hermes-integration

Pass

Audited by Gen Agent Trust Hub on Apr 18, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONDATA_EXFILTRATIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill presents an indirect prompt injection surface by providing tools to read and process content from external messaging platforms. • Ingestion points: External data enters the agent context via the messages_read and attachments_fetch tools described in SKILL.md. • Boundary markers: No explicit instructions or delimiters are provided to ensure the agent ignores or sanitizes instructions embedded in the external content. • Capability inventory: The skill possesses capabilities to send messages to external platforms and execute commands via the hermes CLI (SKILL.md). • Sanitization: There is no mention of sanitizing or validating content retrieved from external sources.
  • [COMMAND_EXECUTION]: The skill instructions direct the agent to utilize the hermes CLI for managing tasks, checking system status, and starting interactive sessions (e.g., hermes chat, hermes status, hermes cron).
  • [DATA_EXFILTRATION]: The messages_send tool provides a mechanism for the agent to transmit data from its environment to external platforms including Telegram, Discord, and Slack.
  • [EXTERNAL_DOWNLOADS]: The attachments_fetch tool enables the agent to retrieve external files and data from third-party messaging services.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 18, 2026, 12:07 PM
Security Audit — agent-trust-hub — hermes-integration