Agents-Hefesto
Health Warn
- License — License: MIT
- Description — Repository has a description
- Active repo — Last push 0 days ago
- Low visibility — Only 7 GitHub stars
Code Pass
- Code scan — Scanned 12 files during light audit, no dangerous patterns found
Permissions Pass
- Permissions — No dangerous permissions requested
No AI report is available for this listing yet.
AI-powered code quality agent with ML semantic analysis. Prevents technical debt before production. Free tier: static analysis. Pro tier: ML duplicate detection, real-time metrics, CI/CD automation. Built for AI coding era. Open core model: Phase 0 free, Phase 1 paid.
HefestoAI — release truth engine for AI-generated code
HefestoAI runs after your AI assistant writes the code and before it ships. It checks that what your project declares (dependencies, configs, install artifacts) matches what it actually does, and it runs security and complexity checks on the code itself.
Operational Truth Analyzers (v4.13.1)
These analyzers look for drift between what your project declares and what it does. They run on every hefesto analyze. The problems they look for don't live in any single file, so a per-file linter or security scanner won't report them: they show up only when you compare two files.
| Analyzer | What it catches | Rule ID |
|---|---|---|
| Imports vs Deps | Python imports not declared in pyproject.toml or requirements.txt |
OT-IMPORTS-001 |
| Docs vs Entrypoints | CLI scripts in [project.scripts] missing from README |
OT-DOCS-001 |
| Packaging Parity | Version mismatch between pyproject.toml, CHANGELOG, and README badges |
OT-PKG-001/002 |
| Install Artifact Parity | action.yml inputs not consumed; Dockerfile COPY sources missing |
OT-INSTALL-001/002 |
| CI Config Drift | Python version or flake8 config mismatch between local and CI workflow | OT-CI-001/002/003 |
# All operational truth findings appear in standard output
hefesto analyze . --severity MEDIUM
Quick Start
pip install hefesto-ai
cd your-project
hefesto analyze . --fail-on critical
# PR review (added in v4.10.0) — analyze only changed code
hefesto pr-review
hefesto pr-review --strict # include file-level context
hefesto pr-review --post --pr 42 # post inline comments via gh CLI
Why Hefesto? The AI Code Problem
Assistants such as Claude Code, GitHub Copilot and Cursor write code faster than anyone can review it line by line. Some of what they write passes a linter and is still dangerous:
os.system(user_input)→ command injectionf"SELECT * FROM {table}"→ SQL injection- code that runs but quietly changes behavior, such as a misspelled attribute or an exception that is caught and dropped (checked in Python)
Hefesto checks for these at pre-commit, at pre-push and in CI, so they surface before the code reaches production.
What Hefesto Catches
| Issue | Severity | Description |
|---|---|---|
| HARDCODED_SECRET | CRITICAL | API keys, passwords in code |
| SQL_INJECTION_RISK | HIGH | String concatenation in queries |
| COMMAND_INJECTION | HIGH | Unsafe shell command execution |
| PATH_TRAVERSAL | HIGH | Unsafe file path handling |
| UNSAFE_DESERIALIZATION | HIGH | pickle, yaml.unsafe_load |
| UNDECLARED_DEPENDENCY | MEDIUM | Import used but not in pyproject.toml |
| PACKAGING_VERSION_DRIFT | MEDIUM | Version mismatch across pyproject/CHANGELOG/README |
| CI_CONFIG_DRIFT | MEDIUM-HIGH | Local env vs CI configuration mismatch |
| INSTALL_ARTIFACT_DRIFT | MEDIUM-HIGH | action.yml inputs or Dockerfile COPY out of sync |
| HIGH_COMPLEXITY | HIGH | Cyclomatic complexity > 10 |
| DEEP_NESTING | HIGH | Nesting depth > 4 levels |
| GOD_CLASS | HIGH | Classes > 500 lines |
| LONG_FUNCTION | MEDIUM | Functions > 50 lines |
| LONG_PARAMETER_LIST | MEDIUM | Functions with > 5 parameters |
# Hefesto catches:
password = "admin123" # HARDCODED_SECRET
query = f"SELECT * FROM users WHERE id={id}" # SQL_INJECTION_RISK
os.system(f"rm {user_input}") # COMMAND_INJECTION
# Hefesto suggests:
password = os.getenv("PASSWORD")
cursor.execute("SELECT * FROM users WHERE id=?", (id,))
subprocess.run(["rm", user_input], check=True)
GitHub Action
steps:
- uses: actions/checkout@v4
- name: Run Hefesto Guardian
uses: artvepa80/[email protected]
with:
target: '.'
fail_on: 'CRITICAL'
Inputs:
| Input | Description | Default |
|---|---|---|
target |
Path to analyze (file or directory) | . |
fail_on |
Exit with error if issues found at or above this severity level | CRITICAL |
min_severity |
Minimum severity to report (CRITICAL, HIGH, MEDIUM, LOW) |
LOW |
format |
Output format (text, json, html) |
text |
telemetry |
1 also enables the CLI's anonymous telemetry inside the Action. In v4.13.1 the Action itself still sends one anonymous ping per run even when this is 0; see Telemetry |
0 |
Outputs:
| Output | Description |
|---|---|
exit_code |
The exit code of the CLI (0 = threshold not breached, 1 = fail_on threshold breached or runtime error; see Exit Codes) |
AI-Generated Code Guardrails (Pre-commit + MCP)
HefestoAI can run as a pre-commit check or be called by an AI agent over MCP, so risky changes are flagged before merge.
Add as an MCP server:
npx @smithery/cli@latest mcp add artvepa80/hefestoai
API Endpoints:
| Endpoint | Protocol | Path |
|---|---|---|
| MCP | JSON-RPC 2.0 | /api/mcp-protocol |
| REST | HTTP GET/POST | /api/mcp |
| OpenAPI | OpenAPI 3.0 | /api/openapi.json |
| Q&A | Natural Language | /api/ask |
| Changelog | JSON | /api/changelog.json |
| FAQ | JSON | /api/faq.json |
PR Review (v4.13.1)
Analyze only the code changed in a pull request and post inline comments on the changed lines. Each finding carries a deterministic dedup key, so a workflow can skip findings it has already posted (the deduped template below does this; the simple one does not).
# Generate review as JSON (default — no network, no token needed)
hefesto pr-review
# Post inline comments via gh CLI (convenience mode)
hefesto pr-review --post --pr 42 --repo owner/name
# Include file-level context findings (not just changed lines)
hefesto pr-review --strict
How it works:
- Parses
git diffbetween base and head (auto-detectsorigin/mainorGITHUB_BASE_REF) - Runs the full analyzer suite on touched files only
- Filters findings to changed lines (default) or full files (
--strict) - Emits JSON with SHA256 dedup keys for each finding
GitHub Actions workflow templates are provided under examples/github-actions/:
| Template | Use case | Idempotent? |
|---|---|---|
hefesto-pr-review-simple.yml |
Quick onboarding, small repos | No (reruns duplicate) |
hefesto-pr-review-deduped.yml |
Production CI, teams | Yes (jq dedup pipeline) |
See examples/github-actions/README.md for setup instructions.
Language Support
Code Languages
| Language | Parser | Status |
|---|---|---|
| Python | Native AST | Full support |
| TypeScript | TreeSitter | Supported¹ |
| JavaScript | TreeSitter | Supported¹ |
| Java | TreeSitter | Supported¹ |
| Go | TreeSitter | Supported¹ |
| Rust | TreeSitter | Supported¹ |
| C# | TreeSitter | Supported¹ |
¹ TreeSitter languages require the [multilang] extra:pip install "hefesto-ai[multilang]". Without it, files in these
languages are skipped at parse time and Hefesto emits a stderr warning
pointing to the install command (also exposed viareport.meta.parser_failures in JSON output).
DevOps & Configuration
| Format | Analyzer | Rules | Status | Run by hefesto analyze² |
|---|---|---|---|---|
| YAML | YamlAnalyzer | Generic YAML security | v4.4.0 | Yes |
| Terraform | TerraformAnalyzer | TfSec-aligned rules | v4.4.0 | Yes |
| Shell | ShellAnalyzer | ShellCheck-aligned | v4.4.0 | Yes |
| Dockerfile | DockerfileAnalyzer | Hadolint-aligned | v4.4.0 | Yes |
| SQL | SqlAnalyzer | SQL Injection prevention | v4.4.0 | Yes |
| PowerShell | PS001-PS006 | 6 security rules | v4.5.0 | Not yet |
| JSON | J001-J005 | 5 security rules | v4.5.0 | Not yet |
| TOML | T001-T003 | 3 security rules | v4.5.0 | Not yet |
| Makefile | MF001-MF005 | 5 security rules | v4.5.0 | Not yet |
| Groovy | GJ001-GJ005 | 5 security rules | v4.5.0 | Not yet |
| COBOL | CobolGovernanceAnalyzer | COBOL001-COBOL007 | v4.12.0 | Yes |
Cloud Infrastructure
| Format | Analyzer | Focus | Status | Run by hefesto analyze² |
|---|---|---|---|---|
| CloudFormation | CloudFormationAnalyzer | AWS IaC Security | v4.7.0 | Not yet |
| ARM Templates | ArmAnalyzer | Azure IaC Security | v4.7.0 | Not yet |
| Helm Charts | HelmAnalyzer | Kubernetes Security | v4.7.0 | Not yet |
| Serverless | ServerlessAnalyzer | Serverless Framework | v4.7.0 | Not yet |
Total: the package ships analyzers for 22 formats (7 code languages + 11 DevOps formats + 4 Cloud formats). In v4.13.1, hefesto analyze (which the GitHub Action and the pre-push hook call) runs 13 of them.
² The PowerShell, JSON, TOML, Makefile, Groovy, CloudFormation, ARM, Helm and Serverless analyzers are included and tested as modules, but the analysis engine does not route files to them yet, so these files are skipped by the CLI.
Installation
# FREE tier
pip install hefesto-ai
# Required for TypeScript, JavaScript, Java, Go, Rust, and C# analysis
pip install "hefesto-ai[multilang]"
pip install hefesto-ai installs the FREE tier only. For PRO or OMEGA, Narapa sends you an activation code after purchase, and the activation instructions come with it.
CLI Reference (v4.13.1)
# Analyze code
hefesto analyze <path>
hefesto analyze . --severity HIGH
hefesto analyze . --output json
# PR review (added in v4.10.0)
hefesto pr-review # JSON to stdout
hefesto pr-review --base main --head HEAD # explicit refs
hefesto pr-review --strict # file-level findings too
hefesto pr-review --post --pr 42 --repo o/r # post via gh CLI
# Check status
hefesto status
# Install/update git hook
hefesto install-hooks
# Start API server (PRO)
hefesto serve --port 8000
# Telemetry Management
hefesto telemetry status
hefesto telemetry clear
JSON Output
hefesto analyze . --output json # stdout = pure JSON, banners -> stderr
hefesto analyze . --output json 2>/dev/null | jq . # pipe-safe
Exit Codes
| Code | Meaning |
|---|---|
0 |
Analysis complete (no --fail-on, or threshold not breached) |
1 |
Gate failure (--fail-on threshold breached) or runtime error |
Gate Examples
hefesto analyze . --fail-on high # exit 1 if HIGH+ found
hefesto analyze . --fail-on critical # exit 1 only if CRITICAL found
hefesto analyze . # always exit 0 (report only)
Pre-Push Hook
Automatic validation before every git push:
# Install/update hook (copies scripts/git-hooks/pre-push -> .git/hooks/pre-push)
hefesto install-hooks
# Update an existing hook
hefesto install-hooks --force
# Bypass temporarily
SKIP_HEFESTO_HOOKS=1 git push
The hook runs two gates:
- Security gate —
hefesto analyzewith--fail-on CRITICAL --exclude-types VERY_HIGH_COMPLEXITY,LONG_FUNCTION(blocks security issues, ignores complexity debt) - Fast lint/test gate — Black, isort, Flake8, and a minimal test suite
Note: Hooks are local to your machine and not committed to git. Run
hefesto install-hooksafter cloning or wheneverscripts/git-hooks/pre-pushis updated.
Features by Tier
| Feature | FREE | PRO ($8/mo) | OMEGA ($19/mo) |
|---|---|---|---|
| Static Analysis | Yes | Yes | Yes |
| Security Scanning | Basic | Advanced | Advanced |
| Pre-push Hooks | Yes | Yes | Yes |
| Language & format support (details) | Yes | Yes | Yes |
| ML Enhancement | No | Yes | Yes |
| REST API | No | Yes | Yes |
| BigQuery Analytics | No | Yes | Yes |
| IRIS Monitoring | No | No | Yes |
| Production Correlation | No | No | Yes |
- PRO: Start Free Trial - 14 days, no credit card
- OMEGA: Start Free Trial - 14 days, no credit card
- Founding Members: 40% off forever (first 25 customers)
Hefesto PRO Optional Features
Hefesto OSS works standalone. If Hefesto PRO is installed, OSS can optionally enable:
Patch C API hardening for hefesto serve, scope gating (first-party by default), TS/JS
symbol discovery, and safe deterministic enrichment (schema-first, masked, bounded).
See docs/PRO_OPTIONAL_FEATURES.md.
REST API (PRO)
# Start server (binds to 127.0.0.1 by default)
hefesto serve --port 8000
# Analyze code
curl -X POST http://localhost:8000/analyze \
-H "Content-Type: application/json" \
-H "X-API-Key: $HEFESTO_API_KEY" \
-d '{"code": "def test(): pass", "severity": "MEDIUM"}'
API Security (v4.8.0)
The API server starts with these defaults:
| Feature | Default | Configure via |
|---|---|---|
| Host binding | 127.0.0.1 (loopback) |
HEFESTO_API_HOST |
| CORS | Localhost only | HEFESTO_CORS_ORIGINS |
| API docs | Disabled (404) | HEFESTO_EXPOSE_DOCS=true |
| Auth | Off (no key set) | HEFESTO_API_KEY |
| Rate limit | 60 req/min | HEFESTO_RATE_LIMIT_PER_MINUTE |
| Path sandbox | cwd() |
HEFESTO_WORKSPACE_ROOT |
# Production example
export HEFESTO_API_KEY=my-secret-key
export HEFESTO_CORS_ORIGINS=https://app.example.com
export HEFESTO_RATE_LIMIT_PER_MINUTE=60
export HEFESTO_EXPOSE_DOCS=false
hefesto serve --host 0.0.0.0 --port 8000
Endpoints
| Endpoint | Method | Description |
|---|---|---|
/analyze |
POST | Analyze code |
/health |
GET | Health check (no auth required) |
/ping |
GET | Fast health ping (no auth required) |
/batch |
POST | Batch analysis |
/metrics |
GET | Quality metrics |
/history |
GET | Analysis history |
/webhook |
POST | GitHub webhook |
/stats |
GET | Statistics |
/validate |
POST | Validate without storing |
CI/CD Integration
GitHub Actions — Full Repo Analysis
name: Hefesto
on: [push, pull_request]
jobs:
analyze:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Install Hefesto
run: pip install hefesto-ai
- name: Run Analysis
run: hefesto analyze . --severity HIGH
GitHub Actions — PR Review with Inline Comments (v4.13.1)
name: Hefesto PR Review
on:
pull_request:
types: [opened, synchronize, reopened]
permissions:
contents: read
pull-requests: write
jobs:
review:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
with:
fetch-depth: 0
- run: pip install hefesto-ai
- name: Review changed code
env:
GITHUB_BASE_REF: ${{ github.event.pull_request.base.ref }}
GITHUB_SHA: ${{ github.event.pull_request.head.sha }}
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
run: hefesto pr-review --post --pr ${{ github.event.pull_request.number }} --repo ${{ github.repository }}
For production use with dedup (no duplicate comments on reruns), see the workflow templates in
examples/github-actions/.
pre-commit Hook
# .pre-commit-config.yaml
repos:
- repo: https://github.com/artvepa80/Agents-Hefesto
rev: v4.13.1
hooks:
- id: hefesto-analyze
GitLab CI
hefesto:
stage: test
script:
- pip install hefesto-ai
- hefesto analyze . --severity HIGH
Configuration
Environment Variables
# Core
export HEFESTO_LICENSE_KEY="your-key"
export HEFESTO_SEVERITY="MEDIUM"
export HEFESTO_OUTPUT="json"
# API Security (v4.7.0)
export HEFESTO_API_KEY="your-api-key" # Enable API key auth
export HEFESTO_RATE_LIMIT_PER_MINUTE=60 # Enable rate limiting
export HEFESTO_CORS_ORIGINS="https://app.example.com" # Restrict CORS
export HEFESTO_EXPOSE_DOCS=true # Enable /docs, /redoc
export HEFESTO_WORKSPACE_ROOT="/srv/code" # Path sandbox root
export HEFESTO_CACHE_MAX_ITEMS=256 # Cache size limit
export HEFESTO_CACHE_TTL_SECONDS=300 # Cache entry TTL
Config File (.hefesto.yaml)
severity: HIGH
exclude:
- tests/
- node_modules/
- .venv/
rules:
complexity:
max_cyclomatic: 10
max_cognitive: 15
security:
check_secrets: true
check_injections: true
OMEGA Guardian
Production monitoring that correlates code issues with production failures.
Features
- IRIS Agent: Real-time production monitoring
- Auto-Correlation: Links code changes to incidents
- Real-Time Alerts: Pub/Sub notifications
- BigQuery Analytics: Track correlations over time
Setup
# iris_config.yaml
project_id: your-gcp-project
dataset: omega_production
pubsub_topic: hefesto-alerts
alert_rules:
- name: error_rate_spike
threshold: 10
- name: latency_increase
threshold: 1000
# Run IRIS Agent
python -m hefesto.omega.iris_agent --config iris_config.yaml
# Check status
hefesto omega status
IRIS Telemetry Contract (OMEGA)
IRIS labels deployments as GREEN/YELLOW/RED using post-deploy telemetry. The input format is an open contract — any observability stack can produce it:
| Resource | Path | Description |
|---|---|---|
| Aggregates Contract v1 | docs/telemetry/AGGREGATES_CONTRACT.md |
Row schema, units, validation checklist |
| JSONL Validator | scripts/validate_aggregates_jsonl.py |
Stdlib-only validator (no deps) |
# Validate your telemetry file
python scripts/validate_aggregates_jsonl.py aggregates.jsonl
# Feed to IRIS (OMEGA tier)
export IRIS_TELEMETRY_SOURCE=file
export IRIS_TELEMETRY_FILE=aggregates.jsonl
iris label-outcomes --repo org/repo --commit abc123 --env production --window both --json
Enterprise collectors (Prometheus, Datadog, CloudWatch) and integration runbooks are available in the PRO distribution.
vs. Competition
| Criterion | Hefesto | Semgrep | CodeRabbit | Qodo | Snyk |
|---|---|---|---|---|---|
| AI-generated code focus | ✅ Primary use case | Generic | ✅ Yes | ✅ Yes | Generic |
| Declared-vs-real drift detection | ✅ Core feature | ❌ | ❌ | ❌ | ❌ |
| Operational truth analyzers | ✅ 5 analyzers | ❌ | ❌ | ❌ | ❌ |
| Languages supported | 13 formats analyzed by the CLI (22 analyzers shipped; details) | Many | Many | Many | Many |
| Setup time | < 5 min, no config | Config-heavy | Cloud signup | Cloud signup | Cloud signup |
| Where it runs | Local CLI / GitHub Action / pre-commit / MCP | Local / cloud | Cloud only | Cloud only | Cloud / CLI |
| Pricing (as of Oct 2026) | Free OSS / $8/mo PRO / $19/mo OMEGA | Free tier / Teams $30/contributor/mo (Code)* | Free for public repos / $24/dev/mo (annual) | Credit-based, $0.012/credit; no permanent free plan | Free / Team $25/mo** |
*Semgrep Supply Chain and Secrets are priced separately. **Snyk Team covers up to 10 developers; Enterprise is credit-based. Prices from each vendor's official pricing page, checked Oct 2026; they change often.
Where HefestoAI fits: most tools check code against the rules of its language. HefestoAI also checks a project against its own declarations: whether the imports match the declared dependencies, whether the versions in pyproject.toml, the CHANGELOG and the README agree, and whether action.yml and the Dockerfile match the files they reference.
Dogfooding (Honest Account)
We run HefestoAI's strict gate against HefestoAI's own code on every push to main. The gate has been GREEN since 2026-04-29, and getting there took more than six weeks: we logged the findings on 2026-03-17.
In strict mode, the gate flagged 12 complexity findings in our own gate-internals code (2 CRITICAL, 10 HIGH). We considered three responses: silence the findings (rejected — that's exactly the drift we critique), accept the override permanently (rejected — same reason), or refactor at root cause (chosen). The root-cause refactor itself was short once we started it: one PR, written over two days (2026-04-27 and 04-28) and merged on 2026-04-29. Along the way we also found a declared-vs-real drift in our own positioning doc and logged it for a fix.
The full audit and refactor history are tracked internally in our private repo. The refactor took the two CRITICAL functions from cyclomatic complexity 33 → 1 and 25 → 6, all helpers under 10. The 10 HIGH findings are under a temporary override whose mechanics and reversion criteria are documented.
Changelog
Highlights only. The full history is in CHANGELOG.md.
v4.13.1 (2026-05-08)
- Fix: R3 (
RELIABILITY_SESSION_LIFECYCLE) no longer flags a connection stored onselfwhen a sibling method closes it
v4.13.0 (2026-05-06)
- Parser-failure visibility: when TypeScript, JavaScript, Java, Go, Rust or C# files are skipped (for example, because
[multilang]is missing), Hefesto prints a warning to stderr and records the files inreport.meta.parser_failures - CI smoke test for the
[multilang]extra on Python 3.10–3.13
v4.12.0 (2026-04-25)
- COBOL governance analysis: 7 rules for COBOL-85 and IBM Enterprise COBOL (3 FREE, 4 PRO)
v4.11.2 (2026-04-12)
- Phase 4 — Narrow Semantic Analyzer:
ATTRIBUTE_NAME_MISMATCH(typo detection via difflib) andSILENT_EXCEPTION_SWALLOW(broad except with trivially silent body) - Cross-repo schema contract test: pins 12-key PR review finding dict between OSS and Pro
code_snippetin PR review JSON: field was silently dropped, now included- Phase 3.1 — Enrichment rendering: PR comments render AI enrichment summary when present
- Upgrade notice: shows when a newer version is available on PyPI
- Fix:
contextlib.suppress(ImportError)recognized as optional-import guard - Fix: AST
BinOp(Mod)catches single-char SQL injection FN (Phase 1c debt closed) - 474 tests (was 430), 0 regressions
v4.10.0 (2026-04-12)
- PR Review: New
hefesto pr-reviewcommand — diff-scoped analysis with inline GitHub PR comments and SHA256 dedup keys. Two workflow templates (simple + deduped) inexamples/github-actions/ - Operational Truth Analyzers: 5 project-level analyzers detect drift between imports/deps, docs/entrypoints, packaging versions, install artifacts, and CI config — all visible via
hefesto analyze - Security Precision (BP-7): SQL_INJECTION FP rate 43%→0% (DB-API placeholders no longer flagged), ASSERT_IN_PRODUCTION 31→0 FPs (AST rewrite), PICKLE/BARE_EXCEPT detectors rewritten with exact matching
- CI Parity Unification:
check-ci-parityfindings now appear inhefesto analyzevia adapter; legacy CLI preserved - 430 tests (was 346), 0 regressions
v4.9.9 (2026-03-13)
- Telemetry: Anonymous usage pings enabled by default (opt-out via
HEFESTO_TELEMETRY=0) - First-run notice printed once to stderr
- No code, paths, or PII collected
v4.9.7 (2026-03-13)
- Telemetry: Anonymous usage ping endpoint (CLI opt-in + GitHub Action always-on)
v4.9.3 (2026-02-24)
- MCP endpoint live (JSON-RPC 2.0)
- AI discoverability stack complete (llms.txt, agent.json, OpenAPI, FAQ, Changelog)
- Registered in official MCP Registry and Smithery
v4.9.0 (2026-02-14)
- Boundary: Public/private repo split — community edition only in public repo.
- Removed: Paid modules (api, llm, licensing, omega), paid infra, paid tests.
- Hardened: Packaging (packages.find exclude, MANIFEST.in prune, CI guard).
v4.8.5 (2026-02-13)
- GitHub Action: Market-ready Docker-based action (bypassing PyPI).
- Security: Deterministic smoke tests with clean/critical fixtures.
- CLI: Verified exit code contract (2 = Issues Found). Current CLI exits with 1 when the
--fail-ongate fails; see Exit Codes.
v4.7.0 (2026-02-10)
- Patch C: API Hardening —
hefesto serveis secure-by-default (local-first) - Security: API key auth, CORS allowlist, docs toggle, path sandbox
v4.3.3 (2025-12-26)
- Fix LONG_PARAMETER_LIST: use AST formal_parameters instead of comma counting
- Fix function naming: infer names from variable_declarator for arrow functions
v4.2.1 (2025-10-31)
- Critical tier hierarchy bugfix
- OMEGA Guardian release
Telemetry
HefestoAI collects anonymous usage data by default to help improve the tool.
What's sent (CLI): event type, version, OS, Python version, file count, duration, issue count, exit code, a random anonymous ID stored in ~/.hefesto/.session_id (delete the file to reset it), environment flags such as ci, github_actions, docker or dogfood, and the install source (pypi or editable).
What's sent (GitHub Action): version, file count, issue count and exit code, once per run. In v4.13.1 this ping is sent even when the telemetry input is 0; setting the input to 1 adds the CLI ping described above.
What's NOT sent: code, file paths, file contents, project names, or any PII.
The CLI prints a one-time notice to stderr the first time it sends a ping, and it uses the server's reply to tell you when a newer version is on PyPI. Disable the CLI ping with:
export HEFESTO_TELEMETRY=0
Tag owner/dogfood runs so they do not mix with end-user analytics (env includes dogfood; also auto-tagged for editable installs):
export HEFESTO_TELEMETRY_ENV=dogfood
# or: export HEFESTO_DOGFOOD=1
Filter in Neon: WHERE NOT ('dogfood' = ANY(env)).
hefesto telemetry status and hefesto telemetry clear manage a separate local telemetry log; they do not show or control the remote ping.
Contact
- Enterprise & licensing: [email protected]
- Support & bug reports: [email protected]
- General inquiries: [email protected]
- GitHub Issues: artvepa80/Agents-Hefesto/issues
- Website: hefestoai.narapallc.com
License
The code in this repository is licensed under the MIT License. The paid PRO and OMEGA features (the separately distributed hefesto_pro add-on) are covered by separate commercial terms in LICENSE-COMMERCIAL.md. Questions about licensing: [email protected].
(c) 2026 Narapa LLC, Miami, Florida
Reviews (0)
Sign in to leave a review.
Leave a reviewNo results found