agentiko-hermes

Warn

Audited by Socket on Jul 9, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally consistent as a Hermes operations guide, but its actual footprint is a high-risk offensive automation playbook. Same-org Hermes provenance reduces supply-chain concern, yet the skill materially increases risk by enabling autonomous scans, disabling approval gates, and guiding red-team activity through an SSH worker and scheduled jobs. Not confirmed malware, but dangerous by design for an AI agent.

Confidence: 92%Severity: 86%
Audit Metadata
Analyzed At
Jul 9, 2026, 06:46 AM
Package URL
pkg:socket/skills-sh/uphiago%2Frecon-skills%2Fagentiko-hermes%2F@6ca3b4e30f97d9415d13abd13e25c898b2f6a6a6c0f7a49a16f5fdd3b8d5d8d4
Security Audit — socket — agentiko-hermes