Hermes Atlas
Security & sandboxing · works with Hermes Agent

Linmas

TanKimGwan/linmas

Proof-carrying defensive security reviews for AI-assisted code with deterministic policy and portable evidence

In short

Linmas is a Node.js CLI that turns one explicit code change into a normalized security finding, a deterministic policy decision and a portable Review Capsule. It is Codex-first and also tagged as a Hermes Agent skill, with human review required for every result.

What Linmas does

Linmas is a Node.js CLI for proof-carrying defensive security reviews of AI-assisted software. It takes one explicit change and turns it into a normalized finding, a deterministic policy decision and a portable Review Capsule that is bound to the exact input bytes with SHA-256. Human review is required for every result, and the README states that a policy pass or a valid proof bundle is evidence, never automatic approval.

A default offline demo replays a synthetic SQL-injection change with no model call and no credentials, evaluating the baseline-appsec policy. Live review through Codex is opt-in behind --live --yes. Release 0.9.0 added compatibility guidance for eleven security skills and seven MCP tools. Linmas is Codex-first as a native integration, and the repository is also tagged for Claude Code and Hermes Agent skills. Usage guides are in English and Bahasa Indonesia.

Key features

  • Normalized security finding from a single explicit change
  • Deterministic policy evaluation, with a baseline-appsec policy
  • Review Capsule evidence bound to input bytes with SHA-256
  • Offline fixture demo needing no credentials or network
  • Opt-in live Codex review behind --live --yes
  • Eleven security skills and seven MCP tools with compatibility guidance

When to use it

  • Reviewing an AI-generated diff for issues such as SQL injection before merging
  • Producing portable evidence of a security review for later audit
  • Trying the review pipeline offline before connecting any model

Who it is for: Developers and security reviewers who use AI coding agents and want auditable, human-reviewed security checks.

How it fits with Hermes Agent

The repository is tagged hermes-agent and hermes-skill and describes itself as portable across AI coding agents. The opening part of the README names Codex as the native integration and does not detail Hermes-specific steps.

How to install Linmas

These commands are copied from the project's README. Check the repository for the latest steps before you run them.

npm install --global linmas@0.9.1
linmas --version

Requirements: Node.js 24 or newer

Note: Linmas is Codex-first as a native integration, and the README says compatibility with other agents depends on the integration level.

FAQ

What is Linmas?

Linmas is a CLI for defensive security reviews of AI-assisted software. It produces a normalized finding, a deterministic policy decision and a portable Review Capsule, and always requires human review.

Does Linmas work with Hermes Agent?

The repository is tagged hermes-agent and hermes-skill, and the README says Linmas stays portable across AI coding agents. Codex is the native integration, and compatibility with other agents depends on the integration level described in its compatibility document.

How do I install Linmas?

Run npm install --global linmas@0.9.1 with Node.js 24 or newer, then check it with linmas --version. To try the offline demo from a clone, run npm ci and npm run demo:judge.

Similar security for Hermes Agent

All security

Related guides: How to run Hermes Agent securely