awesome-hermes-agent-ecosystem
Warn
Audited by Socket on May 17, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the stated purpose is ecosystem guidance, but the skill goes beyond reference material by encouraging extensive installation of third-party skills and tools from many unrelated GitHub owners, plus broad credential setup and autonomous workflows. I do not see confirmed malware or overt exfiltration, but the transitive trust chain and disproportionate operational footprint make this a high security-risk skill.
Confidence: 89%Severity: 81%
Audit Metadata