prompt-hermes-ai

Warn

Audited by Socket on Jul 14, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. Most of the Hermes orchestration guidance matches the stated control-plane purpose, but the chrome-sync workflow is disproportionately risky: it downloads and runs an external CLI, then forwards browser-session bearer cookies to a third-party tenant endpoint rather than using official APIs. That data flow is coherent with remote-browser enablement, yet still creates a high security risk and a strong credential-harvesting/exfiltration concern.

Confidence: 90%Severity: 86%
Audit Metadata
Analyzed At
Jul 14, 2026, 04:23 PM
Package URL
pkg:socket/skills-sh/dzianisv%2Fskills%2Fprompt-hermes-ai%2F@bae93260e81d4b5d970f772f6f4ec9de809bd4367481337a199d74563b84e712
Security Audit — socket — prompt-hermes-ai