generated: '2026-08-09' method: searched probe: true source: https://github.com/dcn13l/hermes-autonomia note: >- There is no security.txt and no security page on either host — the mechanical probe found nothing (`vdp=none`). The disclosure channel LinkPeek actually publishes lives in the source repository: a private-reporting route via GitHub Security Advisories, wired into the repo's issue-template config so it is surfaced to anyone opening an issue, plus a public security-report template for non-critical findings. That is a real, documented, publicly-reachable vulnerability-reporting path, so it is recorded here. policy: - https://github.com/dcn13l/hermes-autonomia/security/advisories/new contact: - https://github.com/dcn13l/hermes-autonomia/security/advisories/new - https://github.com/dcn13l/hermes-autonomia/issues/new?template=security_report.yml bug_bounty: program: null paid: false note: 'No HackerOne, Bugcrowd or Intigriti program; no bounty offered.' security_txt: false disclosure_guidance: >- The repository instructs reporters that critical, actively exploitable vulnerabilities should be filed privately through GitHub Security Advisories so fixes can ship before disclosure, and that reports must not include live secrets, API keys or credentials. Non-critical hardening findings go to the public security issue template, which asks for a severity estimate and a category (SSRF, auth/authorization bypass, rate-limit bypass, injection, information disclosure, dependency vulnerability). evidence: - source: https://github.com/dcn13l/hermes-autonomia/blob/main/.github/ISSUE_TEMPLATE/config.yml kind: issue-template-config http_status: 200 detail: 'contact_links entry "Report a Security Vulnerability" → GitHub Security Advisories' - source: https://github.com/dcn13l/hermes-autonomia/blob/main/.github/ISSUE_TEMPLATE/security_report.yml kind: security-issue-template http_status: 200 detail: 'Public security report form with severity and category taxonomy and private-disclosure guidance' - source: https://147.15.103.217.sslip.io/.well-known/security.txt kind: security.txt http_status: 404 - source: https://linkpeek.com/.well-known/security.txt kind: security.txt http_status: 404 gaps: - No RFC 9116 /.well-known/security.txt on either host. - No SECURITY.md at the repository root. - No stated response-time or safe-harbour commitment.