Agent Install Monitor
swytchcodehq/agent-install-monitor
Local history of every package, Docker image and repository your Hermes Agent installs
Agent Install Monitor is a Hermes Agent plugin that records the packages, Docker images, Git repositories and services the agent installs on your machine.
What Agent Install Monitor does
Coding agents install packages, pull images, clone repositories and start services on your behalf, and weeks later it is hard to remember why. This plugin keeps a local record per session in a SQLite file at $HERMES_HOME/agent-monitor/monitor.db, which defaults to ~/.hermes/agent-monitor/monitor.db. Nothing leaves the machine. After using Hermes normally, run agent-monitor history, sessions, session or export with json or csv output.
Detection covers many package managers (npm, pip, uv, cargo, brew, apt and others), docker and podman pulls and runs, docker compose up, git clone and submodules, runtimes such as npx and uvx, service starts like systemctl start, database creation, and curl or wget downloads of installer files. The README calls it an observability tool, not a control layer: it does not change execution, uninstall anything or roll back. Detection is a best-effort command-string match, not a security boundary.
Key features
- Per-session history of installs, pulls, clones and service starts
- Local SQLite storage with nothing sent off the machine
- agent-monitor CLI with history, sessions, session and export commands
- Export to JSON or CSV
- One-line installer that finds Hermes's own virtual environment
When to use it
- Answering why Playwright or a Docker image appeared on your machine
- Reviewing what changed during one agent task
- Exporting install history for an audit or a handoff
Who it is for: Hermes Agent users who give the agent shell access and want a record of the environment changes it makes.
How it fits with Hermes Agent
Built for Hermes Agent as a plugin. It works with Hermes today, and the README lists Claude Code and OpenClaw as planned.
How to install Agent Install Monitor
These commands are copied from the project's README. Check the repository for the latest steps before you run them.
curl -fsSL https://raw.githubusercontent.com/swytchcodehq/agent-install-monitor/main/install.py | python3
irm https://raw.githubusercontent.com/swytchcodehq/agent-install-monitor/main/install.py | python -Requirements: A Hermes Agent installation; the installer finds Hermes's own virtual environment
FAQ
What is Agent Install Monitor?
Agent Install Monitor is a Hermes Agent plugin that logs what the agent installs, such as packages, Docker images, Git repositories and services, into a local database you can query.
How do I install Agent Install Monitor?
Run the installer one-liner for your system: the curl command on macOS, Linux or WSL, or the PowerShell irm command on Windows. It installs into Hermes's own virtual environment and enables the plugin, and it is safe to re-run.
Is Agent Install Monitor a security tool that blocks installs?
No. The README calls it an observability tool, not a control layer. It does not modify execution, uninstall packages or roll back, and its detection is a best-effort command-string match.
Similar security for Hermes Agent
All securitySecurity layer for Hermes Agent with taint tracking, a policy engine and outbound secret scrubbing
danieljustus Symaira VaultGo command-line password manager with age encryption and an MCP server for AI agents
Adolanium Hermes Plugin ShodanShodan host intel, search, DNS and CVE lookups for Hermes Agent, with credit budgeting
skalenetwork ReefRun Hermes, OpenClaw and your own agents in microsandbox microVMs with TOML-defined policy
aiconnai AgentShieldOffline Rust scanner for risky behavior in MCP servers and agent tools, with a Hermes Agent adapter
anpicasso Hermes Jev ApprovalsPlugin that serves TypeSafe's Jev model as the reviewer for Hermes Agent smart command approvals
Related guides: How to run Hermes Agent securely