_productx_post_insights_historicaldelete_google_business_postlist_tiktok_comment_repliespinterest_audience_insightsupload_tiktok_comment_imagelist_google_business_reviewslist_tiktok_mention_commentsmanage_tiktok_brand_hashtagsmanage_youtube_playlist_imagemanage_youtube_playlist_itemspinterest_targeting_analyticslist_google_business_questionsmanage_youtube_channel_sectionsearch_pinterest_ads_targetinganswer_google_business_questiongoogle_business_search_keywordslist_tiktok_brand_hashtag_postsreply_to_google_business_reviewget_tiktok_post_ad_authorizationset_tiktok_post_ad_authorizationdelete_tiktok_post_ad_authorizationextend_tiktok_post_ad_authorization

AI-flagged — for review

Observations from an AI review of tool descriptions. These are advisory only and do not affect the score — they can be noisy and need human judgement.

  • info
    Tool "hermoso_capabilities" description changed after publish

    Benign definition drift: the description changed vs the prior version with no risk signals in the diff. Clients approve tools by name and don't re-review on update, so the change is invisible to existing grants.

  • info
    Tool "manage_meta_post" description changed after publish

    Benign definition drift: the description changed vs the prior version with no risk signals in the diff. Clients approve tools by name and don't re-review on update, so the change is invisible to existing grants.

  • info
    Tool "get_job" description changed after publish

    Benign definition drift: the description changed vs the prior version with no risk signals in the diff. Clients approve tools by name and don't re-review on update, so the change is invisible to existing grants.

Show 1 more