{"id":51635423,"url":"https://github.com/elder-plinius/T3MP3ST","last_synced_at":"2026-07-15T13:01:16.883Z","repository":{"id":369102654,"uuid":"1287460663","full_name":"elder-plinius/T3MP3ST","owner":"elder-plinius","description":"autonomous red teaming platform; multi-agent offensive-security meta-harness","archived":false,"fork":false,"pushed_at":"2026-07-09T12:51:34.000Z","size":1835,"stargazers_count":4626,"open_issues_count":50,"forks_count":980,"subscribers_count":45,"default_branch":"main","last_synced_at":"2026-07-13T21:25:17.311Z","etag":null,"topics":["agents","ai","multi-agent","offensive-security","redteam"],"latest_commit_sha":null,"homepage":"","language":"TypeScript","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"agpl-3.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/elder-plinius.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":"CONTRIBUTING.md","funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":"SECURITY.md","support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null}},"created_at":"2026-07-02T17:53:55.000Z","updated_at":"2026-07-13T21:24:16.000Z","dependencies_parsed_at":null,"dependency_job_id":null,"html_url":"https://github.com/elder-plinius/T3MP3ST","commit_stats":null,"previous_names":["elder-plinius/t3mp3st"],"tags_count":0,"template":false,"template_full_name":null,"purl":"pkg:github/elder-plinius/T3MP3ST","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/elder-plinius%2FT3MP3ST","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/elder-plinius%2FT3MP3ST/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/elder-plinius%2FT3MP3ST/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/elder-plinius%2FT3MP3ST/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/elder-plinius","download_url":"https://codeload.github.com/elder-plinius/T3MP3ST/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/elder-plinius%2FT3MP3ST/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":35441682,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-05-26T15:22:16.424Z","status":"online","status_checked_at":"2026-07-13T02:00:06.543Z","response_time":119,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["agents","ai","multi-agent","offensive-security","redteam"],"created_at":"2026-07-13T14:00:19.878Z","updated_at":"2026-07-15T13:01:16.867Z","avatar_url":"https://github.com/elder-plinius.png","language":"TypeScript","funding_links":[],"categories":["Pentest \u0026 Red Teaming Agents","TypeScript"],"sub_categories":[],"readme":"# 🌩️ T3MP3ST 🌩️\n\n\u003c!-- ⊰ sharp eye on the raw source. there's a flag for the curious: T3MP3ST{r3c31pt5_n0t_v1b3z} — the one that counts, you earn: run `npm run verify-claims`. LOVE PLINY ⊱ --\u003e\n\n```\n ▄▄▄█████▓▓█████  ███▄ ▄███▓ ██▓███  ▓█████   ██████ ▄▄▄█████▓\n ▓  ██▒ ▓▒▓█   ▀ ▓██▒▀█▀ ██▒▓██░  ██▒▓█   ▀ ▒██    ▒ ▓  ██▒ ▓▒\n ▒ ▓██░ ▒░▒███   ▓██    ▓██░▓██░ ██▓▒▒███   ░ ▓██▄   ▒ ▓██░ ▒░\n ░ ▓██▓ ░ ▒▓█  ▄ ▒██    ▒██ ▒██▄█▓▒ ▒▒▓█  ▄   ▒   ██▒░ ▓██▓ ░\n   ▒██▒ ░ ░▒████▒▒██▒   ░██▒▒██▒ ░  ░░▒████▒▒██████▒▒  ▒██▒ ░\n   ▒ ░░   ░░ ▒░ ░░ ▒░   ░  ░▒▓▒░ ░  ░░░ ▒░ ░▒ ▒▓▒ ▒ ░  ▒ ░░\n     ░     ░ ░  ░░  ░      ░░▒ ░      ░ ░  ░░ ░▒  ░ ░    ░\n   ░         ░   ░      ░   ░░          ░   ░  ░  ░    ░\n             ░  ░       ░               ░  ░      ░\n```\n\n\u003cdiv align=\"center\"\u003e\n\n**A multi-agent offensive-security framework, built to turn the AI coding agent you already run into a zero-day hunter.**\n\n![scores: re-derivable](https://img.shields.io/badge/scores-re--derivable-brightgreen) \u0026nbsp; ![verify-claims 24/24](https://img.shields.io/badge/verify--claims-24%2F24-brightgreen) \u0026nbsp; ![PRs welcome](https://img.shields.io/badge/PRs-welcome-purple) \u0026nbsp; ![License: AGPL-3.0](https://img.shields.io/badge/License-AGPL--3.0-blue)\n\n\u003c/div\u003e\n\n**Your AI coding agent is already a hacker — T3MP3ST hands it an arsenal.**\n\nPoint it at an authorized target and the kill chain runs itself: **recon → exploit → report**, from a browser War Room or the CLI, driven by the agent you're *already* signed into — Claude Code, Codex, Hermes — or a model you run **fully offline** (Ollama, LM Studio, vLLM). No new API keys, no cloud tenant, no second bill. Your agent is the brain; T3MP3ST is the war machine bolted around it. **Self-hosted storm. Keyless warfare.** ⚡\n\nAnd it won't ask you to take its word for it. On **XBOW's own 104-challenge suite it scores 90.1% pass@1** — above XBOW's self-reported 85% — alongside hint-free CTF solves and a **cold hunt on real, post-cutoff CVEs the model had never seen**. Every number in this README recomputes from committed data with one command (`npm run verify-claims`). Loud about the mission, honest about the build — the [status table](#what-ships-today) says exactly what's live, what's scaffolding, and what's still roadmap; full receipts in [Benchmarks](#benchmarks).\n\nThree things set it apart:\n\n1. **Reproducible.** Every number in this README recomputes from committed data — `npm run verify-claims` re-derives all of them, 24/24 green. A claim that can't be reproduced doesn't ship. No trust-me numbers, ever.\n2. **Keyless.** The AI coding agent already on your machine is the backbone. No API keys, no second bill, no gatekeeper.\n3. **Honest about scope.** The [status table](#what-ships-today) marks exactly what's stable, experimental, or roadmap — because red-teaming shouldn't be a priesthood, and it damn sure shouldn't run on vibes.\n\n**Jump to** → [Quick start](#quick-start) · [What it hunts](#what-it-hunts) · [What ships today](#what-ships-today) · [Benchmarks](#benchmarks) · [Architecture](#architecture) · [Docs](#documentation)\n\n## ⚠️ Authorized use only\n\nT3MP3ST is an **offensive** security tool, built for **authorized** testing, research, and education. Point it **only** at systems you own or have **explicit, written permission** to test. Unauthorized access to computers, networks, or data is illegal in most jurisdictions — **you alone are responsible** for how you use this software and for staying inside the law and your rules of engagement. Bring the storm to *your* targets, not someone else's.\n\nT3MP3ST is provided **as-is under the AGPL-3.0 license, with no warranty and no liability** for any damage, loss, or misuse. The authors do not endorse, support, or condone unauthorized activity. Get permission. Stay in scope. Don't be a menace. 🫡\n\n## Why it exists\n\nOffensive security sits behind years of practice and expensive tooling. The bet behind T3MP3ST is that a coordinated agent swarm puts real bug-hunting in reach of people who never got the invite, across web apps, CTFs, smart contracts, source code, and embedded/robotics OSS. That is an ambitious bet, and the sections below are careful to separate what already works from what is still a bet.\n\n## What it hunts\n\n| Domain | What it does | Status |\n|---|---|---|\n| 🕸️ **Web apps** | Black-box, external-attacker recon → exploit (XBEN suite) | ✅ Stable |\n| 🚩 **CTF** | Hint-free, sandbox-jailed solves (Cybench) | ✅ Stable |\n| 🤖 **Robotics / OT / embedded** | Coordinated-disclosure pipeline for OSS vuln hunting (OSV + live-PoC + refuter) | ✅ Pipeline stable |\n| 📂 **Source code** | White-box repo analysis with blind master-builder decomposition | ⚠️ Python-only ingest |\n| 💰 **Smart contracts** | Damn Vulnerable DeFi | ⚠️ reproduction, not novel discovery |\n| ☁️ **Cloud (IaC)** | Misconfig-detection benchmark (`cloud:bench`) + opt-in cloud arsenal (aws/az/gcloud + scoutsuite/cloudfox/pmapper; pacu gated) | 🚧 IaC-misconfig scaffolding — live-cloud exploitation not yet benchmarked |\n| 📱 **Mobile** | Built-in static analyzer (manifest misconfig + secret/cleartext detection, `mobile:bench`) + opt-in arsenal (mobsfscan/objection/drozer; frida gated) | 🚧 static-detection scaffolding — dynamic exploitation not benchmarked |\n| 🔩 **Binary / RE** | Decompiled-output sink detector (unsafe-copy / format-string / cmd-injection / int-overflow, `binary:bench`) + opt-in arsenal (ghidra/radare2/objdump/checksec/strings; gdb gated) | 🚧 static sink-detection scaffolding — solving/pwn not benchmarked |\n\n## Quick start\n\nFastest path to a running War Room (keyless, ~2 min to set up; mission time depends on the target):\n\n```bash\nnpm install\nnpm run server        # War Room → http://127.0.0.1:3333/ui/\n```\n\nIn the War Room, open **Settings** and connect a local agent (Claude Code / Codex / Hermes). Then describe a target to **Op Admiral** in plain English and launch. The agent you connected is the brain. No key required.\n\nPrefer to bring a key? Set one and skip the connect step:\n\n```bash\nexport OPENROUTER_API_KEY=...     # or VENICE_API_KEY / ANTHROPIC_API_KEY / OPENAI_API_KEY\nexport XAI_API_KEY=...            # Grok Build (grok-build-0.1) — xAI's coding model, native tool-calling\n```\n\nSlow local agents can be given more room with `T3MP3ST_LOCAL_AGENT_TIMEOUT_MS`\nfor each CLI call, `T3MP3ST_TASK_TIMEOUT_MS` for mission tasks, and\n`T3MP3ST_GENERAL_TIMEOUT_MS` for planning requests. Values are milliseconds.\n\nOr run it **fully offline** on your own model — no key, no cloud. Defaults to Ollama; point it at any OpenAI-compatible server (LM Studio, vLLM, llama.cpp):\n\n```bash\nollama serve \u0026\u0026 ollama pull llama3                          # or an OpenAI-compatible server\nexport TEMPEST_LOCAL_BASE_URL=http://localhost:11434/api    # LM Studio: http://localhost:1234/v1\nexport TEMPEST_LOCAL_MODEL=llama3\nnpx tempest                                                 # → \"Change default provider\" → local\n```\n\nTool-calling works on any local model (it's driven over text), so the Arsenal runs even on models without native function-calling.\n\nCheck the numbers for yourself:\n\n```bash\nnpm run verify-claims             # re-derives every headline from committed JSON in bench/\n```\n\nLibrary/SDK usage, the full HTTP API, and MCP setup live in [docs/](docs/).\n\n## What ships today\n\nThe framework is an 8-operator kill chain, and this table won't blow smoke about it. **Recon is a live, tool-backed engine** — and the teeth are already real: 90.1% pass@1 on XBEN, 8/10 held-out post-cutoff CVEs pinned to exact file/line/CWE, and a coordinated-disclosure pipeline that's live enough to have drafts held for vendor coordination right now. What's *not* proven is the swarm. Each downstream operator — Exploiter, Infiltrator, Exfiltrator, Ghost — runs the **same real, tool-backed ReAct loop as recon** (real exploit tools, not stubs), but the headline numbers came from a single agent, not the coordinated 8-operator cell, and end-to-end swarm exploitation is unbenchmarked and still unreliable. The engine is real; the swarm is the part still earning its stripes. Loud where we've earned it, blunt about the rest.\n\n| Component | Status | Notes |\n|---|---|---|\n| Re-derivable measurement (`verify-claims`) | ✅ Stable | every headline recomputes from committed artifacts |\n| Recon engine | ✅ Stable | drives nmap / DNS / HTTP / fingerprinting; every finding traces to real tool output |\n| Mission engine + War Room + Op Admiral | ✅ Stable | keyless through a connected local agent |\n| Arsenal, MCP server, HTTP API | ✅ Stable | 35 built-in tools by default; 83 with the opt-in `T3MP3ST_FULL_ARSENAL` (+48 adapters, with the dangerous post-ex drivers — metasploit, hydra — behind a human-approval gate) — both counts re-derive via `verify-claims`. `security_recon` over MCP |\n| Egress-scope containment | ✅ Stable (on by default) | once a mission target is set, built-in networked tools refuse off-scope public hosts — not the target/subdomains, not loopback/private (`SCOPE DENIED`) — a tightened default, not a bare tool runner |\n| Coordinated-disclosure pipeline | ✅ Stable | OSV novelty + live PoC + refuter panel + CVSS; drafts only, a human sends |\n| White-box source analysis | ⚠️ Experimental | Python-only regex ingest; multi-model decomposition costs more tokens, not fewer |\n| DeFi (Damn Vulnerable DeFi) | ⚠️ Experimental | reproduces known exploit classes; not novel discovery |\n| Exploiter / Infiltrator / Exfiltrator / Ghost | ⚠️ Experimental | run the real tool-backed ReAct loop (same engine as recon); unproven as a coordinated swarm — single-agent is the benchmarked path, live swarm exploitation still unreliable |\n| Advanced modules (cloud, persistence, swarm, cognition) | 🚧 Planned | interface-only in `src/stubs/` |\n| Self-improvement loop | 🧪 Research | records lessons + proposals today; feeding them back into planning is roadmap |\n\nFull feature-by-feature breakdown: [FEATURES.md](FEATURES.md).\n\n## Coverage by domain\n\nWhere the storm reaches today — and where it's headed. Same discipline as everything else: a domain is ✅ only when there's a receipt behind it.\n\n| Domain | What it covers | Status |\n|---|---|---|\n| 🕸️ **Web** | apps, APIs, auth flows, OWASP Top 10 | ✅ **Core** — XBEN 90.1% pass@1 |\n| 📂 **Code** | white-box source audits, SAST-style vuln hunting | ✅ **Proven (hunt result)** — held-out CVE-Zero: single-agent 8/10 exact file/line/CWE, 10/10 found (7 languages); the repo-ingest *engine* itself is still ⚠️ experimental |\n| 🚩 **CTF** | wargames, practice ranges, challenges | ✅ **Proven** — Cybench 23/40 hint-free |\n| 🔌 **Network / Infra** | recon, service/stack fingerprinting; lateral + privesc | ✅ recon (live nmap/DNS/HTTP engine) · ⚠️ lateral/privesc experimental |\n| 🤖 **Embedded / IoT / OT** | firmware, robotics, ICS/SCADA OSS | ✅ **CVE pipeline live** — coordinated-disclosure drafts held for vendors |\n| 📦 **Supply chain** | dependency audits, install-without-confirmation | ⚠️ **Real** — dedicated class; hit a CWE-829 on the held-out set |\n| 💰 **Blockchain** | smart contracts, DeFi, Solidity | ⚠️ **Reproduction only** — Damn Vulnerable DeFi, not novel discovery |\n| ☁️ **Cloud** | AWS/GCP/Azure misconfig, IAM, serverless | 🚧 **In development** |\n| 📱 **Mobile** | Android/iOS app security | 🚧 **In development** |\n| 🏢 **Identity / AD** | Kerberos, pass-the-hash, AD attacks | 🚧 **In development** |\n| 🔐 **Binary / RE** | overflows, ROP, exploit dev | 🚧 **In development** — needs specialized tooling |\n\nThe class/squad architecture means new domains *compose* rather than fork — each is a loadout (specialist classes + arsenal + target adapter + a benchmark). 🚧 domains ship dark until they have a number.\n\n## Benchmarks\n\nHeadline results. Each recomputes from the committed JSON with `npm run verify-claims`; full methodology and caveats are in the linked docs.\n\n| Suite | Result | Context |\n|---|---|---|\n| **XBEN** — XBOW's 104-challenge suite, black-box | **pass@1 mean 90.1%** (Wilson-95 86.2–92.9), floor 91/104 · gpt-5.5 | XBOW self-reports 85% on the same suite; ours re-derives the graded verdict from committed artifacts (raw transcripts stripped for privacy) |\n| **XBEN** — white-box (reported separately) | pass@1 98.7%, best-ball 104/104 · gpt-5.5 | never blended with the black-box number |\n| **Cybench** — 40-task academic bench, Opus 4.8, no hints | **23/40 (58%) hint-free, single-run pass@1** (`verify-claims`-enforced) | not the raw-score record (Anthropic: 76.5% pass@10); every flag graded against the committed oracle |\n| **CVE-Zero** — 10 real post-cutoff (2026) CVEs, **held-out**, 7 languages | **single-agent 8/10 exact file/line/CWE** (verified all-exact, stable) · **10/10 found** (full pack) | **memorization- \u0026 fitting-proof**: post-cutoff, and the hardened prompts were never tuned on these; `verify-claims` recomputes it. n=10, directional; the swarm's edge here is recall, not a coordination-beats-solo proof |\n\n**How to read these:**\n\n- Every solved flag is graded against a committed ground-truth oracle — not a self-report — and `verify-claims` recomputes the pass/fail. Raw per-step transcripts are stripped for operator privacy, so you re-check the **graded verdict**, not the raw tool output. Zero fabricated, enforced by an anti-fitting guard that runs on every push.\n- Black-box (source withheld) and white-box (source staged) are reported separately and never blended.\n- These ran a **single-agent ReAct loop, not the 8-operator swarm.** The swarm is framework architecture; it is not what scored these numbers.\n- Results are system-vs-system: this harness driving a strong current model, not an isolated-harness claim.\n\nThe number isn't the flex — the **receipt** is. A keyless, open-source harness that hands you the re-run instead of asking you to trust it: clone it, run `npm run verify-claims`, and every verdict above recomputes from its committed oracle in front of you.\n\nDeeper reading: [WALL_FORENSICS](docs/WALL_FORENSICS.md) (per-challenge misses), [CYBENCH](docs/CYBENCH.md), [INTEGRITY_LEDGER](docs/INTEGRITY_LEDGER.md) (contamination audit and every retraction), [OBSIDIVM](docs/OBSIDIVM.md) (our own live web range).\n\n## Documentation\n\n| Doc | Contents |\n|---|---|\n| [FEATURES.md](FEATURES.md) | feature-by-feature status (`[x]` shipped / `[~]` partial / `[ ]` planned) |\n| [SCOPE_AND_AUTHORIZATION](docs/SCOPE_AND_AUTHORIZATION.md) | authority model, scope receipts, evidence and retest rules |\n| [VERIFIED_PROVENANCE](docs/VERIFIED_PROVENANCE.md) | how findings become tool-proven instead of model-asserted |\n| [TEAM_PREVIEW](docs/TEAM_PREVIEW.md) | first-run path and review script |\n| [INSTALL_MATRIX](docs/INSTALL_MATRIX.md) | macOS / Linux readiness table |\n| [ARSENAL_ACTIVATION_PLAN](docs/ARSENAL_ACTIVATION_PLAN.md) | optional external-tool setup |\n| [CYBENCH](docs/CYBENCH.md) · [WALL_FORENSICS](docs/WALL_FORENSICS.md) · [INTEGRITY_LEDGER](docs/INTEGRITY_LEDGER.md) · [COGNITIVE_ARCHITECTURE](docs/COGNITIVE_ARCHITECTURE.md) | benchmark methodology |\n| [RELEASE_CHECKLIST](docs/RELEASE_CHECKLIST.md) | the gates a release must pass |\n\n## Architecture\n\n```\n┌─────────────────────────────────────────────────────────────────┐\n│                        T3MP3ST COMMAND                          │\n├─────────────────────────────────────────────────────────────────┤\n│   MISSION CONTROL  ◄──  TARGET MODEL  ──►  ARSENAL (TOOLS)       │\n│                          ▲                                       │\n│   AGENT CELL:  RECON · SCANNER · EXPLOITER · INFILTRATOR ·       │\n│                EXFILTRATOR · GHOST · COORDINATOR · ANALYST       │\n│                          ▲                                       │\n│   EVIDENCE VAULT  ·  CREDENTIAL STORE  ·  FINDINGS LEDGER        │\n│                          ▲                                       │\n│   OPSEC LAYER  ·  COMMS CHANNEL  ·  LLM BACKBONE                 │\n└─────────────────────────────────────────────────────────────────┘\n```\n\nOperators map to MITRE ATT\u0026CK and Cyber Kill Chain phases (recon is live; later phases are scaffolded):\n\n| Operator | Phase | MITRE | Function |\n|---|---|---|---|\n| **Recon** | Reconnaissance | TA0043 | OSINT, network discovery, asset enumeration |\n| **Scanner** | Discovery | TA0007 | vulnerability scanning, service fingerprinting |\n| **Exploiter** | Initial Access | TA0001 | exploitation, payload delivery |\n| **Infiltrator** | Lateral Movement | TA0008 | post-exploitation, privilege escalation |\n| **Exfiltrator** | Collection / Exfil | TA0009/10 | data extraction, credential harvesting |\n| **Ghost** | Persistence | TA0003 | persistence, stealth, cleanup |\n| **Coordinator** | Command \u0026 Control | TA0011 | mission control, orchestration |\n| **Analyst** | Analysis | — | pattern analysis, reporting |\n\n**Providers:** OpenRouter, Venice, Anthropic, OpenAI, or a keyless local agent (Claude Code / Codex / Hermes). Set `OPENROUTER_API_KEY` / `VENICE_API_KEY` / `ANTHROPIC_API_KEY`, or connect an agent in Settings.\n\n**Integrations:** `node dist/mcp-server.js` exposes `security_recon` to MCP-aware agents. `npm run server` starts the HTTP API (`POST /api/mission/start`, `GET /api/mission/status`, and more). Full reference in [docs/](docs/).\n\n## Contributing — join the swarm\n\nRed-teaming shouldn't be a priesthood. Bring an adapter, a prompt pack, a runbook, a new arsenal tool, or a bug report.\n\n**One rule, non-negotiable:** everything here is for **authorized testing only**. Owned, scoped, or consenting targets. Build for defenders, or don't build it here.\n\n1. Fork it, branch it.\n2. Open a PR with tests. If you touch a headline number, `npm run verify-claims` has to stay green.\n\nRelease process and gates: [RELEASE_CHECKLIST](docs/RELEASE_CHECKLIST.md).\n\n## License\n\nAGPL-3.0. See [LICENSE](LICENSE).\n\n---\n\n\u003cdiv align=\"center\"\u003e\n\n*Fortes fortuna iuvat* — fortune favors the bold.\n\n⊰•-•✧ LOVE PLINY ✧•-•⊱ 🌩️\n\n\u003c/div\u003e\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Felder-plinius%2FT3MP3ST","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Felder-plinius%2FT3MP3ST","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Felder-plinius%2FT3MP3ST/lists"}