A local workspace for security findings.
Review findings from Hermes or other agents, inspect evidence, and export reports. Recat supports Web, Smart contract, and Other assets, including mobile, desktop, networks, and hardware.
- Dashboard with severity, status, activity, and asset coverage.
- Search and filters by project, category, vulnerability class, and status.
- Evidence viewer, JSON exports, and project ZIP downloads.
- Password access, censored view, and a reporting skill for Codex, Claude Code, and Hermes.
Copy and paste this into Codex, Claude Code, or Hermes:
Install and run Recat from https://github.com/0xtbug/Recat.
Reuse an existing Recat checkout, or clone the repository into an unused folder.
Read the root SKILL.md and follow its automatic setup workflow.
Install missing prerequisites and dependencies, generate a local password if
none is configured, and prepare the findings folder. Preserve existing data
and settings. Run tests, build, start the local server, and verify it responds.
Give me the URL, install directory, password file path, and restart instructions.
The web setup skill also works when its full contents are pasted directly into an agent with terminal access.
Requires Bun. Run commands from the directory containing package.json (frontend/ in this workspace).
Create .env from .env.example and set RECAT_PASSWORD. Keep an existing configuration. The password is server-only; do not use a VITE_ prefix.
bun install
bun run devOpen the local URL printed by Vite, normally http://127.0.0.1:5173.
For production:
bun run build
bun run startThe production server binds to 127.0.0.1:5173; PORT overrides the port. Recat requires a running server with access to the findings folder.
Choose the source folder in Settings. The default is ../finding/source, relative to the web repository. Recat reads project folders every five seconds.
finding/source/
project-name/bug/finding-name/
finding.json
README.md
poc/
| Field | Values |
|---|---|
asset_type |
web, smart_contract, other |
status |
candidate, confirmed, false_positive |
severity |
critical, high, medium, low, info |
Recat displays reported results and preserves the original records. See the findings reference for JSON examples, evidence paths, and import rules.
- Set the source folder in Recat Settings.
- Open Agent integration → Download SKILL.md, or use skills/SKILL.md and set its Active source folder to the same absolute path.
- Install that single file at one of these locations:
| Agent | Project | Personal |
|---|---|---|
| Codex | .agents/skills/recat-findings/SKILL.md |
~/.agents/skills/recat-findings/SKILL.md |
| Claude Code | .claude/skills/recat-findings/SKILL.md |
~/.claude/skills/recat-findings/SKILL.md |
| Hermes | Configured skills directory | ~/.hermes/skills/recat-findings/SKILL.md |
Project paths belong to the agent workspace. Hermes uses its configured home. Installation details: Codex, Claude Code, Hermes.
- Start a new session and invoke
$recat-findingsin Codex or/recat-findingsin Claude Code or Hermes.
The agent writes to the source folder directly. It needs filesystem access, or shared storage when running on another machine. No Recat password is needed to publish files.
For example, install the downloaded file in Codex with PowerShell (adjust the download path if needed):
New-Item -ItemType Directory -Force "$HOME/.agents/skills/recat-findings"
Copy-Item "$HOME/Downloads/SKILL.md" "$HOME/.agents/skills/recat-findings/SKILL.md"Use the Claude Code or Hermes destination above for those agents. Keep any existing customized skill before replacing it. Then ask the agent: “Use recat-findings to save this finding to Recat's configured source folder.”
| File | Purpose |
|---|---|
| SKILL.md | Website installation and development workflow |
| AGENT.md | Code index and shared developer instructions |
| AGENTS.md / CLAUDE.md | Entry points for coding agents |
| skills/SKILL.md | Single-file findings integration |
bun test
bun run lint
bun run buildThe server password is stored in RECAT_PASSWORD; source settings are saved in ../.recat/settings.json.

