ClawAudit verdict
Hermes Agent
hermes-agent-skill
45
🟠 Risky
Significant concerns — only install if you understand the risks
The skill provides突触式多智能体调度 + 主动记忆洞察 + GEPA 技能自进化, and executes processes, but does not exhibit any clearly malicious behavior.
⚠ Flagged for review — coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis — not a human review. ClawAudit flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
98
security
100
transparency
90
maintenance
Findings (1)
Pattern match low
Python os.environ.get — reads environment variable
hermes_config.py · prose · downgraded · os.environ.get(
Permissions & capabilities
No declared permissions — minimal attack surface.
process_exec Is this flag fair?
Thanks — recorded.