Hermes Atlas
Security & sandboxing

Agent Install Monitor

swytchcodehq/agent-install-monitor

Local history of every package, Docker image and repository your Hermes Agent installs

In short

Agent Install Monitor is a Hermes Agent plugin that records the packages, Docker images, Git repositories and services the agent installs on your machine.

What Agent Install Monitor does

Coding agents install packages, pull images, clone repositories and start services on your behalf, and weeks later it is hard to remember why. This plugin keeps a local record per session in a SQLite file at $HERMES_HOME/agent-monitor/monitor.db, which defaults to ~/.hermes/agent-monitor/monitor.db. Nothing leaves the machine. After using Hermes normally, run agent-monitor history, sessions, session or export with json or csv output.

Detection covers many package managers (npm, pip, uv, cargo, brew, apt and others), docker and podman pulls and runs, docker compose up, git clone and submodules, runtimes such as npx and uvx, service starts like systemctl start, database creation, and curl or wget downloads of installer files. The README calls it an observability tool, not a control layer: it does not change execution, uninstall anything or roll back. Detection is a best-effort command-string match, not a security boundary.

Key features

  • Per-session history of installs, pulls, clones and service starts
  • Local SQLite storage with nothing sent off the machine
  • agent-monitor CLI with history, sessions, session and export commands
  • Export to JSON or CSV
  • One-line installer that finds Hermes's own virtual environment

When to use it

  • Answering why Playwright or a Docker image appeared on your machine
  • Reviewing what changed during one agent task
  • Exporting install history for an audit or a handoff

Who it is for: Hermes Agent users who give the agent shell access and want a record of the environment changes it makes.

How it fits with Hermes Agent

Built for Hermes Agent as a plugin. It works with Hermes today, and the README lists Claude Code and OpenClaw as planned.

How to install Agent Install Monitor

These commands are copied from the project's README. Check the repository for the latest steps before you run them.

curl -fsSL https://raw.githubusercontent.com/swytchcodehq/agent-install-monitor/main/install.py | python3
irm https://raw.githubusercontent.com/swytchcodehq/agent-install-monitor/main/install.py | python -

Requirements: A Hermes Agent installation; the installer finds Hermes's own virtual environment

FAQ

What is Agent Install Monitor?

Agent Install Monitor is a Hermes Agent plugin that logs what the agent installs, such as packages, Docker images, Git repositories and services, into a local database you can query.

How do I install Agent Install Monitor?

Run the installer one-liner for your system: the curl command on macOS, Linux or WSL, or the PowerShell irm command on Windows. It installs into Hermes's own virtual environment and enables the plugin, and it is safe to re-run.

Is Agent Install Monitor a security tool that blocks installs?

No. The README calls it an observability tool, not a control layer. It does not modify execution, uninstall packages or roll back, and its detection is a best-effort command-string match.

Similar security for Hermes Agent

All security

Related guides: How to run Hermes Agent securely