Ross ROSS = Recommend OSS · open-source software intelligence for agents

hanc00l/nemo_go

Nemo是用来进行自动化信息收集的一个简单平台,通过集成常用的信息收集工具和技术,实现对内网及互联网资产信息的自动收集,提高隐患排查和渗透测试的工作效率。 observed · 2026-08-28

github.com/hanc00l/nemo_go · JavaScript · Apache-2.0 (permissive) observed · 2026-08-28

Health v2 · maintenance only

88/100

  • Activity 97
  • Release rhythm 69
  • Longevity 100
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.

  • gap_med: 20.5
  • age_days: 1861
  • days_rel: 205
  • days_push: 18
  • n_releases_24m: 7

Full methodology

Adoption not part of the score

2086 stars · 284 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

Nemo is an automated information-gathering platform for penetration testing that integrates common recon tools (Masscan, Nmap, Subfinder, Httpx, Nuclei, etc.) to collect internal and internet-facing asset data. It provides distributed task execution, asset management with MongoDB storage, fingerprint and PoC validation, team collaboration, and an MCP Server for AI integration.

Use cases

  • automate reconnaissance for penetration tests
  • collect subdomains and map external attack surface
  • scan internal network assets and open ports
  • fingerprint web services and validate vulnerabilities with nuclei
  • run distributed scheduled asset discovery tasks
  • generate recon reports with LLM APIs
  • collaborate with a team on asset management during engagements

When to choose

  • you need an integrated recon platform instead of chaining tools manually
  • you want distributed workers for large-scale asset collection
  • you need team collaboration with multi-workspace asset isolation
  • you want fingerprint-driven PoC validation and weak-password brute forcing

When to avoid

  • you only need a single lightweight scanner like nmap or subfinder
  • you need a compliant vulnerability management product rather than offensive tooling
  • you cannot self-host a MongoDB-backed server with workers

Facets

application · maturity active

security osint web-scraping search-engine mcp agent-framework workflow-automation scheduling security penetration-testing osint developer-tools self-hosted cli reconnaissance attack-surface-management asset-discovery subdomain-enumeration fingerprinting vulnerability-scanning nuclei distributed-tasks pentest-platform automation linux docker web-server

1 source

Member repositories

RepositoryRoleHealth v2
hanc00l/nemo_gomain88

For agents

markdown · JSON · MCP: product_card(name="hanc00l/nemo_go")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem