Hermes Atlas
Official Nous Research repos

hermes-plugin-snyk

NousResearch/hermes-plugin-snyk Published by Nous Research

Hermes Agent plugin that runs Snyk code, dependency, container and IaC scans through Snyk's MCP server

In short

hermes-plugin-snyk is a Hermes Agent plugin that scans code, dependencies, container images, IaC and SBOMs through Snyk's first-party MCP server. It bundles the snyk-security-scan workflow skill and is published in the NousResearch GitHub organization.

What hermes-plugin-snyk does

Snyk ships its MCP server inside the Snyk CLI as the snyk mcp subcommand, so this plugin is a pinned npx stdio launch plus a workflow skill. It is a portable Agent Plugins v1 package with an mcp.json entry (server key sn), registered for every new session while the plugin is enabled, and the snyk-security-scan skill, which covers when to use which scanner, the auth, trust, scan and fix loop, pitfalls and a per-tool argument reference.

The server starts with npx -y snyk@1.1306.0 mcp -t stdio --profile full, so Node.js and npm must be on PATH, and the first launch downloads the pinned CLI. No credentials are needed at install. Before the first scan, Hermes runs the snyk_auth tool, which opens Snyk's browser login and stores the token in the Snyk CLI config rather than in Hermes. Snyk analytics are disabled at launch, and the skill tells the agent to ask before scanning private repositories, because SAST uploads source and SCA uploads the dependency graph to Snyk's cloud.

Key features

  • Code (SAST), dependency (SCA), container, IaC and SBOM scanning
  • Snyk's own MCP server, launched with a pinned CLI version
  • snyk-security-scan workflow skill bundled in the plugin
  • Browser login through the snyk_auth tool, with the token kept in the Snyk CLI config
  • Snyk analytics disabled at launch
  • Installs with no edits to mcp_servers in config.yaml

When to use it

  • Scanning a repository for code and dependency vulnerabilities from a Hermes session
  • Checking a container image or infrastructure-as-code files before deploy
  • Following a scan and fix loop with guidance from the bundled skill

Who it is for: Hermes Agent users who want security scanning from Snyk available as an agent tool.

How it fits with Hermes Agent

It is a Hermes Agent plugin published in the NousResearch GitHub organization and installed from the Nous plugin catalog. The README says third-party product integrations ship outside the Hermes core tree.

How to install hermes-plugin-snyk

These commands are copied from the project's README. Check the repository for the latest steps before you run them.

hermes plugins install snyk
hermes plugins enable snyk

Requirements: Node.js and npm on PATH, and a Snyk account; the README says a free account covers the code (SAST) and open-source (SCA) scanners

Note: Scans are network calls that upload source code or the dependency graph to Snyk's cloud, and a Snyk account is needed to sign in.

FAQ

What is hermes-plugin-snyk?

hermes-plugin-snyk is a Hermes Agent plugin that connects Hermes to Snyk's MCP server. It scans code, dependencies, container images, IaC and SBOMs and bundles a workflow skill.

Does hermes-plugin-snyk work with Hermes Agent?

Yes. It is a Hermes plugin installed with hermes plugins install snyk and enabled with hermes plugins enable snyk, then used from a new Hermes session.

How do I install hermes-plugin-snyk?

Run hermes plugins install snyk and hermes plugins enable snyk, then start a new session. Run the snyk_auth tool before the first scan to sign in to Snyk.

Similar official for Hermes Agent

All official

Related guides: What is Hermes Agent? · How to install Hermes Agent