Hermes Atlas
Security & sandboxing

GitHub Safe Push

chchchadzilla/github-safe-push

Hermes skill that keeps secrets out of git and checks a project is properly packaged before shipping

In short

GitHub Safe Push is a Hermes Agent skill that acts as a publishing playbook: it keeps .env files, keys and tokens out of git, refuses a push that would leak them, and requires a finished README, license, version and release.

What GitHub Safe Push does

The skill is a markdown playbook that the agent loads with skill_view when you publish something new. It applies when a project exists only on a hard drive, a repository is about to get its first push, or a README still contains a home-folder path or session recap. The steps are to confirm that .env, local.env and .env.local are ignored with git check-ignore, set the commit author, scan before committing and never add .env files, .pem files or SSH private keys, and add a remote without a password or token in the URL.

It then treats a release as incomplete without a set of pieces: a .gitignore covering env files and keys, a .env.example with empty placeholders, an MIT LICENSE, semantic versioning with a VERSION file, a CHANGELOG, a banner image, a README with Windows, macOS and Linux steps, Discussions enabled and a tagged v* release. It is not a GitHub login helper, and it points to separate guides for tokens and pull requests.

Key features

  • Verifies that env files and keys are ignored before anything is committed
  • Refuses a push that would expose a token-shaped string in a tracked file
  • Checks that the remote URL contains no embedded password
  • Checklist of license, version, changelog, README and release for a finished repository
  • Instructions for Windows, macOS and Linux

When to use it

  • Publishing a new Hermes skill or plugin to GitHub for the first time
  • Making sure a local project does not leak API keys on its first push
  • Cleaning a README of local paths before release

Who it is for: People who let a Hermes agent publish code to GitHub and want secrets kept out of the repository.

How it fits with Hermes Agent

It is a Hermes skill placed under the skills/github folder of the Hermes home directory, which the agent loads with skill_view before pushing.

How to install GitHub Safe Push

These commands are copied from the project's README. Check the repository for the latest steps before you run them.

git clone https://github.com/chchchadzilla/github-safe-push.git
mkdir -p "${HERMES_HOME:-$HOME/.hermes}/skills/github"
ln -s "$(pwd)/github-safe-push" "${HERMES_HOME:-$HOME/.hermes}/skills/github/github-safe-push"

Requirements: Git and a GitHub account that can create repositories; Hermes Agent and a GitHub personal access token are optional

Note: The skill hard-codes the author's name in its commit and license steps, so edit those before using it for your own projects.

FAQ

What is GitHub Safe Push?

GitHub Safe Push is a Hermes Agent skill that guides the agent through publishing a project to GitHub without leaking secrets. It also requires a finished README, license, version and release.

Does GitHub Safe Push work with Hermes Agent?

Yes, it is a Hermes skill. Link or copy it into the skills/github folder of your Hermes home and start a new session, because skills load at process start.

Is GitHub Safe Push free and open source?

Yes, the repository is released under the MIT license.

Similar security for Hermes Agent

All security

Related guides: How to run Hermes Agent securely