Hermes Atlas
Security & sandboxing

Hermes Plugin Guard

mauricemohr88-debug/hermes-plugin-guard

Static security scanner for Hermes Agent plugins that never imports or runs the plugin code

In short

Hermes Plugin Guard is a local static scanner, run as hpg, that reviews Hermes Agent plugins before you enable them. It checks manifests, Python source, dependency declarations, likely secrets and repository hygiene without importing or executing the plugin.

What Hermes Plugin Guard does

Hermes plugins are Python extensions that can register tools and hooks and run with the permissions of the Hermes process, so the scanner provides a fast first pass before enablement and in CI. Its rules look for subprocess calls that bypass Hermes' terminal-tool approval path, dynamic execution, unsafe deserialization, sensitive-path access, destructive file operations, disabled TLS verification, all-interface listeners, outbound calls with redacted destinations and undeclared secret environment variables.

More checks cover work done at import or registration time, privileged registration and middleware surfaces, committed credentials, mutable remote dependencies, remote scripts piped to shells, declaration drift, missing tests and missing project policies. The standalone scan makes no network requests and includes no telemetry. On Hermes v0.20.5 and newer, the guard can also be installed as a native, review-only plugin from the /src subtree, which adds hermes plugin-guard commands. The README states it is unofficial and not affiliated with Nous Research.

Key features

  • Static scan of plugin manifests, Python source and dependency declarations
  • Rules for subprocess approval bypass, dynamic execution and unsafe deserialization
  • Detection of likely committed credentials and undeclared secret environment variables
  • hpg scan with a --fail-on option for use in CI
  • Optional native review-only Hermes plugin for v0.20.5 and newer
  • No network requests and no telemetry in the standalone scan

When to use it

  • Reviewing a third-party Hermes plugin before enabling it
  • Adding a first-pass security check to a plugin repository's CI
  • Giving the maintainer rule feedback through the beta-test report template

Who it is for: Hermes Agent users who install community plugins and plugin authors who want an automated first-pass review.

How it fits with Hermes Agent

It is built specifically for Hermes Agent plugins, and it can itself run as a native Hermes plugin on v0.20.5 or newer.

How to install Hermes Plugin Guard

These commands are copied from the project's README. Check the repository for the latest steps before you run them.

pipx install hermes-plugin-guard
hermes plugins install mauricemohr88-debug/hermes-plugin-guard/src --no-enable
hermes plugins enable hermes-plugin-guard --no-allow-tool-override

Requirements: Python 3.11 or newer and pipx for the CLI; the native plugin mode needs Hermes v0.20.5 or newer

Note: It is an unofficial community project in beta testing, at version 0.2.1, and is not affiliated with Nous Research.

FAQ

What is Hermes Plugin Guard?

Hermes Plugin Guard is a local static scanner for Hermes Agent plugins. It reads plugin files as data and reports risky patterns without importing or running the plugin.

Does Hermes Plugin Guard work with Hermes Agent?

Yes. It scans Hermes Agent plugins, and on Hermes v0.20.5 or newer it can also be installed as a native review-only plugin. The README says to keep it disabled during installation, then enable it with --no-allow-tool-override.

How do I install Hermes Plugin Guard?

Run pipx install hermes-plugin-guard, then scan a plugin with hpg scan followed by its absolute path. Python 3.11 or newer is required.

Similar security for Hermes Agent

All security

Related guides: How to run Hermes Agent securely