Hermes-Aegis
Tranquil-Flow/hermes-aegis
Security layer for Hermes Agent: a MITM proxy that blocks secret leaks and dangerous commands
Hermes-Aegis is a security extension for Hermes Agent that wraps the agent in a transparent MITM proxy. It scans outbound requests for secrets, keeps API keys in an encrypted vault and blocks risky commands.
What Hermes-Aegis does
Hermes-Aegis wraps Hermes Agent with a transparent MITM proxy that scans all outbound HTTP for API keys, tokens and credentials and blocks the request when it finds one. Real API keys stay in a keyring-backed encrypted vault and are injected by the proxy, so they never sit in the agent's memory. Commands are checked against 35 risky patterns covering shell injection, destructive operations, privilege escalation and SSH exfiltration, and in gateway mode a patch blocks them outright when AEGIS_ACTIVE=1 instead of prompting.
Other controls include an optional domain allowlist, rate-burst detection that escalates to blocking, Docker network isolation, Tirith scanning of LLM responses for homograph URLs and code injection, pluggable approval backends (block, log_only, webhook) and a hash-chained audit log. Version 0.2.0 targets Hermes v0.11 with hybrid plugin packaging, and hermes update calls hermes-aegis update so patches are re-applied. The README reports that its own benchmark blocked all 10 exfiltration scenarios, with a median scan time near 70 microseconds.
Key features
- Transparent MITM proxy that blocks secrets in request bodies, headers and URLs
- Encrypted vault that injects API keys so they stay out of agent memory
- 35 dangerous-command patterns, with outright blocking in gateway mode
- Optional outbound domain allowlist and rate-burst escalation
- Hash-chained audit log, reactive audit agents and scheduled reports through Hermes cron
- Docker container isolation and macOS gateway sandbox support
When to use it
- Stop an agent from sending API keys or tokens to an outside server
- Block destructive shell commands when Hermes runs unattended through the gateway
- Keep an audit trail of security events and approval decisions
Who it is for: Hermes Agent users who run the agent unattended or with broad credentials and want an extra layer of outbound and command control.
How it fits with Hermes Agent
It is built specifically for Hermes Agent, as a hybrid plugin plus proxy that is updated together with Hermes through hermes update.
Note: Blocking in gateway mode relies on a patch to Hermes Agent that Aegis re-applies after updates.
FAQ
What is Hermes-Aegis?
Hermes-Aegis is a security hardening layer for Hermes Agent. It routes the agent's traffic through a MITM proxy that blocks secret leaks and flags dangerous commands.
Does Hermes-Aegis work with Hermes Agent?
Yes. It is made for Hermes Agent, and version 0.2.0 is the compatibility release for Hermes v0.11. hermes update calls hermes-aegis update so both stay current.
Is Hermes-Aegis free and open source?
Yes, Hermes-Aegis is open source and MIT licensed.
Similar security for Hermes Agent
All securitySafe-by-design USDC and x402 payment plugin for Hermes Agent with human approval for larger transfers
pawel-cell Agent Shopping Safe CheckoutSafe-checkout pattern for agents that buy online: isolated Chrome, virtual card and a human approval gate
jayelbotvibe-web Hermes Pentest LabKali-native pentesting lab with an MCP tool server, guardrails enforced in code and PDF reports
MahdiHedhli HermesUltraCodeHermes plugin that has a second-lab model review each task before a subagent starts writing code
intentframe IntentFrame for Hermes AgentIntentFrame security plugin that checks Hermes terminal, code, file and cron tool calls against policy
mauricemohr88-debug Hermes Plugin GuardStatic security scanner for Hermes Agent plugins that never imports or runs the plugin code
Related guides: How to run Hermes Agent securely