Hermes Agent CaMeL
nativ3ai/hermes-agent-camel
Hermes Agent fork with an opt-in CaMeL-style guard against indirect prompt injection
Hermes Agent CaMeL is a fork of Hermes Agent that integrates CaMeL trust boundaries as an opt-in runtime guard for indirect prompt-injection experiments. It otherwise carries the Hermes Agent feature set.
What Hermes Agent CaMeL does
This fork adds an opt-in CaMeL-style runtime guard to Hermes Agent for indirect prompt-injection experiments, described in a section titled Optional CaMeL Guard. Most of the README reproduces the upstream Hermes Agent documentation, so the fork keeps the feature set that text describes.
That feature set includes a terminal interface with multiline editing and slash-command autocomplete, a single gateway process for Telegram, Discord, Slack, WhatsApp, Signal and the CLI, and a learning loop in which skills are created from experience and past conversations are searchable with FTS5. It also has a built-in cron scheduler, isolated subagents, model switching with hermes model, and six terminal backends: local, Docker, SSH, Daytona, Singularity and Modal.
Key features
- Opt-in CaMeL-style runtime guard aimed at indirect prompt-injection experiments
- Hermes Agent terminal interface with multiline editing and slash-command autocomplete
- Single gateway process for Telegram, Discord, Slack, WhatsApp, Signal and the CLI
- Skills created from experience and FTS5 session search for cross-session recall
- Built-in cron scheduler and isolated subagents
- Six terminal backends: local, Docker, SSH, Daytona, Singularity and Modal
When to use it
- Experimenting with trust boundaries against indirect prompt injection in a Hermes Agent setup
- Comparing a guarded Hermes Agent fork against the upstream project
- Running a Hermes Agent gateway with an added security layer
Who it is for: Security-minded Hermes Agent users and researchers who want to test CaMeL-style trust boundaries.
How it fits with Hermes Agent
A fork of NousResearch/hermes-agent rather than a plugin; it keeps the Hermes Agent feature set and adds the CaMeL guard.
Note: It is a fork of NousResearch/hermes-agent whose README mostly repeats the upstream text, and the CaMeL guard is opt-in and described as being for prompt-injection experiments.
FAQ
What is Hermes Agent CaMeL?
Hermes Agent CaMeL is a fork of Hermes Agent with integrated CaMeL trust boundaries. The guard is opt-in and aimed at indirect prompt-injection experiments.
Does Hermes Agent CaMeL work with Hermes Agent?
It is itself a fork of Hermes Agent, so it keeps the upstream features such as the terminal interface, the messaging gateway, skills and the cron scheduler. The CaMeL guard is switched on separately.
Is Hermes Agent CaMeL free and open source?
Yes, the repository is licensed under MIT.
Similar security for Hermes Agent
All securityLocal policy, approval and recovery controls that wrap CLI coding agents such as Claude, Codex and Hermes
asimons81 Hermes VaultLocal-first credential broker, secret scanner and encrypted vault for Hermes agents
78 TenBoxLightweight virtual machine monitor for running OpenClaw, QwenPaw and Hermes Agent in isolation
XSafeAI XSafeClawOpen-source agent safety platform that monitors and guards OpenClaw, Hermes and Nanobot sessions
Strategic-Automation ViolinSupervised Hermes pentest profile with guarded execution and evidence-backed reporting
x-glacier kali-pentestKali Linux pentest skill that plans, runs and adapts attacks with approval gates
Related guides: How to run Hermes Agent securely