agentiko-hermes
Warn
Audited by Socket on Jul 9, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill is internally consistent as a Hermes operations guide, but its actual footprint is a high-risk offensive automation playbook. Same-org Hermes provenance reduces supply-chain concern, yet the skill materially increases risk by enabling autonomous scans, disabling approval gates, and guiding red-team activity through an SSH worker and scheduled jobs. Not confirmed malware, but dangerous by design for an AI agent.
Confidence: 92%Severity: 86%
Audit Metadata