boks Index
Docs Releases

hermes-agent

2 tools · 1 release line

Nous Research's self-improving agent, and the headless backend Hermes Desktop drives. Each tool carries its own sandbox boundary — they are not the same.

boks hermes
boks hermes-agent

Release lines we maintain · the project decides these

findings shown are the whole project at that line

Tag Resolves to Lifecycle Updated Findings What the tag promises
  • stable — floats, carries security updates
  • unstable — tracks pre-releases, may break
  • eol — frozen, upstream is done

Tools in this project · pick one to inspect

capabilities differ between them

Tool Capabilities Seccomp Findings Image Description
showing hermes hermes-agent from hermes-agent@latest → 0.20.5 stable

Findings

clean

identical on amd64, arm64 — one table describes both

No known findings in this image at the last scan.

These are the findings of hermes-agent, which ships every tool in this project. boks reports and gates; it never edits an image to clear a finding.

Composition

default + bash, coreutils, diffutils, findutils, gawk, git, grep, rg, sed
runtime python
composes bash, coreutils, diffutils, findutils, gawk, git, grep, python, rg, sed

Some tools are only useful composed: a pip-installed CLI needs python as its runtime, bash pulls in coreutils. boks resolves that for you — -e git,python:flake8 composes explicitly.

Composition

default + bash, coreutils, diffutils, findutils, gawk, git, grep, rg, sed
runtime python
composes bash, coreutils, diffutils, findutils, gawk, git, grep, python, rg, sed

Some tools are only useful composed: a pip-installed CLI needs python as its runtime, bash pulls in coreutils. boks resolves that for you — -e git,python:flake8 composes explicitly.

Image

image ghcr.io/boks-sh/hermes-agent:0.20.5
digest
platforms
size 224 MB unpacked · 2 layers
base scratch
signed cosign · verified
last scan

Sandbox boundary

hermes

capabilities

browsernetnomountrorw

Filled is granted to every invocation, outlined to some and not others — see per-subcommand below; the rest need --cap at the point of use.

seccomp tier

per tool

default

The syscall filter applied to this tool's entry point. Tools sharing an image do not share a tier.

dotfiles mapped in

read-only unless noted

  • ~/.hermes · writable
  • ~/.hermes/.install_method · writable

env passed through

15 forwarded

ALL_PROXYGH_TOKENGITHUB_TOKENHERMES_MODELHTTPS_PROXYHTTP_PROXYNOUS_API_KEYNO_PROXYOPENAI_API_KEYOPENAI_BASE_URLOPENROUTER_API_KEYall_proxyhttp_proxyhttps_proxyno_proxy

Nothing else crosses in. No AWS_*, no SSH_AUTH_SOCK unless you ask.

env set by boks

1 set

HERMES_DISABLE_LAZY_INSTALLS

per-subcommand

grants differ

completion + nomount browsernetrw
gateway browser
logs + ro browsernetrw
mcp browser
proxy browser
serve browser
status + ro browsernetrw
worktree browsernet

Where a tool needs more for one subcommand only, boks scopes it there rather than granting it everywhere. Where it needs less, boks takes it away there too.

Sandbox boundary

hermes-agent

capabilities

netrw

Filled is granted to every invocation; the rest need --cap at the point of use.

seccomp tier

per tool

default

The syscall filter applied to this tool's entry point. Tools sharing an image do not share a tier.

dotfiles mapped in

read-only unless noted

  • ~/.hermes · writable
  • ~/.hermes/.install_method · writable

env passed through

12 forwarded

ALL_PROXYHERMES_MODELHTTPS_PROXYHTTP_PROXYNO_PROXYOPENAI_API_KEYOPENAI_BASE_URLOPENROUTER_API_KEYall_proxyhttp_proxyhttps_proxyno_proxy

Nothing else crosses in. No AWS_*, no SSH_AUTH_SOCK unless you ask.

env set by boks

1 set

HERMES_DISABLE_LAZY_INSTALLS

per-subcommand

no overrides

Every invocation gets the same boundary. Where a tool needs more for one subcommand only, boks scopes it there rather than granting it everywhere.

Provenance

Every image ships a full SBOM and a signed build attestation. Nothing here is a claim you have to take on trust.

0 findings across this project at latest. Counted once per advisory across every image the project builds.