nemoclaw-contributor-update-hermes
Warn
Audited by Snyk on Aug 1, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (low risk: 0.10). The skill “Update Hermes” reads outsider-authored free text at runtime by ingesting GitHub release and tag-ref JSON fetched from
NousResearch/hermes-agentvia thegh api ... /releasesand... /git/matching-refs/tags/...endpoints, then parsing their record fields (including tag and metadata) inscripts/collect-hermes-release-supplement.py.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata