hermes-desktop-os1-native-macos-client

Warn

Audited by Socket on May 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is largely coherent with its stated remote-desktop/agent-management purpose and uses mostly official Orgo/OpenAI endpoints, but it has a broad operational footprint: remote command execution, file/session access, websocket terminals, SSH fallback, and optional model-driven shell/admin actions. The main concerns are third-party distribution trust, credential forwarding to runtime-installed tooling, and high-impact autonomous capabilities rather than clear malicious intent.

Confidence: 82%Severity: 72%
Audit Metadata
Analyzed At
May 16, 2026, 06:51 PM
Package URL
pkg:socket/skills-sh/Aradotso%2Fhermes-skills%2Fhermes-desktop-os1-native-macos-client%2F@bae729ee9371c37fdcddce6b4d1e1011c74be983
Security Audit — socket — hermes-desktop-os1-native-macos-client