Hermes Pentest Lab
jayelbotvibe-web/hermes-pentest-lab
Kali-native pentesting lab with an MCP tool server, guardrails enforced in code and PDF reports
Hermes Pentest Lab is a Kali Linux pentesting workstation setup in which Hermes Agent dispatches subagents, runs native tools under scope, VPN, rate-limit and audit guardrails, verifies findings and builds PDF reports.
What Hermes Pentest Lab does
Hermes Pentest Lab runs on Kali Linux, with tools executing natively on the host for raw sockets, SMB and packet capture, and Docker used only for lab targets and Neo4j. In a session you invoke the pentest-engage skill and tell Hermes what to test. It checks scope, starts the VPN, dispatches seven subagents in parallel, stores findings in a shared SQLite database, has a verify agent independently reproduce each draft finding with benign checks, and builds a PDF report with verdict badges. Every action is logged to an audit trail.
The toolchain is also exposed as an MCP tool server, so other MCP clients such as Claude Code, Claude Desktop and Cursor can drive it. Each target-touching tool goes through a scope check before it runs and appends to a tamper-evident audit chain afterwards, so scope, VPN, rate-limit and audit guardrails are enforced in code rather than requested of the agent. Destructive tools such as sqlmap, hydra, metasploit and responder stay operator-run. Findings can carry MITRE ATT&CK and OWASP Top 10 tags, and 15 generic finding templates speed up writing. WireGuard and LUKS encryption are part of the setup.
Key features
- Seven parallel subagents for OSINT, recon, web, network and verification work
- MCP tool server with scope, VPN, rate-limit and audit checks enforced in code
- Independent verify agent for draft findings
- MITRE ATT&CK and OWASP Top 10 tagging
- Library of 15 generic finding templates
- Automated PDF reports with verdict badges, plus retest tracking
When to use it
- Running an authorized scoped engagement and getting a draft report at the end
- Letting an MCP client drive pentest tools without bypassing the scope check
- Tracking retests of previously reported findings
Who it is for: Penetration testers who work from Kali Linux and want Hermes Agent to orchestrate tools with enforced guardrails.
How it fits with Hermes Agent
Built around Hermes Agent: engagements start from the pentest-engage skill, and Hermes dispatches the subagents.
Requirements: Kali Linux, with Docker for lab targets and Neo4j
Note: It requires Kali Linux because the tools run natively on the host rather than in Docker.
FAQ
What is Hermes Pentest Lab?
Hermes Pentest Lab is a Kali Linux pentesting setup where Hermes Agent orchestrates subagents and native tools, an MCP server enforces scope and audit guardrails, and findings are verified and turned into PDF reports.
Does Hermes Pentest Lab work with Hermes Agent?
Yes. Sessions start from the pentest-engage skill in Hermes. The MCP server can also be driven by other clients such as Claude Code and Cursor.
What do I need to run Hermes Pentest Lab?
You need Kali Linux, because the tools run natively on the host, and Docker for the lab targets and Neo4j.
Similar security for Hermes Agent
All securitySafe-by-design USDC and x402 payment plugin for Hermes Agent with human approval for larger transfers
pawel-cell Agent Shopping Safe CheckoutSafe-checkout pattern for agents that buy online: isolated Chrome, virtual card and a human approval gate
Tranquil-Flow Hermes-AegisSecurity layer for Hermes Agent: a MITM proxy that blocks secret leaks and dangerous commands
MahdiHedhli HermesUltraCodeHermes plugin that has a second-lab model review each task before a subagent starts writing code
intentframe IntentFrame for Hermes AgentIntentFrame security plugin that checks Hermes terminal, code, file and cron tool calls against policy
mauricemohr88-debug Hermes Plugin GuardStatic security scanner for Hermes Agent plugins that never imports or runs the plugin code
Related guides: How to run Hermes Agent securely