Back to skill

Security audit

Hermes Tweet

Security checks for vulnerabilities and agentic risk

Overview

The skill is transparent about X/Twitter reads and approval-gated actions, but its install step enables an unpinned external plugin that may later run with Xquik API and account-action privileges.

Review and pin the exact Hermes Tweet plugin version before enabling it, keep HERMES_TWEET_ENABLE_ACTIONS off unless needed, and approve only specific X account-changing operations after checking the endpoint, payload, account, and side effects.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:90
Finding

Unpinned External Plugin Installation Creates a Supply-Chain Risk

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 90–92
Vulnerability Type: Unpinned third-party executable dependency
Risk Level: Medium

Vulnerable Code

markdown
- Install and enable the plugin with
  `hermes plugins install Xquik-dev/hermes-tweet --enable`.

Technical Analysis

The skill instructs users to retrieve and immediately enable the external Xquik-dev/hermes-tweet plugin without specifying an immutable version, commit hash, checksum, or trusted signature. Consequently, the code installed later may differ from the code that was originally reviewed.

The external plugin is not included in the audited project, so its implementation and integrity cannot be verified from this artifact. Enabling it immediately after retrieval expands the supply-chain exposure because downloaded plugin code may execute within Hermes with access to configured network and tool capabilities.

This is an insecure dependency practice rather than evidence that the current upstream plugin is malicious.

Attack Path

  1. An attacker compromises the upstream repository, its distribution mechanism, or a maintainer account.
  2. The attacker modifies the plugin revision resolved by the unpinned repository reference.
  3. A user follows the documented installation command.
  4. Hermes downloads the changed plugin and enables it immediately through --enable.
  5. The altered plugin executes in the Hermes runtime.
  6. Depending on runtime configuration, it may gain access to authenticated Xquik reads and approved action capabilities.

Impact Assessment

A compromised plugin could operate within the privileges granted to the Hermes plugin runtime. The potential scope includes:

  • Access to authenticated Xquik API functionality when XQUIK_API_KEY is configured.
  • Unauthorized observation or manipulation of data handled by plugin tools.
  • Abuse of X account or workflow operations when action tooling is enabled.
  • Compromise of the confidentiality and ...[truncated 227 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin installation to an immutable, reviewed release or commit rather than a mutable repository reference.
  2. Publish and verify a cryptographic checksum or signature for the exact plugin artifact before enabling it.
  3. Separate installation from activation so integrity and provenance checks occur before plugin code is loaded.
  4. Record the reviewed plugin version and source commit in SKILL.md.
  5. Prefer a trusted package registry with immutable releases and provenance attestations.
  6. Vendor the reviewed plugin when practical, or include it in the audit scope.
  7. Retain the existing least-privilege controls: keep action tooling disabled by default, require explicit per-operation approval, and limit runtime credentials and network permissions.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.