Hermes Atlas
Security & sandboxing

Hermes-Aegis

Tranquil-Flow/hermes-aegis

Security layer for Hermes Agent: a MITM proxy that blocks secret leaks and dangerous commands

In short

Hermes-Aegis is a security extension for Hermes Agent that wraps the agent in a transparent MITM proxy. It scans outbound requests for secrets, keeps API keys in an encrypted vault and blocks risky commands.

What Hermes-Aegis does

Hermes-Aegis wraps Hermes Agent with a transparent MITM proxy that scans all outbound HTTP for API keys, tokens and credentials and blocks the request when it finds one. Real API keys stay in a keyring-backed encrypted vault and are injected by the proxy, so they never sit in the agent's memory. Commands are checked against 35 risky patterns covering shell injection, destructive operations, privilege escalation and SSH exfiltration, and in gateway mode a patch blocks them outright when AEGIS_ACTIVE=1 instead of prompting.

Other controls include an optional domain allowlist, rate-burst detection that escalates to blocking, Docker network isolation, Tirith scanning of LLM responses for homograph URLs and code injection, pluggable approval backends (block, log_only, webhook) and a hash-chained audit log. Version 0.2.0 targets Hermes v0.11 with hybrid plugin packaging, and hermes update calls hermes-aegis update so patches are re-applied. The README reports that its own benchmark blocked all 10 exfiltration scenarios, with a median scan time near 70 microseconds.

Key features

  • Transparent MITM proxy that blocks secrets in request bodies, headers and URLs
  • Encrypted vault that injects API keys so they stay out of agent memory
  • 35 dangerous-command patterns, with outright blocking in gateway mode
  • Optional outbound domain allowlist and rate-burst escalation
  • Hash-chained audit log, reactive audit agents and scheduled reports through Hermes cron
  • Docker container isolation and macOS gateway sandbox support

When to use it

  • Stop an agent from sending API keys or tokens to an outside server
  • Block destructive shell commands when Hermes runs unattended through the gateway
  • Keep an audit trail of security events and approval decisions

Who it is for: Hermes Agent users who run the agent unattended or with broad credentials and want an extra layer of outbound and command control.

How it fits with Hermes Agent

It is built specifically for Hermes Agent, as a hybrid plugin plus proxy that is updated together with Hermes through hermes update.

Note: Blocking in gateway mode relies on a patch to Hermes Agent that Aegis re-applies after updates.

FAQ

What is Hermes-Aegis?

Hermes-Aegis is a security hardening layer for Hermes Agent. It routes the agent's traffic through a MITM proxy that blocks secret leaks and flags dangerous commands.

Does Hermes-Aegis work with Hermes Agent?

Yes. It is made for Hermes Agent, and version 0.2.0 is the compatibility release for Hermes v0.11. hermes update calls hermes-aegis update so both stay current.

Is Hermes-Aegis free and open source?

Yes, Hermes-Aegis is open source and MIT licensed.

Similar security for Hermes Agent

All security

Related guides: How to run Hermes Agent securely