Teknium says Hermes checks nearly 500 plugins for malware, not security hardening
Teknium says Hermes lists nearly 500 plugins, but only eight are officially tested. Community submissions get malware and guideline checks, not broader security hardening.

TL;DR
- Hermes has nearly 500 catalog mods, according to Teknium's announcement, with eight official plugins described as tested in his reply.
- Community submissions get malware and guideline checks, according to Teknium's follow-up; broader security hardening falls outside the review he described in an earlier clarification.
- Approval follows a specific commit: the submission rules linked in Teknium's follow-up require exact SHA pins and another reviewed PR for updates.
Desktop plugins get a startling amount of trust: they execute with the app's full authority and no sandbox. Plugin dependencies also fall outside Hermes's own 14-day release quarantine. A reviewed caution finding can pass installation without another prompt.
Catalog size and official testing
Teknium, cofounder of Nous Research, named four types of additions in his catalog announcement:
- New agent capabilities.
- Model providers.
- Memory enhancements.
- Visual components.
The plugin directory offers separate Official and Community filters. Teknium identified eight official plugins as “the tested ones.”
Malware screening
Review covers whether submissions contain viruses or are malicious to Hermes users. Teknium said plugins “aren't verified to be security hardened in themselves” in his clarification.
Hermes handles scanner findings through three paths under its catalog trust model:
dangerous: blocks catalog admission and installation.cautionat the reviewed SHA: appears in CI for the maintainer to read; installation accepts it without asking again.- Raw URL or another revision: receives the normal warning prompt for
cautionfindings.
Commit pins and reviewed updates
A plugin reaches the catalog through the human-merged process in the submission rules:
- The repository owner or a major contributor submits an entry, or maintainers add it through a reviewed community sweep. There is no automatic ingestion.
- The entry pins a full 40-character commit SHA. Branches, tags and abbreviated SHAs are rejected.
- Catalog CI clones that commit and runs
hermes plugins validate /path/to/your-plugin --install-deps. - A maintainer reads the pinned tree and merges, requests changes or declines.
Every pin update requires another PR, with reviewers examining the upstream commit range. Listed plugins cannot fetch replacement code or update themselves.
For catalog installs, hermes plugins update <name> checks out the newly reviewed pin rather than running git pull, according to the update documentation. Failed dependency validation or publication keeps the working installation in place.
Desktop plugin authority
A Desktop plugin runs in the same JavaScript realm as the application's own code. It can access these surfaces under the documented runtime model:
- Gateway RPC.
- The full
window.hermesDesktopbridge. - Other plugins' storage.
The loader isolates errors, not capabilities. Admission lint restricts plugins to the SDK, and the loader checks non-SDK imports again at load time; the documentation explicitly describes the lint as a review aid rather than a guarantee.
Capabilities and credential rules
Admission includes behavioral restrictions beyond the malware scan. The catalog rules require:
- Accurate declarations: the
capabilitiesblock must match registered tools, hooks, middleware and environment variables. Undeclared capability creep fails validation. - Public extension points: Python plugins cannot replace, wrap or rebind Hermes core functions or private tables at runtime.
- SDK-only Desktop code: prototype patching,
eval,new Function, non-SDK imports, script injection and rewriting core UI are prohibited. - Credential ownership: reading another client's login must be disclosed and receive a maintainer trust-tier decision. Refreshing or writing another client's OAuth tokens requires an explicit ruling.
- Approval preservation: plugins cannot auto-approve actions, disable guards or launch child processes in YOLO or non-interactive mode to bypass approval.
- Risk disclosure: third-party network calls, external file reads, shell commands, background processes and stored credentials belong in the PR description and README. Telemetry is opt-in.
Unattended runs also have a specific requirement: prompts and OAuth browser flows must fail cleanly or time out rather than hang cron jobs or messaging gateways.
Plugin dependency quarantine
Hermes applies a 14-day exclude-newer quarantine to its own dependencies. Plugin python_dependencies and pyproject.toml packages follow the plugin's policy instead, while remaining subject to Hermes's core dependency constraints, under the dependency admission rule.
Reviewers request an older API-compatible floor plus an upper bound when dependencies use bare >=X requirements or floors on the newest release. A recent floor alone does not hold an entry.
Delisting and security removal
Hermes distinguishes two outcomes in its removal rules:
- Delisting: deletes the catalog entry for an unmaintained, superseded or noncompliant plugin. Existing installations remain.
- Security or policy removal: adds the plugin to
removed.yaml. Installation is refused, existing copies stop updating, and they cannot be enabled.
Removal enforcement also happens at load time, according to the catalog documentation.
Clients fetch the live catalog at most once every six hours. Offline, they use the cached copy for up to 24 hours before falling back to the shipped catalog; both in-tree and live removal lists are enforced under the refresh rules.
Catalog redesign and team size
A catalog redesign was underway but had not gone live, Teknium said in a reply. He described Hermes as an open-source project built by a four-person team, with three more people joining.
He also mocked the prospect of making Hermes “like every single other ai product” in another reply.
Discord setup checks
Discord onboarding gained five concrete changes in Teknium's separate update:
- Invalid bot tokens are requested again and never saved.
- Disabled Message Content Intent gets a direct link to the toggle, followed by another check.
- Setup prints a bot invite link with the correct permissions.
- The owner is detected and allowlisted without requiring Developer Mode.
- The
.envtemplate includes a Discord section.