hermes-forge

Pass

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill facilitates interaction with the local environment exclusively through the forge CLI tools (forge orient, forge recap, forge comment, forge update, forge create). These commands are used to synchronize state and record evidence within the project repository.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from project files and issue trackers via the forge CLI. To mitigate the risk of processing untrusted content, the skill mandates the use of a deterministic JSON envelope and requires the agent to cite the provenance (file path, authority level, and source role) for every piece of information surfaced from the project.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 5, 2026, 10:07 AM
Security Audit — agent-trust-hub — hermes-forge