agentCLAWHUBUnverified

hermes-attestation-guardian

Hermes-only runtime security attestation and drift detection skill for operator-managed Hermes infrastructure. Skill: hermes-attestation-guardian Owner: davida-ps Summary: Hermes-only runtime security attestation and drift detection skill for operator-managed Hermes infrastructure. Tags: latest:0.1.3 Version history: v0.1.3 | 2026-05-24T18:48:08.071Z | user Release 0.1.3 via CI v0.1.2 | 2026-05-16T21:44:23.135Z | user Release 0.1.2 via CI v0.1.1 | 2026-05-14T11:43:07.920Z | user Release 0.1.1 via CI v0.1.0 | 2026-04-21T11:00:

OpenClaw

Rank

62

Safety

84

Downloads

1.2k

Updated

Oct 10, 2026

Version

0.1.3

Source

CLAWHUB

About

What it does, and when to use it.

Capability contract not published. No trust telemetry is available yet. 1.2K downloads reported by the source. Last updated 10/10/2026.

Avoid when

  • Contract metadata is missing or unavailable for deterministic execution.

Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing

Public facts

Every fact links back to the source it came from.

Vendor
Clawhubvendor · observed Oct 10, 2026
Protocol compatibility
OpenClawcompatibility · observed Oct 10, 2026
Adoption signal
1.2K downloadsadoption · observed Oct 10, 2026
Latest release
0.1.3release · observed May 24, 2026
Handshake status
UNKNOWNsecurity

Install and run

Setup complexity: low.

clawhub skill install s17ewxqmthh68xc4bv5vc6f30183jsf1:hermes-attestation-guardian
  1. Setup complexity is LOW. This package is likely designed for quick installation with minimal external side-effects.
  2. Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data.

Contract: missing

curl -s "https://www.xpersona.co/api/v1/agents/clawhub-davida-ps-hermes-attestation-guardian/snapshot"

Documentation

CLAWHUB

101,237 characters of source documentation, loaded on request.

Extracted files

5 files captured from the source.

SKILL.md

---
name: hermes-attestation-guardian
version: 0.1.3
description: Hermes-only runtime security attestation and drift detection skill for operator-managed Hermes infrastructure.
homepage: https://clawsec.prompt.security
hermes:
  emoji: "🛡️"
  requires:
    bins: [node]
---

# Hermes Attestation Guardian

IMPORTANT SCOPE:
- This skill targets Hermes infrastructure only (CLI/Gateway/profile-managed deployments).
- This skill is not an OpenClaw runtime hook package.


## Release Artifact Verification

For standalone installs, verify the signed release manifest before trusting `SKILL.md`, `skill.json`, or the archive. The `skill.json` file is the package metadata/SBOM source, and the release pipeline signs `checksums.json` with the ClawSec release key.

```bash
set -euo pipefail

SKILL_NAME="hermes-attestation-guardian"
VERSION="0.1.3"
REPO="prompt-security/clawsec"
TAG="${SKILL_NAME}-v${VERSION}"
BASE="https://github.com/${REPO}/releases/download/${TAG}"
ZIP_NAME="${SKILL_NAME}-v${VERSION}.zip"
TMP_DIR="$(mktemp -d)"
trap 'rm -rf "$TMP_DIR"' EXIT

RELEASE_PUBKEY_SHA256="711424e4535f84093fefb024cd1ca4ec87439e53907b305b79a631d5befba9c8"

curl -fsSL "$BASE/checksums.json" -o "$TMP_DIR/checksums.json"
curl -fsSL "$BASE/checksums.sig" -o "$TMP_DIR/checksums.sig"
curl -fsSL "$BASE/signing-public.pem" -o "$TMP_DIR/signing-public.pem"
curl -fsSL "$BASE/$ZIP_NAME" -o "$TMP_DIR/$ZIP_NAME"
curl -fsSL "$BASE/SKILL.md" -o "$TMP_DIR/SKILL.md"
curl -fsSL "$BASE/skill.json" -o "$TMP_DIR/skill.json"

ACTUAL_PUBKEY_SHA256="$(openssl pkey -pubin -in "$TMP_DIR/signing-public.pem" -outform DER | shasum -a 256 | awk '{print $1}')"
if [ "$ACTUAL_PUBKEY_SHA256" != "$RELEASE_PUBKEY_SHA256" ]; then
  echo "ERROR: signing-public.pem fingerprint mismatch" >&2
  exit 1
fi

openssl base64 -d -A -in "$TMP_DIR/checksums.sig" -out "$TMP_DIR/checksums.sig.bin"
openssl pkeyutl -verify -rawin -pubin \
  -inkey "$TMP_DIR/signing-public.pem" \
  -sigfile "$TMP_DIR/checksums.sig.bin" \
  -in "$TMP_DIR/checksums.json" >/dev/null

hash_file() {
  if command -v shasum >/dev/null 2>&1; then
    shasum -a 256 "$1" | awk '{print $1}'
  else
    sha256sum "$1" | awk '{print $1}'
  fi
}

verify_manifest_file() {
  asset="$1"
  path="$2"
  expected="$(jq -r --arg asset "$asset" '.files[$asset].sha256 // empty' "$TMP_DIR/checksums.json")"
  if [ -z "$expected" ]; then
    echo "ERROR: checksums.json missing $asset" >&2
    exit 1
  fi
  actual="$(hash_file "$path")"
  if [ "$actual" != "$expected" ]; then
    echo "ERROR: checksum mismatch for $asset" >&2
    exit 1
  fi
}

expected_archive="$(jq -r '.archive.sha256 // empty' "$TMP_DIR/checksums.json")"
if [ -z "$expected_archive" ]; then
  echo "ERROR: checksums.json missing archive.sha256" >&2
  exit 1
fi
actual_archive="$(hash_file "$TMP_DIR/$ZIP_NAME")"
if [ "$actual_archive" != "$expected_archive" ]; then
  echo "ERROR: archive checksum mismatch" >&2
  exit 1
fi

verify_manifest_file "SKILL.md" "$TMP_DIR/SKILL.md"
verify_manifest_file "skill

README.md

# hermes-attestation-guardian

Hermes-only attestation, advisory verification, and guarded verification workflow.

Status: implemented (v0.1.0), Hermes-only.

## Capabilities

This skill now covers the full Hermes-side capability set expected from the clawsec-suite parity workstream:

- Deterministic runtime posture attestation generation.
- Fail-closed attestation verification (schema + canonical digest).
- Optional detached signature verification for attestation artifacts.
- Authenticated baseline diffing with stable severity classification.
- Scoped output-path enforcement under `$HERMES_HOME`.
- Signed advisory feed verification (Ed25519) with optional checksum-manifest verification.
- Fail-closed advisory verification state persistence under `$HERMES_HOME/security/advisories`.
- Advisory-aware guarded skill verification with explicit `--confirm-advisory` override.
- Optional recurring scheduler helpers for attestation and advisory checks (print-only by default, explicit apply mode).
- Sandboxed end-to-end regression harness for install + verify + advisory gates.

## Quickstart

Canonical release verification and trust-policy guidance lives in `SKILL.md`:
- `Mandatory release verification gate (before install)`
- `Hermes guard trust policy note`

After running that gate, use:

```bash
node scripts/generate_attestation.mjs
node scripts/verify_attestation.mjs --input ~/.hermes/security/attestations/current.json
node scripts/refresh_advisory_feed.mjs
node scripts/check_advisories.mjs
node scripts/guarded_skill_verify.mjs --skill some-skill --version 1.2.3
node scripts/setup_attestation_cron.mjs --every 6h --print-only
node scripts/setup_advisory_check_cron.mjs --every 6h --skill some-skill --print-only
```

Scheduler safety warning: never leave `--allow-unsigned` enabled in recurring advisory check jobs except during short emergency recovery windows.

## Runtime requirements

Required:
- `node`

Optional tooling (for local verification workflows):
- `openssl`, `bash`, `docker`

## Tests

```bash
node test/attestation_schema.test.mjs
node test/attestation_diff.test.mjs
node test/attestation_cli.test.mjs
node test/setup_attestation_cron.test.mjs
node test/setup_advisory_check_cron.test.mjs
node test/feed_verification.test.mjs
node test/guarded_skill_verify.test.mjs
bash test/hermes_attestation_sandbox_regression.sh
```

_meta.json

{
  "ownerId": "kn76m78f01hqrtpgm895s0jsax80jd8v",
  "slug": "hermes-attestation-guardian",
  "version": "0.1.3",
  "publishedAt": 1779648488071
}

CHANGELOG.md

# Changelog

## [0.1.3] - 2026-05-24

### Changed
- Documented that the default signed advisory feed is consolidated and may include NVD CVEs, approved community advisories, and provisional GHSA-without-CVE records while Hermes matching remains package-scoped.

## [0.1.2] - 2026-05-15

### Fixed
- Included `lib/semver.mjs` and `lib/cron.mjs` in the release SBOM so signed archives contain every runtime library imported by shipped scripts.

## [0.1.1] - 2026-05-13

### Security
- Added explicit signed release artifact verification instructions for standalone installs, including `checksums.json`, `checksums.sig`, `signing-public.pem`, archive hash verification, and `SKILL.md`/`skill.json` checksum checks.

### Changed
- Re-release skill payload metadata after excluding test-only files from release SBOMs and archives.

## [0.1.0] - 2026-04-21

- Added mandatory release verification gate guidance before install: `checksums.json`, `checksums.sig`, and pinned signing public-key fingerprint.
- Added explicit Hermes guard trust-policy note for signature-aware trust (trusted signer fingerprint allowlist) over source-name-only trust.
- Moved sandbox regression harness into the skill test surface (`test/hermes_attestation_sandbox_regression.sh`) and fixed in-skill default path resolution.
- Tightened advisory feed verification to require checksum-manifest artifacts when checksum-manifest verification is enabled (fail-closed when missing).
- Added feed regression coverage for missing local/remote checksum-manifest artifacts under strict verification mode.
- Refactored cron setup scripts to share managed-block helpers from `lib/cron.mjs`, reducing drift risk.
- Added explicit `.mjs` scan/test coverage guidance so Hermes-side scanner scope and regression harness context stay aligned with `scripts/*.mjs`, `lib/*.mjs`, and `test/*.test.mjs`.
- Clarified fresh-node first-run edge-case documentation.
- Clarified Hermes runtime metadata/frontmatter and README capability coverage for ClawHub publishing.
- Removed compatibility-report wiki page references in favor of README capability matrix as the primary compatibility surface.
- Updated skill metadata/docs to v0.1.0 and aligned README quickstart with fail-closed verification expectations.

## [0.0.1] - 2026-04-15

- Implemented deterministic Hermes attestation generator CLI (`scripts/generate_attestation.mjs`).
- Implemented fail-closed verifier CLI with schema, canonical digest, expected checksum, and optional detached signature checks (`scripts/verify_attestation.mjs`).
- Implemented meaningful baseline diff engine with stable severity mapping for risky toggle regressions, feed verification regressions, trust anchor drift, and watched file drift (`lib/diff.mjs`).
- Implemented Hermes-only cron setup helper with print-only default and managed-block apply mode (`scripts/setup_attestation_cron.mjs`).
- Added shared attestation library for canonicalization, schema validation, digest generation, and policy parsing (`li

skill-card.md

## Description:

Hermes-only runtime security attestation and drift detection skill for operator-managed Hermes infrastructure.

This skill is ready for commercial/non-commercial use.

## Publisher:

[davida-ps](https://clawhub.ai/user/davida-ps)

### License/Terms of Use:

MIT-0

## Use Case:

Developers and operators use this skill to generate deterministic Hermes posture attestations, verify attestation integrity fail-closed, compare authenticated baseline drift, and run advisory-aware guarded verification for Hermes-managed infrastructure.

### Deployment Geography for Use:

Global

## Known Risks and Mitigations:

Risk: Attestations may expose watched file paths, trust anchor paths, and hashes from Hermes security state.

Mitigation: Review watch_files and trust_anchor_files before use, protect ~/.hermes, and limit access to generated attestation artifacts.

Risk: Recurring scheduler setup can mutate the current user's cron state when --apply is used.

Mitigation: Preview scheduler entries with --print-only, avoid running scheduled jobs as root, and apply only the managed Hermes schedule blocks intentionally.

Risk: Unsigned advisory feed bypass weakens fail-closed verification.

Mitigation: Use --allow-unsigned only during a short audited emergency window and remove it immediately after recovery.

Risk: Using the skill outside Hermes infrastructure can produce unsupported trust and attestation assumptions.

Mitigation: Install and operate the skill only for Hermes CLI, Gateway, or profile-managed deployments.

## Reference(s):

- [ClawSec Homepage](https://clawsec.prompt.security)
- [ClawHub Skill Page](https://clawhub.ai/davida-ps/skills/hermes-attestation-guardian)
- [Skill Operator Playbook](artifact/SKILL.md)
- [Capability Overview](artifact/README.md)
- [Release Changelog](artifact/CHANGELOG.md)

## Skill Output:

**Output Type(s):** [text, markdown, code, shell commands, configuration, guidance]

**Output Format:** [Markdown guidance with shell commands and JSON configuration artifacts]

**Output Parameters:** [1D]

**Other Properties Related to Output:** [Produces Hermes attestation JSON files, optional sha256 sidecar files, advisory feed verification state, and optional managed cron entries when explicitly applied.]

## Skill Version(s):

0.1.3 (source: frontmatter, changelog, server release evidence; released 2026-05-24)

## Ethical Considerations:

Users should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.
Github ReposUpdated 1d agoRank 70

AionUi

Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!

MCPOPENCLAW
Github ReposUpdated 6mo agoRank 70

activepieces

AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents

OPENCLAW
Github ReposUpdated 6mo agoRank 70

cherry-studio

AI productivity studio with smart chat, autonomous agents, and 300+ assistants.

MCPOPENCLAW
Github ReposUpdated 7mo agoRank 70

CopilotKit

The Frontend for Agents & Generative UI. React + Angular

OPENCLAW

Machine-readable data

The same record, as JSON, for agents and crawlers.

{
  "facts": [
    {
      "factKey": "vendor",
      "category": "vendor",
      "label": "Vendor",
      "value": "Clawhub",
      "href": "https://clawhub.ai/davida-ps/skills/hermes-attestation-guardian",
      "sourceUrl": "https://clawhub.ai/davida-ps/skills/hermes-attestation-guardian",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-10-10T22:09:15.455Z",
      "isPublic": true
    },
    {
      "factKey": "protocols",
      "category": "compatibility",
      "label": "Protocol compatibility",
      "value": "OpenClaw",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-davida-ps-hermes-attestation-guardian/contract",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-davida-ps-hermes-attestation-guardian/contract",
      "sourceType": "contract",
      "confidence": "medium",
      "observedAt": "2026-10-10T22:09:15.455Z",
      "isPublic": true
    },
    {
      "factKey": "traction",
      "category": "adoption",
      "label": "Adoption signal",
      "value": "1.2K downloads",
      "href": "https://clawhub.ai/davida-ps/hermes-attestation-guardian",
      "sourceUrl": "https://clawhub.ai/davida-ps/hermes-attestation-guardian",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-10-10T22:09:15.455Z",
      "isPublic": true
    },
    {
      "factKey": "latest_release",
      "category": "release",
      "label": "Latest release",
      "value": "0.1.3",
      "href": "https://clawhub.ai/davida-ps/hermes-attestation-guardian",
      "sourceUrl": "https://clawhub.ai/davida-ps/hermes-attestation-guardian",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-05-24T18:48:08.071Z",
      "isPublic": true
    },
    {
      "factKey": "handshake_status",
      "category": "security",
      "label": "Handshake status",
      "value": "UNKNOWN",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-davida-ps-hermes-attestation-guardian/trust",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-davida-ps-hermes-attestation-guardian/trust",
      "sourceType": "trust",
      "confidence": "medium",
      "observedAt": null,
      "isPublic": true
    }
  ],
  "events": [
    {
      "eventType": "release",
      "title": "Release 0.1.3",
      "description": "Release 0.1.3 via CI",
      "href": "https://clawhub.ai/davida-ps/hermes-attestation-guardian",
      "sourceUrl": "https://clawhub.ai/davida-ps/hermes-attestation-guardian",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-05-24T18:48:08.071Z",
      "isPublic": true
    }
  ]
}

Record generated Oct 10, 2026.

Sponsored

Ads related to hermes-attestation-guardian and adjacent AI workflows.