prompt-hermes-ai
Warn
Audited by Socket on Jul 14, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. Most of the Hermes orchestration guidance matches the stated control-plane purpose, but the chrome-sync workflow is disproportionately risky: it downloads and runs an external CLI, then forwards browser-session bearer cookies to a third-party tenant endpoint rather than using official APIs. That data flow is coherent with remote-browser enablement, yet still creates a high security risk and a strong credential-harvesting/exfiltration concern.
Confidence: 90%Severity: 86%
Audit Metadata