d44a295492
Claude Cowork (Aug 6, 2026) added skill & plugin security scanning: third-party skills and plugins are automatically checked for malicious content on upload/edit, returning pass/warn/fail. Hermes already scans hub-installed skills (tools/skills_guard.py), but `hermes plugins install` cloned and activated arbitrary Git repos completely unscanned — and plugins run Python in-process, making them the more dangerous surface. - tools/plugin_guard.py: plugin-adapted scanner reusing the skills_guard pattern engine. Exempts the documented provider-plugin patterns (own requires_env API-key reads, HTTP calls with keys) on code files while keeping true threat signals (foreign credential-store access, reverse shells, destructive/persistence/obfuscation patterns, prompt injection in docs). Plugin-sized structural limits; VCS/venv dirs excluded. - hermes_cli/plugins_cmd.py: scan the temp clone before it is moved into ~/.hermes/plugins/. safe=install, caution=confirm (interactive prompt or --force), dangerous=blocked (--force does NOT override). Re-scan on `hermes plugins update`; a dangerous updated tree is deactivated until the user reviews the findings. Dashboard install path returns structured scan_blocked/scan_findings. - Config gate: plugins.scan_on_install (default true) in config.yaml. - Validated against all 60 bundled plugins: 57 safe, 3 caution (real sudo / curl|sh content in their docs), 0 false-positive blocks. - 15 new tests incl. E2E through _install_plugin_core with real git clones.
Website
This website is built using Docusaurus, a modern static website generator.
Installation
yarn
Local Development
yarn start
This command starts a local development server and opens up a browser window. Most changes are reflected live without having to restart the server.
Build
yarn build
This command generates static content into the build directory and can be served using any static contents hosting service.
Deployment
Using SSH:
USE_SSH=true yarn deploy
Not using SSH:
GIT_USER=<Your GitHub username> yarn deploy
If you are using GitHub pages for hosting, this command is a convenient way to build the website and push to the gh-pages branch.
Diagram Linting
CI runs ascii-guard to lint docs for ASCII box diagrams. Use Mermaid (````mermaid`) or plain lists/tables instead of ASCII boxes to avoid CI failures.