hermes-studio-dashboard
Pass
Audited by Gen Agent Trust Hub on Jun 14, 2026
Risk Level: SAFECOMMAND_EXECUTIONCREDENTIALS_UNSAFEEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill documents a Web Terminal feature that allows users to create terminal sessions and execute arbitrary shell commands on the host machine using Socket.IO.
- [COMMAND_EXECUTION]: Includes a "Scheduled Jobs" feature that enables the execution of agent tasks according to user-defined cron expressions.
- [CREDENTIALS_UNSAFE]: Discloses default administrative credentials ("admin/123456") and provides instructions for managing sensitive platform tokens (Telegram, Discord, Slack) within environment files.
- [EXTERNAL_DOWNLOADS]: Provides links to download native binary installers from GitHub and instructs users to install a CLI package via the public NPM registry.
Audit Metadata