Hermes Security Audit
dafka007/hermes-security-audit
Approval-gated Hermes plugin that runs Gitleaks, OSV-Scanner and Semgrep CE on a workspace
Hermes Security Audit is a Hermes Agent plugin that adds one approval-gated security_audit tool. It scans a workspace for leaked secrets, vulnerable dependencies and static-analysis findings using Gitleaks, OSV-Scanner and Semgrep CE.
What Hermes Security Audit does
The author built it so Hermes can run the same security check used before calling a coding task finished, without being given a pile of shell commands or running scans silently. Hermes asks for human approval before every audit. Scanner commands are launched with shell=False, the plugin does not edit the scanned project, Gitleaks runs with full redaction, and secret values are never copied into the normalized result. Scanner output is bounded while the process runs, and child processes get a cleaned environment.
Missing tools, timeouts, malformed output and partial Semgrep errors are reported as incomplete coverage rather than a pass. The final result uses PASS, FAIL, NOT_APPLICABLE, UNRESOLVED or BLOCKED, so the agent can tell clean from unverified, and OSV-Scanner exit code 128 maps to NOT_APPLICABLE. Environment variables set scanner paths, the Semgrep config and a per-scanner timeout of 10 to 1800 seconds, default 300. The first test setup used Hermes Agent v0.21.3 on Windows 11, and the test suite runs on Windows and Linux.
Key features
- One security_audit tool that needs human approval before each run
- Gitleaks secret scanning, OSV-Scanner dependency checks and Semgrep CE analysis
- Results of PASS, FAIL, NOT_APPLICABLE, UNRESOLVED or BLOCKED
- Incomplete coverage is reported instead of passing silently
- Secrets redacted and never copied into results
- No third-party Python dependencies
When to use it
- Running a final security check before a coding task is called finished
- Scanning a workspace for committed credentials and vulnerable packages
- Giving an agent audit ability while keeping a human in the approval loop
Who it is for: Hermes Agent users who let the agent write code and want a controlled secret, dependency and static-analysis check.
How it fits with Hermes Agent
Built as a Hermes Agent plugin, installed with hermes plugins install, that registers the security_audit tool.
How to install Hermes Security Audit
These commands are copied from the project's README. Check the repository for the latest steps before you run them.
hermes plugins install dafka007/hermes-security-audit --enableRequirements: Gitleaks, OSV-Scanner and Semgrep CE installed separately and on PATH; no third-party Python dependencies
Note: Gitleaks runs in dir mode, so it scans files in the workspace tree and not the repository's Git commit history.
FAQ
What is Hermes Security Audit?
Hermes Security Audit is a Hermes Agent plugin that runs Gitleaks, OSV-Scanner and Semgrep CE through one approval-gated security_audit tool and returns a structured result.
Does Hermes Security Audit work with Hermes Agent?
Yes. It is a Hermes plugin tested with Hermes Agent v0.21.3 on Windows 11. Restart Hermes after installing it.
What do I need to run Hermes Security Audit?
You need Gitleaks, OSV-Scanner and Semgrep CE installed and on your PATH. The plugin itself has no third-party Python dependencies and does not require patching Hermes.
Similar security for Hermes Agent
All securityProof-carrying defensive security reviews for AI-assisted code with deterministic policy and portable evidence
nordicnode Model SherpaHermes Agent plugin that repairs bad tool calls, breaks tool loops and redacts secrets from logs
chchchadzilla GitHub Safe PushHermes skill that keeps secrets out of git and checks a project is properly packaged before shipping
xielevi Hermes Dashboard Auth for FeishuFeishu and Lark OAuth sign-in for the Hermes Agent web dashboard, limited to an allow-list of users
cybertecla Hermes Telemetry DashboardDashboard tab that shows what telemetry Hermes Agent would send to Nous before any sending is enabled
angel12 hermes-ldap-authLDAP and Active Directory password login for the Hermes Agent web dashboard, as a Hermes plugin
Related guides: How to run Hermes Agent securely