Hermes Atlas
Security & sandboxing

hermes-bumblebee-bridge

Deconstruct2021/hermes-bumblebee-bridge

Daily read-only supply-chain scans for a Hermes Agent host using Perplexity's Bumblebee

In short

hermes-bumblebee-bridge is a set of shell scripts and a Hermes skill that run Perplexity's Bumblebee scanner on a schedule and report the result. It gives Hermes Agent users a continuous security signal about the machine the agent runs on.

What hermes-bumblebee-bridge does

hermes-bumblebee-bridge connects Perplexity's Bumblebee, a read-only supply-chain scanner written in Go, to a Hermes Agent install. Its installer downloads a sha256-verified Bumblebee v0.1.1 binary, fetches the upstream threat-intel catalogs, adds a systemd user timer that scans daily at 10:55 and catches up after downtime, and places a bumblebee-scan skill in ~/.hermes/skills/. Scan summaries are written as JSON under ~/.local/state/.

The skill lets Hermes run the scan when asked whether the system is clean and describe what it found. An optional notifier fires only for findings that are new compared with the previous scan, and the repository ships examples for a Telegram bot and generic webhooks. The installer also prints a SOUL-snippet.md to paste into ~/.hermes/SOUL.md so the agent reaches for the skill on security questions. The bridge itself is bash glue and a systemd timer.

Key features

  • Daily systemd user timer with Persistent=true catch-up after the machine was off
  • bumblebee-scan skill installed into ~/.hermes/skills/
  • Summary JSON with package totals and findings, built from Bumblebee's NDJSON output
  • Opt-in alerts only when a new finding appears versus the last scan
  • Telegram and generic webhook notifier examples
  • SOUL.md snippet that points the agent at the scan skill

When to use it

  • Asking Hermes whether the host machine is clean and getting a narrated answer
  • Receiving a Telegram message when a newly published threat-intel entry matches installed packages
  • Running a daily check on a laptop that is not on all the time

Who it is for: Hermes Agent users on Linux or macOS who want automated, read-only supply-chain checks on the machine that hosts their agent.

How it fits with Hermes Agent

It is built for Hermes Agent: it installs a Hermes skill, follows the SOUL.md convention and can send alerts through a Telegram bridge. The scanner itself comes from Perplexity's Bumblebee project.

How to install hermes-bumblebee-bridge

These commands are copied from the project's README. Check the repository for the latest steps before you run them.

git clone https://github.com/Deconstruct2021/hermes-bumblebee-bridge.git
cd hermes-bumblebee-bridge
./install.sh

Requirements: A Linux or macOS machine with a systemd user timer and a Hermes Agent install using ~/.hermes

FAQ

What is hermes-bumblebee-bridge?

hermes-bumblebee-bridge is a bridge between Perplexity's Bumblebee supply-chain scanner and Hermes Agent. It schedules daily scans, installs a skill so Hermes can run them, and can send alerts for new findings.

Does hermes-bumblebee-bridge work with Hermes Agent?

Yes. It installs a bumblebee-scan skill into ~/.hermes/skills/ and prints a SOUL.md snippet so Hermes calls the skill on security questions.

Is hermes-bumblebee-bridge free and open source?

GitHub could not identify a standard license for this repository (it reports NOASSERTION), so check the repository and contact the author before reusing the code.

Similar security for Hermes Agent

All security

Related guides: How to run Hermes Agent securely