Security, sandboxing and guardrails for Hermes Agent
An agent that runs shell commands needs boundaries. These projects audit, sandbox, monitor and restrict Hermes Agent and similar agents, on top of Hermes's own command approvals, file write denylist and container backends.
Top 12 security by GitHub stars
Reference stack for running Hermes, OpenClaw and LangChain Deep Agents inside NVIDIA OpenShell sandboxes
Dicklesworthstone Destructive Command Guard (dcg)Hook that blocks dangerous git and shell commands before AI coding agents run them
lennney Stop That ShitHook and skill guard that stops AI coding agents from unrequested checksums and scope creep
LoRexxar KunLun-MOpen-source static code security scanner with a built-in skill for AI agents including Hermes
Infisical Agent VaultHTTP credential proxy and vault that keeps real API keys away from AI agents such as Hermes
kenryu42 CC Safety NetGuard that blocks destructive Git and file commands and secret access before a coding agent runs them
prompt-security ClawSecSecurity skill suite with signed advisories and drift detection for OpenClaw, Hermes and related agents
SafeAI-Lab-X ClawKeeperHost-agnostic safety middleware that blocks risky agent tool calls and redacts sensitive tool results
Zyrexnn CybermesSecurity assistant framework for authorized bug bounty work, with an MCP server and Hermes Agent support
EXboys EvotownSelf-hosted control plane for governing OpenClaw, Hermes and SkillLite agents across a company
vivekchand ClawMetryLocal dashboard that reads agent session files to show timelines, tool calls and token costs
runta-dev ClawShellLocal proxy that swaps virtual API keys for real ones and scans traffic for PII, for OpenClaw and Hermes
All 48 security repos
Click a column to sort| NVIDIA/NemoClawReference stack for running Hermes, OpenClaw and LangChain Deep Agents inside NVIDIA OpenShell sandboxes | TypeScript | 22,690 | Oct 10, 2026 |
| Dicklesworthstone/destructive_command_guardHook that blocks dangerous git and shell commands before AI coding agents run them | Rust | 6,125 | Oct 10, 2026 |
| lennney/stop-that-shitHook and skill guard that stops AI coding agents from unrequested checksums and scope creep | JavaScript | 2,527 | Oct 7, 2026 |
| LoRexxar/Kunlun-MOpen-source static code security scanner with a built-in skill for AI agents including Hermes | Python | 2,416 | Oct 10, 2026 |
| Infisical/agent-vaultHTTP credential proxy and vault that keeps real API keys away from AI agents such as Hermes | Go | 2,332 | Oct 4, 2026 |
| kenryu42/cc-safety-netGuard that blocks destructive Git and file commands and secret access before a coding agent runs them | TypeScript | 1,582 | Oct 10, 2026 |
| prompt-security/clawsecSecurity skill suite with signed advisories and drift detection for OpenClaw, Hermes and related agents | JavaScript | 1,117 | Oct 10, 2026 |
| SafeAI-Lab-X/ClawKeeperHost-agnostic safety middleware that blocks risky agent tool calls and redacts sensitive tool results | TypeScript | 1,024 | Aug 17, 2026 |
| Zyrexnn/CybermesSecurity assistant framework for authorized bug bounty work, with an MCP server and Hermes Agent support | Python | 928 | Oct 2, 2026 |
| EXboys/evotownSelf-hosted control plane for governing OpenClaw, Hermes and SkillLite agents across a company | Python | 647 | Sep 14, 2026 |
| vivekchand/clawmetryLocal dashboard that reads agent session files to show timelines, tool calls and token costs | Python | 426 | Oct 8, 2026 |
| runta-dev/clawshellLocal proxy that swaps virtual API keys for real ones and scans traffic for PII, for OpenClaw and Hermes | Rust | 346 | Jul 13, 2026 |
| 0xNyk/lacpLocal policy, approval and recovery controls that wrap CLI coding agents such as Claude, Codex and Hermes | Shell | 305 | Sep 22, 2026 |
| asimons81/hermes-vaultLocal-first credential broker, secret scanner and encrypted vault for Hermes agents | Python | 278 | Sep 14, 2026 |
| 78/tenboxLightweight virtual machine monitor for running OpenClaw, QwenPaw and Hermes Agent in isolation | C++ | 257 | Sep 17, 2026 |
| nativ3ai/hermes-agent-camelHermes Agent fork with an opt-in CaMeL-style guard against indirect prompt injection | Python | 193 | May 7, 2026 |
| XSafeAI/XSafeClawOpen-source agent safety platform that monitors and guards OpenClaw, Hermes and Nanobot sessions | Python | 164 | Jul 10, 2026 |
| Strategic-Automation/violinSupervised Hermes pentest profile with guarded execution and evidence-backed reporting | Python | 148 | Oct 9, 2026 |
| x-glacier/kali-pentestKali Linux pentest skill that plans, runs and adapts attacks with approval gates | — | 138 | Jun 25, 2026 |
| agentrhq/authsomeCredential gateway that logs in once via OAuth2 or API key and keeps AI agents authenticated | Python | 96 | Jul 24, 2026 |
| mturac/promptguardOffline prompt auditor with a pre-write guard for Hermes, Claude Code, Codex, OpenCode and OpenClaw | Python | 76 | Jul 22, 2026 |
| TheAiSingularity/hermesclawRun Hermes Agent inside NVIDIA OpenShell with enforced network, filesystem and syscall limits | Shell | 73 | Apr 24, 2026 |
| claudlos/hermes-katanaSecurity layer for Hermes Agent with taint tracking, a policy engine and outbound secret scrubbing | Python | 49 | Oct 5, 2026 |
| danieljustus/symaira-vaultGo command-line password manager with age encryption and an MCP server for AI agents | Go | 31 | Oct 9, 2026 |
| swytchcodehq/agent-install-monitorLocal history of every package, Docker image and repository your Hermes Agent installs | Python | 31 | Jul 10, 2026 |
| Adolanium/hermes-plugin-shodanShodan host intel, search, DNS and CVE lookups for Hermes Agent, with credit budgeting | Python | 28 | Sep 12, 2026 |
| skalenetwork/microsandbox-reefRun Hermes, OpenClaw and your own agents in microsandbox microVMs with TOML-defined policy | Rust | 25 | Oct 8, 2026 |
| aiconnai/agentshieldOffline Rust scanner for risky behavior in MCP servers and agent tools, with a Hermes Agent adapter | Rust | 20 | Sep 14, 2026 |
| anpicasso/hermes-jev-approvalsPlugin that serves TypeSafe's Jev model as the reviewer for Hermes Agent smart command approvals | Python | 19 | Sep 22, 2026 |
| Deconstruct2021/hermes-bumblebee-bridgeDaily read-only supply-chain scans for a Hermes Agent host using Perplexity's Bumblebee | Shell | 18 | May 24, 2026 |
| nativ3ai/hermes-payguardSafe-by-design USDC and x402 payment plugin for Hermes Agent with human approval for larger transfers | Python | 14 | Mar 20, 2026 |
| pawel-cell/agent-shopping-safe-checkoutSafe-checkout pattern for agents that buy online: isolated Chrome, virtual card and a human approval gate | — | 14 | May 13, 2026 |
| jayelbotvibe-web/hermes-pentest-labKali-native pentesting lab with an MCP tool server, guardrails enforced in code and PDF reports | Python | 13 | Aug 25, 2026 |
| Tranquil-Flow/hermes-aegisSecurity layer for Hermes Agent: a MITM proxy that blocks secret leaks and dangerous commands | Python | 13 | May 19, 2026 |
| MahdiHedhli/HermesUltraCodeHermes plugin that has a second-lab model review each task before a subagent starts writing code | Python | 11 | Jul 29, 2026 |
| intentframe/agent-integrationsIntentFrame security plugin that checks Hermes terminal, code, file and cron tool calls against policy | Python | 11 | Jun 28, 2026 |
| mauricemohr88-debug/hermes-plugin-guardStatic security scanner for Hermes Agent plugins that never imports or runs the plugin code | Python | 10 | Aug 31, 2026 |
| wnstify/hermes-agentHardened Docker Compose and SSH sandbox patterns for self-hosting Hermes Agent with Honcho | Shell | 10 | May 23, 2026 |
| aibuild-lab/skills-guardThreat scanner and trust matrix for AI skill files, ported from Hermes Agent's skills_guard | Python | 10 | Sep 2, 2026 |
| 0xtbug/RecatLocal workspace for reviewing security findings reported by Hermes and other agents | TypeScript | 10 | Sep 27, 2026 |
| jooray/hermes-firewallPrompt-injection gate plugin that scans web, MCP, email and image content before Hermes Agent sees it | Python | 10 | Oct 8, 2026 |
| TanKimGwan/linmasProof-carrying defensive security reviews for AI-assisted code with deterministic policy and portable evidence | JavaScript | 2 | Oct 2, 2026 |
| nordicnode/model-sherpaHermes Agent plugin that repairs bad tool calls, breaks tool loops and redacts secrets from logs | Python | 1 | Jul 6, 2026 |
| dafka007/hermes-security-auditApproval-gated Hermes plugin that runs Gitleaks, OSV-Scanner and Semgrep CE on a workspace | Python | 1 | Sep 18, 2026 |
| chchchadzilla/github-safe-pushHermes skill that keeps secrets out of git and checks a project is properly packaged before shipping | Python | 1 | Aug 14, 2026 |
| xielevi/hermes-dashboard-auth-feishuFeishu and Lark OAuth sign-in for the Hermes Agent web dashboard, limited to an allow-list of users | Python | 0 | Oct 9, 2026 |
| cybertecla/hermes-telemetry-dashboardDashboard tab that shows what telemetry Hermes Agent would send to Nous before any sending is enabled | Python | 0 | Oct 3, 2026 |
| angel12/hermes-ldap-authLDAP and Active Directory password login for the Hermes Agent web dashboard, as a Hermes plugin | Python | 0 | Oct 1, 2026 |
Security FAQ
How does Hermes Agent protect against dangerous commands?
Hermes has an approval system with smart, manual and off modes, a hardline blocklist that always refuses commands such as rm -rf /, and a denylist that blocks writes to credential folders like ~/.ssh.
Is a Hermes profile a sandbox?
No. A profile separates Hermes's own data, but tools still run with your user account's access. For real isolation, use a container backend or a separate server.
Related guides: How to run Hermes Agent securely