byreal-hermes-deploy-native
Warn
Audited by Socket on May 20, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill is largely coherent with a Hermes deployment task, and its main external sources are official projects, but its footprint is broader than the stated 'only input is a new Telegram Bot Token.' It reads local API credentials, copies memory and other skills into the new agent, and launches a persistent Telegram-facing service. The strongest security issue is supply-chain hygiene: the core Hermes repo is pulled from official GitHub but left on moving `main` instead of a reviewed commit, so the deployed agent is not reproducibly pinned.
Confidence: 89%Severity: 72%
Audit Metadata