Hermes Atlas
Security & sandboxing

Hermes Security Audit

dafka007/hermes-security-audit

Approval-gated Hermes plugin that runs Gitleaks, OSV-Scanner and Semgrep CE on a workspace

In short

Hermes Security Audit is a Hermes Agent plugin that adds one approval-gated security_audit tool. It scans a workspace for leaked secrets, vulnerable dependencies and static-analysis findings using Gitleaks, OSV-Scanner and Semgrep CE.

What Hermes Security Audit does

The author built it so Hermes can run the same security check used before calling a coding task finished, without being given a pile of shell commands or running scans silently. Hermes asks for human approval before every audit. Scanner commands are launched with shell=False, the plugin does not edit the scanned project, Gitleaks runs with full redaction, and secret values are never copied into the normalized result. Scanner output is bounded while the process runs, and child processes get a cleaned environment.

Missing tools, timeouts, malformed output and partial Semgrep errors are reported as incomplete coverage rather than a pass. The final result uses PASS, FAIL, NOT_APPLICABLE, UNRESOLVED or BLOCKED, so the agent can tell clean from unverified, and OSV-Scanner exit code 128 maps to NOT_APPLICABLE. Environment variables set scanner paths, the Semgrep config and a per-scanner timeout of 10 to 1800 seconds, default 300. The first test setup used Hermes Agent v0.21.3 on Windows 11, and the test suite runs on Windows and Linux.

Key features

  • One security_audit tool that needs human approval before each run
  • Gitleaks secret scanning, OSV-Scanner dependency checks and Semgrep CE analysis
  • Results of PASS, FAIL, NOT_APPLICABLE, UNRESOLVED or BLOCKED
  • Incomplete coverage is reported instead of passing silently
  • Secrets redacted and never copied into results
  • No third-party Python dependencies

When to use it

  • Running a final security check before a coding task is called finished
  • Scanning a workspace for committed credentials and vulnerable packages
  • Giving an agent audit ability while keeping a human in the approval loop

Who it is for: Hermes Agent users who let the agent write code and want a controlled secret, dependency and static-analysis check.

How it fits with Hermes Agent

Built as a Hermes Agent plugin, installed with hermes plugins install, that registers the security_audit tool.

How to install Hermes Security Audit

These commands are copied from the project's README. Check the repository for the latest steps before you run them.

hermes plugins install dafka007/hermes-security-audit --enable

Requirements: Gitleaks, OSV-Scanner and Semgrep CE installed separately and on PATH; no third-party Python dependencies

Note: Gitleaks runs in dir mode, so it scans files in the workspace tree and not the repository's Git commit history.

FAQ

What is Hermes Security Audit?

Hermes Security Audit is a Hermes Agent plugin that runs Gitleaks, OSV-Scanner and Semgrep CE through one approval-gated security_audit tool and returns a structured result.

Does Hermes Security Audit work with Hermes Agent?

Yes. It is a Hermes plugin tested with Hermes Agent v0.21.3 on Windows 11. Restart Hermes after installing it.

What do I need to run Hermes Security Audit?

You need Gitleaks, OSV-Scanner and Semgrep CE installed and on your PATH. The plugin itself has no third-party Python dependencies and does not require patching Hermes.

Similar security for Hermes Agent

All security

Related guides: How to run Hermes Agent securely