Index › ai › hermes-agent hermes-agent 2 tools · 1 release line Nous Research's self-improving agent, and the headless backend Hermes Desktop drives. Each tool carries its own sandbox boundary — they are not the same. $ boks hermes ⧉ $ boks hermes-agent ⧉ Source ↗ Registry ↗ Release lines we maintain · the project decides these findings shown are the whole project at that line Tag Resolves to Lifecycle Updated Findings What the tag promises ▸ latest 0.20.5 stable 2026-08-25 0 tracks the newest supported release stable — floats, carries security updates unstable — tracks pre-releases, may break eol — frozen, upstream is done Tools in this project · pick one to inspect capabilities differ between them Tool Capabilities Seccomp Findings Image Description ▸ hermes browsernetnomountrorw default clean hermes-agent Nous Research's self-improving agent CLI ▸ hermes-agent netrw default clean hermes-agent One-shot Hermes agent runner for scripted and non-interactive use ▸ showing hermes hermes-agent from hermes-agent@latest → 0.20.5 stable Findings clean identical on amd64, arm64 — one table describes both No known findings in this image at the last scan. These are the findings of hermes-agent, which ships every tool in this project. boks reports and gates; it never edits an image to clear a finding. Composition default + bash, coreutils, diffutils, findutils, gawk, git, grep, rg, sed runtime python composes bash, coreutils, diffutils, findutils, gawk, git, grep, python, rg, sed Some tools are only useful composed: a pip-installed CLI needs python as its runtime, bash pulls in coreutils. boks resolves that for you — -e git,python:flake8 composes explicitly. Composition default + bash, coreutils, diffutils, findutils, gawk, git, grep, rg, sed runtime python composes bash, coreutils, diffutils, findutils, gawk, git, grep, python, rg, sed Some tools are only useful composed: a pip-installed CLI needs python as its runtime, bash pulls in coreutils. boks resolves that for you — -e git,python:flake8 composes explicitly. Image image ghcr.io/boks-sh/hermes-agent:0.20.5 digest sha256:1501…4908 copy platforms amd64 sha256:61d5…6bf9 copy arm64 sha256:43db…f9aa copy size 224 MB unpacked · 2 layers base scratch signed cosign · verified last scan 2026-08-25 Sandbox boundary hermes capabilities browsernetnomountrorw Filled is granted to every invocation, outlined to some and not others — see per-subcommand below; the rest need --cap at the point of use. seccomp tier per tool default The syscall filter applied to this tool's entry point. Tools sharing an image do not share a tier. dotfiles mapped in read-only unless noted ~/.hermes · writable ~/.hermes/.install_method · writable env passed through 15 forwarded ALL_PROXYGH_TOKENGITHUB_TOKENHERMES_MODELHTTPS_PROXYHTTP_PROXYNOUS_API_KEYNO_PROXYOPENAI_API_KEYOPENAI_BASE_URLOPENROUTER_API_KEYall_proxyhttp_proxyhttps_proxyno_proxy Nothing else crosses in. No AWS_*, no SSH_AUTH_SOCK unless you ask. env set by boks 1 set HERMES_DISABLE_LAZY_INSTALLS per-subcommand grants differ completion + nomount − browsernetrw gateway − browser logs + ro − browsernetrw mcp − browser proxy − browser serve − browser status + ro − browsernetrw worktree − browsernet Where a tool needs more for one subcommand only, boks scopes it there rather than granting it everywhere. Where it needs less, boks takes it away there too. Sandbox boundary hermes-agent capabilities netrw Filled is granted to every invocation; the rest need --cap at the point of use. seccomp tier per tool default The syscall filter applied to this tool's entry point. Tools sharing an image do not share a tier. dotfiles mapped in read-only unless noted ~/.hermes · writable ~/.hermes/.install_method · writable env passed through 12 forwarded ALL_PROXYHERMES_MODELHTTPS_PROXYHTTP_PROXYNO_PROXYOPENAI_API_KEYOPENAI_BASE_URLOPENROUTER_API_KEYall_proxyhttp_proxyhttps_proxyno_proxy Nothing else crosses in. No AWS_*, no SSH_AUTH_SOCK unless you ask. env set by boks 1 set HERMES_DISABLE_LAZY_INSTALLS per-subcommand no overrides Every invocation gets the same boundary. Where a tool needs more for one subcommand only, boks scopes it there rather than granting it everywhere. Provenance sbom amd64 ↗ arm64 ↗ attestation amd64 ↗ arm64 ↗ scan report amd64 ↗ arm64 ↗ grype · 2026-08-25 vex amd64 ↗ arm64 ↗ Every image ships a full SBOM and a signed build attestation. Nothing here is a claim you have to take on trust. 0 findings across this project at latest. Counted once per advisory across every image the project builds.