hermes-studio-dashboard

Pass

Audited by Gen Agent Trust Hub on Jun 14, 2026

Risk Level: SAFECOMMAND_EXECUTIONCREDENTIALS_UNSAFEEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill documents a Web Terminal feature that allows users to create terminal sessions and execute arbitrary shell commands on the host machine using Socket.IO.
  • [COMMAND_EXECUTION]: Includes a "Scheduled Jobs" feature that enables the execution of agent tasks according to user-defined cron expressions.
  • [CREDENTIALS_UNSAFE]: Discloses default administrative credentials ("admin/123456") and provides instructions for managing sensitive platform tokens (Telegram, Discord, Slack) within environment files.
  • [EXTERNAL_DOWNLOADS]: Provides links to download native binary installers from GitHub and instructs users to install a CLI package via the public NPM registry.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 14, 2026, 08:46 AM
Security Audit — agent-trust-hub — hermes-studio-dashboard