Back to skill

Security audit

Hermes Control

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only skill for administering Hermes Agent; it covers powerful commands, but the behavior is disclosed and aligned with its stated purpose.

Install this only if you want an agent to help administer Hermes. Treat commands involving --yolo, approvals.mode off, session/profile deletion, cron jobs, gateway services, webhooks, credentials, and /debug uploads as sensitive: review them before running and avoid approval bypass outside controlled environments.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The skill description is extremely broad ('complete control' of Hermes Agent) and keyed to generic Hermes-related terms, which increases the chance of the skill being auto-invoked for benign informational requests. Because the skill includes high-risk operations such as approval bypass, tool enablement, gateway control, and destructive state changes, overbroad activation materially raises the chance of unsafe guidance being surfaced in the wrong context.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
This section documents approval-bypass features like '--yolo', '/yolo', and approvals.mode off without prominent safety warnings or strong guardrails. In a skill whose purpose is to automate full agent control, normalizing confirmation bypass makes accidental or unauthorized execution of sensitive commands more likely, especially when paired with terminal, browser, messaging, and multi-agent capabilities.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The skill lists destructive commands such as deleting sessions, uninstalling software, removing webhooks, deleting profiles, and removing cron jobs without clearly flagging irreversibility or data-loss risk. In an automation-focused skill, omission of warnings increases the likelihood that operators or downstream agents invoke these commands casually or embed them into scripts without understanding the consequences.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The '/debug' command is described as uploading system information and logs to obtain a shareable link, but the skill does not warn about potential disclosure of sensitive data contained in logs, environment-derived values, filenames, host metadata, or conversation traces. Because Hermes manages credentials, sessions, gateways, and automation state, debug bundles can contain highly sensitive operational context.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.