hermes-war-room-ui

Warn

Audited by Socket on May 17, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is largely coherent with its stated purpose as a local Hermes orchestration UI, and its reads of ~/.hermes plus hermes CLI control are proportionate. The main concerns are install trust for a GitHub release binary tied to a different stated publisher identity, a documented shell-out pattern that may permit command injection if copied literally, and elevated autonomy from multi-agent orchestration with broad worker tools. No clear malicious exfiltration or deceptive credential harvesting is evident from the provided skill text.

Confidence: 80%Severity: 59%
Audit Metadata
Analyzed At
May 17, 2026, 06:24 PM
Package URL
pkg:socket/skills-sh/Aradotso%2Fhermes-skills%2Fhermes-war-room-ui%2F@8feebd719b92cc1c6c08188fb3e683530a2a5af0
Security Audit — socket — hermes-war-room-ui