hermes-environment-migration

Pass

Audited by Gen Agent Trust Hub on Jul 25, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill provides explicit instructions to treat all inspected content as untrusted evidence and to ignore any embedded instructions. It mandates that prompt injection attempts be recorded as findings rather than executed.
  • [DATA_EXFILTRATION]: The safety contract explicitly forbids the inclusion of secrets or credentials in migration archives. It identifies sensitive file paths and mandates that secrets be handled via separate secure channels.
  • [COMMAND_EXECUTION]: Installation instructions use standard, non-privileged file operations. The skill enforces a planning-only default state, requiring explicit user approval before any file writes or system mutations occur.
  • [REMOTE_CODE_EXECUTION]: The skill's validation and test scripts utilize only the Python standard library. No third-party dependencies are required, and no remote code download or execution patterns were identified.
  • [SAFE]: The skill implements strong security boundaries, evidence-based reporting requirements, and automated checks to prevent the accidental inclusion of sensitive information.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 25, 2026, 07:07 PM
Security Audit — agent-trust-hub — hermes-environment-migration