hermes-agent

Warn

Audited by Socket on May 10, 2026

1 alert found:

Anomaly
AnomalyLOW
references/getting-started/installation.md

No direct malicious code is shown in this documentation fragment. However, it instructs users to execute a network-fetched installer script immediately via a curl|bash pipeline, which is a high-impact supply-chain execution pattern. Because secrets are configured in ~/.hermes/.env and multiple dependencies/integration extras are installed, the blast radius of a compromised installer or dependency could be substantial. Integrity verification (pinned revision, checksum/signature validation) and inspection of scripts/install.sh and installed package sources are recommended before trusting this install method.

Confidence: 56%Severity: 68%
Audit Metadata
Analyzed At
May 10, 2026, 04:08 PM
Package URL
pkg:socket/skills-sh/Fandhe-AI%2Fagent-reference-skills%2Fhermes-agent%2F@580efda50d026701322b6245560d385e95f62512
Security Audit — socket — hermes-agent