Back to skill

Security audit

Hermes For Win

Security checks across malware telemetry and agentic risk

Overview

This skill is a Windows installer guide for Hermes, but it asks users to rely on privileged startup, background, update, and uninstall scripts that are not included in the reviewed package.

Treat this as Review, not proof of malware. Install only if you separately inspect and trust the PowerShell scripts from the claimed source, understand the scheduled task it creates, know where API keys will be stored, and are comfortable with background persistence and update behavior. Back up any Hermes data before using the reinstall or uninstall commands.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill advertises automatic startup, background persistence, and automatic updates as convenience features without clearly warning about their security and system-control implications. In an agent-installation context, these behaviors materially affect persistence, execution trust, and update-chain risk, so omission of consent and safety guidance can lead users to enable privileged, long-lived software without informed approval.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The README includes forceful administrative commands such as killing processes, unregistering scheduled tasks, and recursively deleting the installation directory, but it does not clearly warn users that these actions are destructive and may be irreversible. In this Windows admin/install context, users are likely to copy-paste commands directly, so missing safety guidance increases the risk of accidental service disruption, data loss, or deletion of the wrong target if variables or paths are modified.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.