Hermes Atlas
Security & sandboxing · works with Hermes Agent

PromptGuard

mturac/promptguard

Offline prompt auditor with a pre-write guard for Hermes, Claude Code, Codex, OpenCode and OpenClaw

In short

PromptGuard is an offline, dependency-free Python command-line auditor that checks whether an agent prompt states its role, surface, constraints, verification and safety, and it ships a pre-write guard for Hermes Agent and four other agents.

What PromptGuard does

PromptGuard treats a prompt as a contract. It checks whether role, surface, constraints, verification and safety are explicit enough to execute, and reports findings with evidence, impact, the missing contract, questions and approval criteria, plus a fix draft that keeps your wording. Four profiles tune the rules: coding-agent, system, security and general. It makes no model calls and no network requests, so it is safe in hooks and on air-gapped machines.

For CI it offers severity gates with --fail-on, a repository walk, SARIF export and baseline diffs that fail only on new findings. For agents, install-agent-adapters.sh installs adapters for Hermes, Claude, Codex, OpenCode and OpenClaw. The Hermes adapter is a skill plus a pre_tool_call plugin with a /promptguard chat command. The plugin blocks prompt-like write_file, patch and edit calls and can be switched off with PROMPTGUARD_HERMES_DISABLE=1. A terminal review mode lets you walk through findings, open fix drafts and record accepted risks.

Key features

  • Findings with evidence, impact, missing contract and approval criteria
  • Four profiles: coding-agent, system, security and general
  • Severity gates, repository walk, SARIF export and baseline diffs for CI
  • Hermes skill and pre_tool_call plugin with a /promptguard command
  • Terminal review mode with fix drafts and accept-risk records
  • No model calls, no network and zero dependencies

When to use it

  • Stopping a vague instruction such as 'Fix this bug and write code' before an agent writes files
  • Failing a CI job when prompt files contain high-severity findings
  • Checking system or router prompts for override and exfiltration patterns

Who it is for: Developers who give coding agents written instructions and want vague prompts caught before the agent acts.

How it fits with Hermes Agent

Supports Hermes Agent among five agents, with a Hermes skill and a pre_tool_call plugin that guards file-writing tools.

How to install PromptGuard

These commands are copied from the project's README. Check the repository for the latest steps before you run them.

pipx install "git+https://github.com/mturac/promptguard.git"
./install-agent-adapters.sh hermes

Requirements: Python with pipx or pip; no model API, network access or third-party dependencies

FAQ

What is PromptGuard?

PromptGuard is an offline command-line tool that audits agent prompts as contracts. It flags missing role, scope, verification and safety details and can block vague prompts before an agent writes code.

Does PromptGuard work with Hermes Agent?

Yes, it ships a Hermes skill and a pre_tool_call plugin, with a /promptguard chat command. The plugin blocks prompt-like write_file, patch and edit calls, and it uses the active profile home from hermes config path.

Does PromptGuard need a model API or network access?

No. It makes no model calls and no network requests, which makes it safe to run in hooks and on air-gapped machines.

Similar security for Hermes Agent

All security

Related guides: How to run Hermes Agent securely