Violin
Strategic-Automation/violin
Supervised Hermes pentest profile with guarded execution and evidence-backed reporting
Violin is a Hermes-native penetration testing profile that runs supervised, authorized pentests, from reconnaissance through exploit validation to a release-gated report.
What Violin does
Violin installs as a Hermes Agent profile and routes each engagement through 35 playbooks and seven skills, covering reconnaissance, vulnerability research and exploit validation. A required violin-guard plugin checks scope, phase, hypothesis state and command history before any command touches a real target, and persistent engagement state keeps PTT tasks, checkpoints and evidence intact across context compression.
Findings are typed submissions bound to authenticated execution receipts rather than free text, and releases are gated behind schema checks, linting and a full test suite. Violin adds no credentials of its own: it reuses the model and tool providers already configured in Hermes, and the project recommends Qwen3.8 27B locally or DeepSeek V4 Flash through a hosted provider as a capable default.
Key features
- Guarded target execution with scope, phase and history checks before each command
- 35 routed playbooks across recon, identity, API and LLM-security testing
- Persistent engagement state that survives context compression
- Evidence-backed findings tied to authenticated execution receipts
- Release-gated plugin registration, schema checks and a full test suite
When to use it
- Running an authorized, supervised penetration test against a scoped target
- Tracking a multi-day engagement's hypotheses, checkpoints and evidence in one place
- Producing a release-gated report backed by execution receipts rather than narrative claims
Who it is for: Security engineers and red teams who run authorized penetration tests through Hermes Agent and want guardrails around target execution.
How it fits with Hermes Agent
Violin installs directly as a Hermes Agent profile and depends on the required violin-guard plugin at the point where commands reach a real target.
How to install Violin
These commands are copied from the project's README. Check the repository for the latest steps before you run them.
hermes profile install https://github.com/Strategic-Automation/violin
hermes -p violinRequirements: Hermes Agent 0.18.0 or newer, Python 3.11 and uv for local development, Kali Linux or Parrot OS, written authorization and an approved scope
FAQ
What is Violin?
Violin is a Hermes-native agentic pentest profile that runs supervised, authorized penetration tests from reconnaissance through exploit validation to reporting. It uses Hermes' built-in toolsets plus seven routed skills and a required guard plugin at the point commands reach a target.
Does Violin work with Hermes Agent?
Yes, it installs as a Hermes Agent profile and requires Hermes Agent 0.18.0 or newer to run. It inherits whatever model and tool providers are already configured in that Hermes installation.
How do I install Violin?
Run hermes profile install with this repository's URL, then switch to the profile with hermes -p violin. After that, point it at an authorized target to begin scope collection.
Similar security for Hermes Agent
All securityLocal-first credential broker, secret scanner and encrypted vault for Hermes agents
78 TenBoxLightweight virtual machine monitor for running OpenClaw, QwenPaw and Hermes Agent in isolation
nativ3ai Hermes Agent CaMeLHermes Agent fork with an opt-in CaMeL-style guard against indirect prompt injection
XSafeAI XSafeClawOpen-source agent safety platform that monitors and guards OpenClaw, Hermes and Nanobot sessions
x-glacier kali-pentestKali Linux pentest skill that plans, runs and adapts attacks with approval gates
agentrhq AuthsomeCredential gateway that logs in once via OAuth2 or API key and keeps AI agents authenticated
Related guides: How to run Hermes Agent securely