Source: RepoLens Security-Audit 2026-08-16 (findings security/data-exposure/004–011, input-sanitization/003, cryptography/005, adversarial-verified ✅)
- Published personal/infra identifiers in skill metadata and references: Telegram chat + supergroup IDs, Hermes host/network audit content, home-network/Wi-Fi fingerprint, owner + cloud resource identifiers
input-san/003 start-server.sh --project-dir concatenated into SESSION_DIR without canonicalization (.. traversal)
data-exposure/012 hardcoded dashboard session tokens in docs (my-static-token, test-token-hermes-mobile-2026)
cryptography/005 MD5 for non-security IDs (fine, but document the intent)
- LOW: raw exception text in 500s, full tracebacks in PDF scripts, Harbor default password echo
Suggested fix: scrub identifiers from docs, realpath the project-dir, replace placeholder tokens with <your-token> style, central exception handler.
Source: RepoLens Security-Audit 2026-08-16 (findings
security/data-exposure/004–011,input-sanitization/003,cryptography/005, adversarial-verified ✅)input-san/003start-server.sh --project-dirconcatenated intoSESSION_DIRwithout canonicalization (..traversal)data-exposure/012hardcoded dashboard session tokens in docs (my-static-token,test-token-hermes-mobile-2026)cryptography/005MD5 for non-security IDs (fine, but document the intent)Suggested fix: scrub identifiers from docs,
realpaththe project-dir, replace placeholder tokens with<your-token>style, central exception handler.