PromptGuard
mturac/promptguard
Offline prompt auditor with a pre-write guard for Hermes, Claude Code, Codex, OpenCode and OpenClaw
PromptGuard is an offline, dependency-free Python command-line auditor that checks whether an agent prompt states its role, surface, constraints, verification and safety, and it ships a pre-write guard for Hermes Agent and four other agents.
What PromptGuard does
PromptGuard treats a prompt as a contract. It checks whether role, surface, constraints, verification and safety are explicit enough to execute, and reports findings with evidence, impact, the missing contract, questions and approval criteria, plus a fix draft that keeps your wording. Four profiles tune the rules: coding-agent, system, security and general. It makes no model calls and no network requests, so it is safe in hooks and on air-gapped machines.
For CI it offers severity gates with --fail-on, a repository walk, SARIF export and baseline diffs that fail only on new findings. For agents, install-agent-adapters.sh installs adapters for Hermes, Claude, Codex, OpenCode and OpenClaw. The Hermes adapter is a skill plus a pre_tool_call plugin with a /promptguard chat command. The plugin blocks prompt-like write_file, patch and edit calls and can be switched off with PROMPTGUARD_HERMES_DISABLE=1. A terminal review mode lets you walk through findings, open fix drafts and record accepted risks.
Key features
- Findings with evidence, impact, missing contract and approval criteria
- Four profiles: coding-agent, system, security and general
- Severity gates, repository walk, SARIF export and baseline diffs for CI
- Hermes skill and pre_tool_call plugin with a /promptguard command
- Terminal review mode with fix drafts and accept-risk records
- No model calls, no network and zero dependencies
When to use it
- Stopping a vague instruction such as 'Fix this bug and write code' before an agent writes files
- Failing a CI job when prompt files contain high-severity findings
- Checking system or router prompts for override and exfiltration patterns
Who it is for: Developers who give coding agents written instructions and want vague prompts caught before the agent acts.
How it fits with Hermes Agent
Supports Hermes Agent among five agents, with a Hermes skill and a pre_tool_call plugin that guards file-writing tools.
How to install PromptGuard
These commands are copied from the project's README. Check the repository for the latest steps before you run them.
pipx install "git+https://github.com/mturac/promptguard.git"
./install-agent-adapters.sh hermesRequirements: Python with pipx or pip; no model API, network access or third-party dependencies
FAQ
What is PromptGuard?
PromptGuard is an offline command-line tool that audits agent prompts as contracts. It flags missing role, scope, verification and safety details and can block vague prompts before an agent writes code.
Does PromptGuard work with Hermes Agent?
Yes, it ships a Hermes skill and a pre_tool_call plugin, with a /promptguard chat command. The plugin blocks prompt-like write_file, patch and edit calls, and it uses the active profile home from hermes config path.
Does PromptGuard need a model API or network access?
No. It makes no model calls and no network requests, which makes it safe to run in hooks and on air-gapped machines.
Similar security for Hermes Agent
All securityOpen-source agent safety platform that monitors and guards OpenClaw, Hermes and Nanobot sessions
Strategic-Automation ViolinSupervised Hermes pentest profile with guarded execution and evidence-backed reporting
x-glacier kali-pentestKali Linux pentest skill that plans, runs and adapts attacks with approval gates
agentrhq AuthsomeCredential gateway that logs in once via OAuth2 or API key and keeps AI agents authenticated
TheAiSingularity HermesClawRun Hermes Agent inside NVIDIA OpenShell with enforced network, filesystem and syscall limits
claudlos Hermes KatanaSecurity layer for Hermes Agent with taint tracking, a policy engine and outbound secret scrubbing
Related guides: How to run Hermes Agent securely