hermes-agent-optimization

Warn

Audited by Socket on May 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. Most content is legitimate Hermes administration guidance, but the trust model is weak: a raw GitHub bootstrap script from a different publisher runs as root, and unpinned external MCP tools receive sensitive credentials. Combined with broad autonomous action surfaces and untrusted inbound content, the skill is high risk even without clear evidence of confirmed malware.

Confidence: 88%Severity: 84%
Audit Metadata
Analyzed At
May 18, 2026, 03:10 AM
Package URL
pkg:socket/skills-sh/Aradotso%2Fhermes-skills%2Fhermes-agent-optimization%2F@730c398d14ff4a4b96d2ec6246b5cebf7980fc62
Security Audit — socket — hermes-agent-optimization