Hermes Atlas
Security & sandboxing · works with Hermes Agent

Skills Guard

aibuild-lab/skills-guard

Threat scanner and trust matrix for AI skill files, ported from Hermes Agent's skills_guard

In short

Skills Guard is a Python static analysis tool that scans AI skill files for known threat patterns before they are installed. It pairs the regex catalog from Hermes Agent's skills_guard.py with a three-level trust matrix, so you can decide which skills install automatically, need review, or are blocked.

What Skills Guard does

Skills Guard checks skill bundles, the YAML-frontmatter plus Markdown files that Claude Code, Hermes and OpenClaw load, before they reach an agent. The scanner looks for prompt injection, exfiltration, destructive operations, persistence, reverse shells, obfuscation, supply-chain risks, leaked credentials and invisible Unicode characters. A scan returns one of three verdicts: safe for no findings, caution for medium or high severity findings only, and dangerous when at least one finding is critical.

A trust matrix then turns the verdict into a decision. TRUSTED sources allow caution verdicts but block dangerous ones. REVIEW_REQUIRED, the default for community skills, blocks both caution and dangerous results. BLOCKED sources are rejected whatever the scan says. The command line returns exit codes (0 allowed, 1 blocked, 2 needs confirmation, 3 bad arguments) and a --json flag for CI pipelines. A TrustMatrix class offers the same logic as a library. The README attributes the scanner code to NousResearch's hermes-agent.

Key features

  • Regex catalog covering prompt injection, exfiltration, persistence, reverse shells and obfuscation
  • Three scan verdicts: safe, caution and dangerous
  • Three trust levels: TRUSTED, REVIEW_REQUIRED and BLOCKED
  • Custom trusted sources through the --trusted flag
  • JSON output and distinct exit codes for CI pipelines
  • TrustMatrix Python API that returns allow, review or block

When to use it

  • Vetting a community skill you cloned before adding it to your agent
  • Gating skill installs in a CI pipeline using exit codes
  • Keeping a list of trusted and blocked skill sources for a team

Who it is for: People who install third-party skills for Hermes Agent, Claude Code or OpenClaw and want an automatic check first.

How it fits with Hermes Agent

Supports Hermes Agent among other agents. It ports the skills_guard.py scanner from NousResearch's hermes-agent with attribution and scans the skill files that Hermes loads.

How to install Skills Guard

These commands are copied from the project's README. Check the repository for the latest steps before you run them.

pip install skills-guard
skills-guard --check ./some-skill

Note: GitHub reports the license as NOASSERTION even though the repository description says MIT, so check the license file before reuse.

FAQ

What is Skills Guard?

Skills Guard is a static analysis tool that scans AI skill files for prompt injection, exfiltration, destructive commands and other known threat patterns. It then applies a three-level trust matrix to decide whether a skill is allowed, needs review or is blocked.

Does Skills Guard work with Hermes Agent?

Yes, it scans the skill bundles that Hermes, Claude Code and OpenClaw load. Its scanner is a port of skills_guard.py from NousResearch's hermes-agent, credited in the repository.

How do I install Skills Guard?

Run pip install skills-guard, then scan a skill directory with skills-guard --check ./some-skill. The README says pip is the only install path, because the package was never published under its old name, skill-vault.

Similar security for Hermes Agent

All security

Related guides: How to run Hermes Agent securely