hermes-agent

Pass

Audited by Gen Agent Trust Hub on Apr 24, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions to extend its functionality by installing the @better-openclaw/mcp package from the npm registry using the npx command. This is part of the documented setup for adding MCP capabilities.
  • [PROMPT_INJECTION]: The skill exposes an indirect prompt injection surface through its webhook receiver and chat API. (1) Ingestion points: External data enters via the webhook receiver on port 8644 and the Chat Completions API endpoints in SKILL.md. (2) Boundary markers: No explicit delimiters or ignore-instructions markers are documented for processed inputs. (3) Capability inventory: The agent can perform sensitive actions such as generating Docker infrastructure using the generate-stack tool. (4) Sanitization: The documentation does not specify sanitization or validation routines for external data processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 24, 2026, 07:39 AM
Security Audit — agent-trust-hub — hermes-agent