Hermes Atlas
Security & sandboxing

Hermes Pentest Lab

jayelbotvibe-web/hermes-pentest-lab

Kali-native pentesting lab with an MCP tool server, guardrails enforced in code and PDF reports

In short

Hermes Pentest Lab is a Kali Linux pentesting workstation setup in which Hermes Agent dispatches subagents, runs native tools under scope, VPN, rate-limit and audit guardrails, verifies findings and builds PDF reports.

What Hermes Pentest Lab does

Hermes Pentest Lab runs on Kali Linux, with tools executing natively on the host for raw sockets, SMB and packet capture, and Docker used only for lab targets and Neo4j. In a session you invoke the pentest-engage skill and tell Hermes what to test. It checks scope, starts the VPN, dispatches seven subagents in parallel, stores findings in a shared SQLite database, has a verify agent independently reproduce each draft finding with benign checks, and builds a PDF report with verdict badges. Every action is logged to an audit trail.

The toolchain is also exposed as an MCP tool server, so other MCP clients such as Claude Code, Claude Desktop and Cursor can drive it. Each target-touching tool goes through a scope check before it runs and appends to a tamper-evident audit chain afterwards, so scope, VPN, rate-limit and audit guardrails are enforced in code rather than requested of the agent. Destructive tools such as sqlmap, hydra, metasploit and responder stay operator-run. Findings can carry MITRE ATT&CK and OWASP Top 10 tags, and 15 generic finding templates speed up writing. WireGuard and LUKS encryption are part of the setup.

Key features

  • Seven parallel subagents for OSINT, recon, web, network and verification work
  • MCP tool server with scope, VPN, rate-limit and audit checks enforced in code
  • Independent verify agent for draft findings
  • MITRE ATT&CK and OWASP Top 10 tagging
  • Library of 15 generic finding templates
  • Automated PDF reports with verdict badges, plus retest tracking

When to use it

  • Running an authorized scoped engagement and getting a draft report at the end
  • Letting an MCP client drive pentest tools without bypassing the scope check
  • Tracking retests of previously reported findings

Who it is for: Penetration testers who work from Kali Linux and want Hermes Agent to orchestrate tools with enforced guardrails.

How it fits with Hermes Agent

Built around Hermes Agent: engagements start from the pentest-engage skill, and Hermes dispatches the subagents.

Requirements: Kali Linux, with Docker for lab targets and Neo4j

Note: It requires Kali Linux because the tools run natively on the host rather than in Docker.

FAQ

What is Hermes Pentest Lab?

Hermes Pentest Lab is a Kali Linux pentesting setup where Hermes Agent orchestrates subagents and native tools, an MCP server enforces scope and audit guardrails, and findings are verified and turned into PDF reports.

Does Hermes Pentest Lab work with Hermes Agent?

Yes. Sessions start from the pentest-engage skill in Hermes. The MCP server can also be driven by other clients such as Claude Code and Cursor.

What do I need to run Hermes Pentest Lab?

You need Kali Linux, because the tools run natively on the host, and Docker for the lab targets and Neo4j.

Similar security for Hermes Agent

All security

Related guides: How to run Hermes Agent securely