Linmas
TanKimGwan/linmas
Proof-carrying defensive security reviews for AI-assisted code with deterministic policy and portable evidence
Linmas is a Node.js CLI that turns one explicit code change into a normalized security finding, a deterministic policy decision and a portable Review Capsule. It is Codex-first and also tagged as a Hermes Agent skill, with human review required for every result.
What Linmas does
Linmas is a Node.js CLI for proof-carrying defensive security reviews of AI-assisted software. It takes one explicit change and turns it into a normalized finding, a deterministic policy decision and a portable Review Capsule that is bound to the exact input bytes with SHA-256. Human review is required for every result, and the README states that a policy pass or a valid proof bundle is evidence, never automatic approval.
A default offline demo replays a synthetic SQL-injection change with no model call and no credentials, evaluating the baseline-appsec policy. Live review through Codex is opt-in behind --live --yes. Release 0.9.0 added compatibility guidance for eleven security skills and seven MCP tools. Linmas is Codex-first as a native integration, and the repository is also tagged for Claude Code and Hermes Agent skills. Usage guides are in English and Bahasa Indonesia.
Key features
- Normalized security finding from a single explicit change
- Deterministic policy evaluation, with a baseline-appsec policy
- Review Capsule evidence bound to input bytes with SHA-256
- Offline fixture demo needing no credentials or network
- Opt-in live Codex review behind --live --yes
- Eleven security skills and seven MCP tools with compatibility guidance
When to use it
- Reviewing an AI-generated diff for issues such as SQL injection before merging
- Producing portable evidence of a security review for later audit
- Trying the review pipeline offline before connecting any model
Who it is for: Developers and security reviewers who use AI coding agents and want auditable, human-reviewed security checks.
How it fits with Hermes Agent
The repository is tagged hermes-agent and hermes-skill and describes itself as portable across AI coding agents. The opening part of the README names Codex as the native integration and does not detail Hermes-specific steps.
How to install Linmas
These commands are copied from the project's README. Check the repository for the latest steps before you run them.
npm install --global linmas@0.9.1
linmas --versionRequirements: Node.js 24 or newer
Note: Linmas is Codex-first as a native integration, and the README says compatibility with other agents depends on the integration level.
FAQ
What is Linmas?
Linmas is a CLI for defensive security reviews of AI-assisted software. It produces a normalized finding, a deterministic policy decision and a portable Review Capsule, and always requires human review.
Does Linmas work with Hermes Agent?
The repository is tagged hermes-agent and hermes-skill, and the README says Linmas stays portable across AI coding agents. Codex is the native integration, and compatibility with other agents depends on the integration level described in its compatibility document.
How do I install Linmas?
Run npm install --global linmas@0.9.1 with Node.js 24 or newer, then check it with linmas --version. To try the offline demo from a clone, run npm ci and npm run demo:judge.
Similar security for Hermes Agent
All securityHermes Agent plugin that repairs bad tool calls, breaks tool loops and redacts secrets from logs
dafka007 Hermes Security AuditApproval-gated Hermes plugin that runs Gitleaks, OSV-Scanner and Semgrep CE on a workspace
chchchadzilla GitHub Safe PushHermes skill that keeps secrets out of git and checks a project is properly packaged before shipping
xielevi Hermes Dashboard Auth for FeishuFeishu and Lark OAuth sign-in for the Hermes Agent web dashboard, limited to an allow-list of users
cybertecla Hermes Telemetry DashboardDashboard tab that shows what telemetry Hermes Agent would send to Nous before any sending is enabled
angel12 hermes-ldap-authLDAP and Active Directory password login for the Hermes Agent web dashboard, as a Hermes plugin
Related guides: How to run Hermes Agent securely