⏳ This skill is pending AI review.
Scores will appear once the review pipeline completes.
recat-findings
Use when bug hunting, reviewing web, smart contract, or other security vulnerabilities, preparing PoC reports, or saving and updating findings for Recat. Applies to authorized security findings and their reporting artifacts.
Choose how to use this skill
You do not need every option. Choose the path your AI client supports. The stable page stays the same; versioned files are immutable.
1. Native installer
This listing has no registered native installer command. Use the complete package or source fallback below, depending on what your client supports.
Do not guess an installer command or replace an existing version without reviewing the diff.
2. Complete package recommended
Download the ZIP when available. It includes SKILL.md plus the references, security notes and version metadata.
No complete ProSkills package is published for this listing yet.3. Prompt-only
Copy the prompt above when the agent can read the stable page or when you want to adopt the workflow without installing a skill.
Need only the instruction file?
Download SKILL.md only if your client requires a single file. The complete ZIP is safer for a full installation because it preserves the references and release context.
No path installs or executes anything by itself. Your agent still needs access to the project files. Before updating, compare the installed version and review the diff.
// RATINGS
// README
Review findings from Hermes or other agents, inspect evidence, and export reports. Recat supports Web, Smart contract, and Other assets, including mobile, desktop, networks, and hardware.
Features
- Dashboard with severity, status, activity, and asset coverage.
- Search and filters by project, category, vulnerability class, and status.
- Evidence viewer, JSON exports, and project ZIP downloads.
- Password access, censored view, and a reporting skill for Codex, Claude Code, and Hermes.
Installation
With an AI agent
Copy and paste this into Codex, Claude Code, or Hermes:
Install and run Recat from https://github.com/0xtbug/Recat.
Reuse an existing Recat checkout, or clone the repository into an unused folder.
Read the root SKILL.md and follow its automatic setup workflow.
Install missing prerequisites and dependencies, generate a local password if
none is configured, and prepare the findings folder. Preserve existing data
and settings. Run tests, build, start the local server, and verify it responds.
Give me the URL, install directory, password file path, and restart instructions.
The web setup skill also works when its full contents are pasted directly into an agent with terminal access.
Manual
Requires Bun. Run commands from the directory containing package.json (frontend/ in this workspace).
Create .env from .env.example and set RECAT_PASSWORD. Keep an existing configuration. The password is server-only; do not use a VITE_ prefix.
bun install
bun run dev
Open the local URL printed by Vite, normally http://127.0.0.1:5173.
For production:
bun run build
bun run start
The production server binds to 127.0.0.1:5173; PORT overrides the port. Recat requires a running server with access to the findings folder.
Findings
Choose the source folder in Settings. The default is ../finding/source, relative to the web repository. Recat reads project folders every five seconds.
finding/source/
project-name/bug/finding-name/
finding.json
README.md
poc/
| Field | Values |
|---|---|
asset_type | web, smart_contract, other |
status | candidate, confirmed, false_positive |
severity | critical, high, medium, low, info |
Recat displays reported results and preserves the original records. See the findings reference for JSON examples, evidence paths, and import rules.
Agent setup
- Set the source folder in Recat Settings.
- Open Agent integration → Download SKILL.md, or use skills/SKILL.md and set its Active source folder to the same absolute path.
- Install that single file at one of these locations:
| Agent | Project | Personal |
|---|---|---|
| Codex | .agents/skills/recat-findings/SKILL.md | ~/.agents/skills/recat-findings/SKILL.md |
| Claude Code | .claude/skills/recat-findings/SKILL.md | ~/.claude/skills/recat-findings/SKILL.md |
| Hermes | Configured skills directory | ~/.hermes/skills/recat-findings/SKILL.md |
Project paths belong to the agent workspace. Hermes uses its configured home. Installation details: Codex, Claude Code, Hermes.
- Start a new session and invoke
$recat-findingsin Codex or/recat-findingsin Claude Code or Hermes.
The agent writes to the source folder directly. It needs filesystem access, or shared storage when running on another machine. No Recat password is needed to publish files.
For example, install the downloaded file in Codex with PowerShell (adjust the download path if needed):
New-Item -ItemType Directory -Force "$HOME/.agents/skills/recat-findings"
Copy-Item "$HOME/Downloads/SKILL.md" "$HOME/.agents/skills/recat-findings/SKILL.md"
Use the Claude Code or Hermes destination above for those agents. Keep any existing customized skill before replacing it. Then ask the agent: “Use recat-findings to save this finding to Recat's configured source folder.”
Development
| File | Purpose |
|---|---|
| SKILL.md | Website installation and development workflow |
| AGENT.md | Code index and shared developer instructions |
| AGENTS.md / CLAUDE.md | Entry points for coding agents |
| skills/SKILL.md | Single-file findings integration |
bun test
bun run lint
bun run build
The server password is stored in RECAT_PASSWORD; source settings are saved in ../.recat/settings.json.
License
// HOW IT'S BUILT
KEY FILES