Hermes Atlas
Security & sandboxing

Violin

Strategic-Automation/violin

Supervised Hermes pentest profile with guarded execution and evidence-backed reporting

In short

Violin is a Hermes-native penetration testing profile that runs supervised, authorized pentests, from reconnaissance through exploit validation to a release-gated report.

What Violin does

Violin installs as a Hermes Agent profile and routes each engagement through 35 playbooks and seven skills, covering reconnaissance, vulnerability research and exploit validation. A required violin-guard plugin checks scope, phase, hypothesis state and command history before any command touches a real target, and persistent engagement state keeps PTT tasks, checkpoints and evidence intact across context compression.

Findings are typed submissions bound to authenticated execution receipts rather than free text, and releases are gated behind schema checks, linting and a full test suite. Violin adds no credentials of its own: it reuses the model and tool providers already configured in Hermes, and the project recommends Qwen3.8 27B locally or DeepSeek V4 Flash through a hosted provider as a capable default.

Key features

  • Guarded target execution with scope, phase and history checks before each command
  • 35 routed playbooks across recon, identity, API and LLM-security testing
  • Persistent engagement state that survives context compression
  • Evidence-backed findings tied to authenticated execution receipts
  • Release-gated plugin registration, schema checks and a full test suite

When to use it

  • Running an authorized, supervised penetration test against a scoped target
  • Tracking a multi-day engagement's hypotheses, checkpoints and evidence in one place
  • Producing a release-gated report backed by execution receipts rather than narrative claims

Who it is for: Security engineers and red teams who run authorized penetration tests through Hermes Agent and want guardrails around target execution.

How it fits with Hermes Agent

Violin installs directly as a Hermes Agent profile and depends on the required violin-guard plugin at the point where commands reach a real target.

How to install Violin

These commands are copied from the project's README. Check the repository for the latest steps before you run them.

hermes profile install https://github.com/Strategic-Automation/violin
hermes -p violin

Requirements: Hermes Agent 0.18.0 or newer, Python 3.11 and uv for local development, Kali Linux or Parrot OS, written authorization and an approved scope

FAQ

What is Violin?

Violin is a Hermes-native agentic pentest profile that runs supervised, authorized penetration tests from reconnaissance through exploit validation to reporting. It uses Hermes' built-in toolsets plus seven routed skills and a required guard plugin at the point commands reach a target.

Does Violin work with Hermes Agent?

Yes, it installs as a Hermes Agent profile and requires Hermes Agent 0.18.0 or newer to run. It inherits whatever model and tool providers are already configured in that Hermes installation.

How do I install Violin?

Run hermes profile install with this repository's URL, then switch to the profile with hermes -p violin. After that, point it at an authorized target to begin scope collection.

Similar security for Hermes Agent

All security

Related guides: How to run Hermes Agent securely