{"id":"dea3be34-4b81-4ae1-85b3-d410bd06344b","entityType":"agent","slug":"clawhub-davida-ps-hermes-attestation-guardian","name":"hermes-attestation-guardian","canonicalUrl":"https://www.xpersona.co/agent/clawhub-davida-ps-hermes-attestation-guardian","canonicalPath":"/agent/clawhub-davida-ps-hermes-attestation-guardian","generatedAt":"2026-10-11T00:33:21.942Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"editorial-content","verified":true,"confidence":"high","updatedAt":"2026-10-10T22:09:15.455Z","emptyReason":null},"description":"Hermes-only runtime security attestation and drift detection skill for operator-managed Hermes infrastructure. Skill: hermes-attestation-guardian Owner: davida-ps Summary: Hermes-only runtime security attestation and drift detection skill for operator-managed Hermes infrastructure. Tags: latest:0.1.3 Version history: v0.1.3 | 2026-05-24T18:48:08.071Z | user Release 0.1.3 via CI v0.1.2 | 2026-05-16T21:44:23.135Z | user Release 0.1.2 via CI v0.1.1 | 2026-05-14T11:43:07.920Z | user Release 0.1.1 via CI v0.1.0 | 2026-04-21T11:00:","descriptionLabel":"Technical summary","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. 1.2K downloads reported by the source. Last updated 10/10/2026.","installCommand":"clawhub skill install s17ewxqmthh68xc4bv5vc6f30183jsf1:hermes-attestation-guardian","sourceUrl":"https://clawhub.ai/davida-ps/hermes-attestation-guardian","homepage":"https://clawhub.ai/davida-ps/skills/hermes-attestation-guardian","primaryLinks":[{"label":"View on ClawHub","url":"https://clawhub.ai/davida-ps/hermes-attestation-guardian","kind":"source"},{"label":"Homepage","url":"https://clawhub.ai/davida-ps/skills/hermes-attestation-guardian","kind":"homepage"}],"safetyScore":84,"overallRank":62,"popularityScore":62,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"Hermes-only runtime security attestation and drift detection skill for operator-managed Hermes infrastructure. Skill: hermes-attestation-guardian Owner: davida-"},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-10-10T22:09:15.455Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-10T22:09:15.455Z","emptyReason":null},"stars":null,"forks":null,"downloads":1246,"packageName":null,"latestVersion":"0.1.3","tractionLabel":"1.2K downloads"},"release":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-10T22:09:15.390Z","emptyReason":null},"lastUpdatedAt":"2026-10-10T22:09:15.455Z","lastCrawledAt":"2026-10-10T22:09:15.390Z","lastIndexedAt":null,"nextCrawlAt":"2026-10-11T22:09:15.390Z","lastVerifiedAt":null,"highlights":[{"version":"0.1.3","createdAt":"2026-05-24T18:48:08.071Z","changelog":"Release 0.1.3 via CI","fileCount":26,"zipByteSize":62460},{"version":"0.1.2","createdAt":"2026-05-16T21:44:23.135Z","changelog":"Release 0.1.2 via CI","fileCount":25,"zipByteSize":60832},{"version":"0.1.1","createdAt":"2026-05-14T11:43:07.920Z","changelog":"Release 0.1.1 via CI","fileCount":25,"zipByteSize":60711},{"version":"0.1.0","createdAt":"2026-04-21T11:00:07.586Z","changelog":"Release 0.1.0 via CI","fileCount":25,"zipByteSize":60326},{"version":"0.0.1","createdAt":"2026-04-16T15:04:12.235Z","changelog":"Release 0.0.1 via CI","fileCount":14,"zipByteSize":26157}]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install s17ewxqmthh68xc4bv5vc6f30183jsf1:hermes-attestation-guardian","setupComplexity":"low","setupSteps":["Setup complexity is LOW. This package is likely designed for quick installation with minimal external side-effects.","Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-davida-ps-hermes-attestation-guardian/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-davida-ps-hermes-attestation-guardian/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-davida-ps-hermes-attestation-guardian/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-davida-ps-hermes-attestation-guardian/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-davida-ps-hermes-attestation-guardian/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-davida-ps-hermes-attestation-guardian/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-11T00:33:21.939Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-davida-ps-hermes-attestation-guardian/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-davida-ps-hermes-attestation-guardian/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-davida-ps-hermes-attestation-guardian/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-davida-ps-hermes-attestation-guardian/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"high","updatedAt":"2026-10-10T22:09:15.455Z","emptyReason":null},"readme":"Skill: hermes-attestation-guardian\n\nOwner: davida-ps\n\nSummary: Hermes-only runtime security attestation and drift detection skill for operator-managed Hermes infrastructure.\n\nTags: latest:0.1.3\n\nVersion history:\n\nv0.1.3 | 2026-05-24T18:48:08.071Z | user\n\nRelease 0.1.3 via CI\n\nv0.1.2 | 2026-05-16T21:44:23.135Z | user\n\nRelease 0.1.2 via CI\n\nv0.1.1 | 2026-05-14T11:43:07.920Z | user\n\nRelease 0.1.1 via CI\n\nv0.1.0 | 2026-04-21T11:00:07.586Z | user\n\nRelease 0.1.0 via CI\n\nv0.0.1 | 2026-04-16T15:04:12.235Z | user\n\nRelease 0.0.1 via CI\n\nArchive index:\n\nArchive v0.1.3: 26 files, 62460 bytes\n\nFiles: CHANGELOG.md (3258b), lib/attestation.mjs (16502b), lib/cron.mjs (5146b), lib/diff.mjs (7725b), lib/feed.mjs (26937b), lib/semver.mjs (5897b), README.md (2360b), scripts/check_advisories.mjs (3165b), scripts/generate_attestation.mjs (4670b), scripts/guarded_skill_verify.mjs (6531b), scripts/refresh_advisory_feed.mjs (3208b), scripts/setup_advisory_check_cron.mjs (5496b), scripts/setup_attestation_cron.mjs (7002b), scripts/verify_attestation.mjs (11353b), skill-card.md (2645b), skill.json (5261b), SKILL.md (10490b), test/attestation_cli.test.mjs (10377b), test/attestation_diff.test.mjs (2246b), test/attestation_schema.test.mjs (13105b), test/feed_verification.test.mjs (26499b), test/guarded_skill_verify.test.mjs (11172b), test/hermes_attestation_sandbox_regression.sh (11530b), test/setup_advisory_check_cron.test.mjs (11999b), test/setup_attestation_cron.test.mjs (9306b), _meta.json (146b)\n\nFile v0.1.3:SKILL.md\n\n---\nname: hermes-attestation-guardian\nversion: 0.1.3\ndescription: Hermes-only runtime security attestation and drift detection skill for operator-managed Hermes infrastructure.\nhomepage: https://clawsec.prompt.security\nhermes:\n  emoji: \"🛡️\"\n  requires:\n    bins: [node]\n---\n\n# Hermes Attestation Guardian\n\nIMPORTANT SCOPE:\n- This skill targets Hermes infrastructure only (CLI/Gateway/profile-managed deployments).\n- This skill is not an OpenClaw runtime hook package.\n\n\n## Release Artifact Verification\n\nFor standalone installs, verify the signed release manifest before trusting `SKILL.md`, `skill.json`, or the archive. The `skill.json` file is the package metadata/SBOM source, and the release pipeline signs `checksums.json` with the ClawSec release key.\n\n```bash\nset -euo pipefail\n\nSKILL_NAME=\"hermes-attestation-guardian\"\nVERSION=\"0.1.3\"\nREPO=\"prompt-security/clawsec\"\nTAG=\"${SKILL_NAME}-v${VERSION}\"\nBASE=\"https://github.com/${REPO}/releases/download/${TAG}\"\nZIP_NAME=\"${SKILL_NAME}-v${VERSION}.zip\"\nTMP_DIR=\"$(mktemp -d)\"\ntrap 'rm -rf \"$TMP_DIR\"' EXIT\n\nRELEASE_PUBKEY_SHA256=\"711424e4535f84093fefb024cd1ca4ec87439e53907b305b79a631d5befba9c8\"\n\ncurl -fsSL \"$BASE/checksums.json\" -o \"$TMP_DIR/checksums.json\"\ncurl -fsSL \"$BASE/checksums.sig\" -o \"$TMP_DIR/checksums.sig\"\ncurl -fsSL \"$BASE/signing-public.pem\" -o \"$TMP_DIR/signing-public.pem\"\ncurl -fsSL \"$BASE/$ZIP_NAME\" -o \"$TMP_DIR/$ZIP_NAME\"\ncurl -fsSL \"$BASE/SKILL.md\" -o \"$TMP_DIR/SKILL.md\"\ncurl -fsSL \"$BASE/skill.json\" -o \"$TMP_DIR/skill.json\"\n\nACTUAL_PUBKEY_SHA256=\"$(openssl pkey -pubin -in \"$TMP_DIR/signing-public.pem\" -outform DER | shasum -a 256 | awk '{print $1}')\"\nif [ \"$ACTUAL_PUBKEY_SHA256\" != \"$RELEASE_PUBKEY_SHA256\" ]; then\n  echo \"ERROR: signing-public.pem fingerprint mismatch\" >&2\n  exit 1\nfi\n\nopenssl base64 -d -A -in \"$TMP_DIR/checksums.sig\" -out \"$TMP_DIR/checksums.sig.bin\"\nopenssl pkeyutl -verify -rawin -pubin \\\n  -inkey \"$TMP_DIR/signing-public.pem\" \\\n  -sigfile \"$TMP_DIR/checksums.sig.bin\" \\\n  -in \"$TMP_DIR/checksums.json\" >/dev/null\n\nhash_file() {\n  if command -v shasum >/dev/null 2>&1; then\n    shasum -a 256 \"$1\" | awk '{print $1}'\n  else\n    sha256sum \"$1\" | awk '{print $1}'\n  fi\n}\n\nverify_manifest_file() {\n  asset=\"$1\"\n  path=\"$2\"\n  expected=\"$(jq -r --arg asset \"$asset\" '.files[$asset].sha256 // empty' \"$TMP_DIR/checksums.json\")\"\n  if [ -z \"$expected\" ]; then\n    echo \"ERROR: checksums.json missing $asset\" >&2\n    exit 1\n  fi\n  actual=\"$(hash_file \"$path\")\"\n  if [ \"$actual\" != \"$expected\" ]; then\n    echo \"ERROR: checksum mismatch for $asset\" >&2\n    exit 1\n  fi\n}\n\nexpected_archive=\"$(jq -r '.archive.sha256 // empty' \"$TMP_DIR/checksums.json\")\"\nif [ -z \"$expected_archive\" ]; then\n  echo \"ERROR: checksums.json missing archive.sha256\" >&2\n  exit 1\nfi\nactual_archive=\"$(hash_file \"$TMP_DIR/$ZIP_NAME\")\"\nif [ \"$actual_archive\" != \"$expected_archive\" ]; then\n  echo \"ERROR: archive checksum mismatch\" >&2\n  exit 1\nfi\n\nverify_manifest_file \"SKILL.md\" \"$TMP_DIR/SKILL.md\"\nverify_manifest_file \"skill.json\" \"$TMP_DIR/skill.json\"\n\necho \"Signed release manifest, archive, SKILL.md, and skill.json verified.\"\n```\n\nOnly install or extract the archive after this verification succeeds.\n\n## Goal\n\nGenerate deterministic Hermes posture attestations, verify them with fail-closed integrity checks, and compare baseline drift using stable severity mapping.\n\n## Hermes guard trust policy note\n\nWhen installing from community sources, configure Hermes guard to use signature-aware trust (trusted signer fingerprint allowlist) rather than source-name-only trust. Unknown signer fingerprints should stay on community policy, and invalid signatures must remain blocked.\n\n## Commands\n\n```bash\n# Generate attestation (default output: ~/.hermes/security/attestations/current.json)\nnode scripts/generate_attestation.mjs\n\n# Generate with explicit policy + deterministic timestamp\nnode scripts/generate_attestation.mjs \\\n  --policy ~/.hermes/security/attestation-policy.json \\\n  --generated-at 2026-04-15T18:00:00.000Z \\\n  --write-sha256\n\n# Verify schema + canonical digest\nnode scripts/verify_attestation.mjs --input ~/.hermes/security/attestations/current.json\n\n# Verify with baseline diff (baseline must be authenticated)\nnode scripts/verify_attestation.mjs \\\n  --input ~/.hermes/security/attestations/current.json \\\n  --baseline ~/.hermes/security/attestations/baseline.json \\\n  --baseline-expected-sha256 <trusted-baseline-sha256> \\\n  --fail-on-severity high\n\n# Optional detached signature verification\nnode scripts/verify_attestation.mjs \\\n  --input ~/.hermes/security/attestations/current.json \\\n  --signature ~/.hermes/security/attestations/current.json.sig \\\n  --public-key ~/.hermes/security/keys/attestation-public.pem\n\n# Refresh advisory feed verification state (fail-closed by default)\nnode scripts/refresh_advisory_feed.mjs\n\n# Check advisory feed verification + feed summary\nnode scripts/check_advisories.mjs\n\n# Guarded advisory-aware skill verification gate (returns 42 on advisory match without explicit confirm)\nnode scripts/guarded_skill_verify.mjs --skill some-skill --version 1.2.3\n\n# Explicit operator acknowledgement path for advisory matches\nnode scripts/guarded_skill_verify.mjs --skill some-skill --version 1.2.3 --confirm-advisory\n\n# Optional temporary unsigned bypass (dangerous; emergency-only)\nHERMES_ADVISORY_ALLOW_UNSIGNED_FEED=1 node scripts/refresh_advisory_feed.mjs --allow-unsigned\n\n# Preview scheduler config without mutating user schedule state\nnode scripts/setup_attestation_cron.mjs --every 6h --print-only\n\n# Apply managed scheduler block\nnode scripts/setup_attestation_cron.mjs --every 6h --apply\n\n# Preview advisory check scheduler config (guarded flow, print-only default)\nnode scripts/setup_advisory_check_cron.mjs --every 6h --skill some-skill --print-only\n\n# Apply advisory check scheduler block (uses guarded_skill_verify flow)\nnode scripts/setup_advisory_check_cron.mjs --every 6h --skill some-skill --version 1.2.3 --apply\n\n# Emergency-only: unsigned bypass for scheduled advisory checks (do not keep enabled)\nnode scripts/setup_advisory_check_cron.mjs --every 6h --skill some-skill --allow-unsigned --apply\n```\n\nWARNING: `--allow-unsigned` in scheduled commands is incident-response only. Remove it immediately after recovery and restore signed advisory verification.\n\n## Attestation payload (implemented)\n\nThe generator emits:\n- schema_version, platform, generated_at\n- generator metadata (skill + node version)\n- host metadata (hostname/platform/arch)\n- posture.runtime (gateway enabled flags + risky toggles)\n- posture.feed_verification status (verified|unverified|unknown) sourced from `$HERMES_HOME/security/advisories/feed-verification-state.json`\n- posture.integrity watched_files and trust_anchors (existence + sha256)\n- digests.canonical_sha256 over a stable canonical JSON representation\n\n## Fail-closed behavior\n\nVerifier exits non-zero when:\n- schema validation fails\n- canonical digest algorithm is unsupported or digest binding mismatches\n- expected file sha256 mismatches (if configured)\n- detached signature verification fails (if configured)\n- baseline is provided without authenticated trust binding (`--baseline-expected-sha256` and/or baseline signature + public key)\n- baseline authenticity or baseline schema/digest validation fails\n- baseline diff highest severity is at/above `--fail-on-severity` (default: critical)\n\nSeverity messages are emitted as INFO / WARNING / CRITICAL style lines.\n\n## Side effects\n\n- `generate_attestation.mjs` writes one JSON file (and optional `.sha256`) under `$HERMES_HOME/security/attestations`.\n- `verify_attestation.mjs` is read-only.\n- `refresh_advisory_feed.mjs` writes verified feed cache + verification state under `$HERMES_HOME/security/advisories`.\n- `check_advisories.mjs` is read-only.\n- `guarded_skill_verify.mjs` re-runs feed refresh/verification (same advisory cache + state side effects) and then performs advisory-aware gate checks.\n- `setup_attestation_cron.mjs` is read-only unless `--apply` is provided.\n- `setup_attestation_cron.mjs --apply` rewrites only the current user managed schedule block delimited by:\n  - `# >>> hermes-attestation-guardian >>>`\n  - `# <<< hermes-attestation-guardian <<<`\n- `setup_advisory_check_cron.mjs` is read-only unless `--apply` is provided.\n- `setup_advisory_check_cron.mjs --apply` rewrites only the current user advisory-check managed schedule block delimited by:\n  - `# >>> hermes-attestation-guardian-advisory-check >>>`\n  - `# <<< hermes-attestation-guardian-advisory-check <<<`\n  - generated command path uses `guarded_skill_verify.mjs` (advisory-aware gate), not raw `check_advisories.mjs`\n\n## Advisory feed override knobs\n\nThe default signed advisory feed is consolidated: it can contain NVD CVEs, approved community advisories, and provisional GHSA-without-CVE records. Hermes matching still gates on affected package names and supported version ranges.\n\n- Source selection: `HERMES_ADVISORY_FEED_SOURCE=auto|remote|local`\n- Remote artifacts: `HERMES_ADVISORY_FEED_URL`, `HERMES_ADVISORY_FEED_SIG_URL`, `HERMES_ADVISORY_FEED_CHECKSUMS_URL`, `HERMES_ADVISORY_FEED_CHECKSUMS_SIG_URL`\n- Local artifacts: `HERMES_LOCAL_ADVISORY_FEED`, `HERMES_LOCAL_ADVISORY_FEED_SIG`, `HERMES_LOCAL_ADVISORY_FEED_CHECKSUMS`, `HERMES_LOCAL_ADVISORY_FEED_CHECKSUMS_SIG`\n- Pinned key override: `HERMES_ADVISORY_FEED_PUBLIC_KEY` (default is built-in pinned key)\n- Optional checksum toggle: `HERMES_ADVISORY_VERIFY_CHECKSUM_MANIFEST` (default: enabled)\n- UNSAFE emergency bypass only: `HERMES_ADVISORY_ALLOW_UNSIGNED_FEED=1`\n\n## Notes\n\n- Hermes scan + test context is `.mjs`-based by design:\n  - runtime scripts: `scripts/*.mjs`\n  - shared libraries: `lib/*.mjs`\n  - regression tests: `test/*.test.mjs`\n- Keep `.mjs` paths/extensions stable so scanner scope, SBOM wiring, and test harness references stay valid.\n- Default output root is `~/.hermes/security/attestations/`.\n- No destructive remediation actions (delete/restore/quarantine) are implemented.\n- Advisory feed remote URL allowlisting is not implemented in v0.0.2; operators must explicitly trust configured feed/checksum endpoints.\n- Guarded advisory version matching currently uses a lightweight comparator parser (`>=`, `<=`, `>`, `<`, `=`, `^`, `~`, wildcard `*`) and does not implement full npm semver range grammar (for example, OR ranges and complex comparator sets).\n- Operator policy file is optional JSON with:\n  - `watch_files`: list of file paths\n  - `trust_anchor_files`: list of file paths\n\nFile v0.1.3:README.md\n\n# hermes-attestation-guardian\n\nHermes-only attestation, advisory verification, and guarded verification workflow.\n\nStatus: implemented (v0.1.0), Hermes-only.\n\n## Capabilities\n\nThis skill now covers the full Hermes-side capability set expected from the clawsec-suite parity workstream:\n\n- Deterministic runtime posture attestation generation.\n- Fail-closed attestation verification (schema + canonical digest).\n- Optional detached signature verification for attestation artifacts.\n- Authenticated baseline diffing with stable severity classification.\n- Scoped output-path enforcement under `$HERMES_HOME`.\n- Signed advisory feed verification (Ed25519) with optional checksum-manifest verification.\n- Fail-closed advisory verification state persistence under `$HERMES_HOME/security/advisories`.\n- Advisory-aware guarded skill verification with explicit `--confirm-advisory` override.\n- Optional recurring scheduler helpers for attestation and advisory checks (print-only by default, explicit apply mode).\n- Sandboxed end-to-end regression harness for install + verify + advisory gates.\n\n## Quickstart\n\nCanonical release verification and trust-policy guidance lives in `SKILL.md`:\n- `Mandatory release verification gate (before install)`\n- `Hermes guard trust policy note`\n\nAfter running that gate, use:\n\n```bash\nnode scripts/generate_attestation.mjs\nnode scripts/verify_attestation.mjs --input ~/.hermes/security/attestations/current.json\nnode scripts/refresh_advisory_feed.mjs\nnode scripts/check_advisories.mjs\nnode scripts/guarded_skill_verify.mjs --skill some-skill --version 1.2.3\nnode scripts/setup_attestation_cron.mjs --every 6h --print-only\nnode scripts/setup_advisory_check_cron.mjs --every 6h --skill some-skill --print-only\n```\n\nScheduler safety warning: never leave `--allow-unsigned` enabled in recurring advisory check jobs except during short emergency recovery windows.\n\n## Runtime requirements\n\nRequired:\n- `node`\n\nOptional tooling (for local verification workflows):\n- `openssl`, `bash`, `docker`\n\n## Tests\n\n```bash\nnode test/attestation_schema.test.mjs\nnode test/attestation_diff.test.mjs\nnode test/attestation_cli.test.mjs\nnode test/setup_attestation_cron.test.mjs\nnode test/setup_advisory_check_cron.test.mjs\nnode test/feed_verification.test.mjs\nnode test/guarded_skill_verify.test.mjs\nbash test/hermes_attestation_sandbox_regression.sh\n```\n\nFile v0.1.3:_meta.json\n\n{\n  \"ownerId\": \"kn76m78f01hqrtpgm895s0jsax80jd8v\",\n  \"slug\": \"hermes-attestation-guardian\",\n  \"version\": \"0.1.3\",\n  \"publishedAt\": 1779648488071\n}\n\nFile v0.1.3:CHANGELOG.md\n\n# Changelog\n\n## [0.1.3] - 2026-05-24\n\n### Changed\n- Documented that the default signed advisory feed is consolidated and may include NVD CVEs, approved community advisories, and provisional GHSA-without-CVE records while Hermes matching remains package-scoped.\n\n## [0.1.2] - 2026-05-15\n\n### Fixed\n- Included `lib/semver.mjs` and `lib/cron.mjs` in the release SBOM so signed archives contain every runtime library imported by shipped scripts.\n\n## [0.1.1] - 2026-05-13\n\n### Security\n- Added explicit signed release artifact verification instructions for standalone installs, including `checksums.json`, `checksums.sig`, `signing-public.pem`, archive hash verification, and `SKILL.md`/`skill.json` checksum checks.\n\n### Changed\n- Re-release skill payload metadata after excluding test-only files from release SBOMs and archives.\n\n## [0.1.0] - 2026-04-21\n\n- Added mandatory release verification gate guidance before install: `checksums.json`, `checksums.sig`, and pinned signing public-key fingerprint.\n- Added explicit Hermes guard trust-policy note for signature-aware trust (trusted signer fingerprint allowlist) over source-name-only trust.\n- Moved sandbox regression harness into the skill test surface (`test/hermes_attestation_sandbox_regression.sh`) and fixed in-skill default path resolution.\n- Tightened advisory feed verification to require checksum-manifest artifacts when checksum-manifest verification is enabled (fail-closed when missing).\n- Added feed regression coverage for missing local/remote checksum-manifest artifacts under strict verification mode.\n- Refactored cron setup scripts to share managed-block helpers from `lib/cron.mjs`, reducing drift risk.\n- Added explicit `.mjs` scan/test coverage guidance so Hermes-side scanner scope and regression harness context stay aligned with `scripts/*.mjs`, `lib/*.mjs`, and `test/*.test.mjs`.\n- Clarified fresh-node first-run edge-case documentation.\n- Clarified Hermes runtime metadata/frontmatter and README capability coverage for ClawHub publishing.\n- Removed compatibility-report wiki page references in favor of README capability matrix as the primary compatibility surface.\n- Updated skill metadata/docs to v0.1.0 and aligned README quickstart with fail-closed verification expectations.\n\n## [0.0.1] - 2026-04-15\n\n- Implemented deterministic Hermes attestation generator CLI (`scripts/generate_attestation.mjs`).\n- Implemented fail-closed verifier CLI with schema, canonical digest, expected checksum, and optional detached signature checks (`scripts/verify_attestation.mjs`).\n- Implemented meaningful baseline diff engine with stable severity mapping for risky toggle regressions, feed verification regressions, trust anchor drift, and watched file drift (`lib/diff.mjs`).\n- Implemented Hermes-only cron setup helper with print-only default and managed-block apply mode (`scripts/setup_attestation_cron.mjs`).\n- Added shared attestation library for canonicalization, schema validation, digest generation, and policy parsing (`lib/attestation.mjs`).\n- Expanded tests for schema determinism, diff behavior, generator/verifier fail-closed behavior, and cron helper Hermes-only output.\n- Updated metadata/docs to match actual implemented behavior and ClawSec release pipeline expectations.\n\nFile v0.1.3:skill-card.md\n\n## Description:\n\nHermes-only runtime security attestation and drift detection skill for operator-managed Hermes infrastructure.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[davida-ps](https://clawhub.ai/user/davida-ps)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and operators use this skill to generate deterministic Hermes posture attestations, verify attestation integrity fail-closed, compare authenticated baseline drift, and run advisory-aware guarded verification for Hermes-managed infrastructure.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Attestations may expose watched file paths, trust anchor paths, and hashes from Hermes security state.\n\nMitigation: Review watch_files and trust_anchor_files before use, protect ~/.hermes, and limit access to generated attestation artifacts.\n\nRisk: Recurring scheduler setup can mutate the current user's cron state when --apply is used.\n\nMitigation: Preview scheduler entries with --print-only, avoid running scheduled jobs as root, and apply only the managed Hermes schedule blocks intentionally.\n\nRisk: Unsigned advisory feed bypass weakens fail-closed verification.\n\nMitigation: Use --allow-unsigned only during a short audited emergency window and remove it immediately after recovery.\n\nRisk: Using the skill outside Hermes infrastructure can produce unsupported trust and attestation assumptions.\n\nMitigation: Install and operate the skill only for Hermes CLI, Gateway, or profile-managed deployments.\n\n## Reference(s):\n\n- [ClawSec Homepage](https://clawsec.prompt.security)\n- [ClawHub Skill Page](https://clawhub.ai/davida-ps/skills/hermes-attestation-guardian)\n- [Skill Operator Playbook](artifact/SKILL.md)\n- [Capability Overview](artifact/README.md)\n- [Release Changelog](artifact/CHANGELOG.md)\n\n## Skill Output:\n\n**Output Type(s):** [text, markdown, code, shell commands, configuration, guidance]\n\n**Output Format:** [Markdown guidance with shell commands and JSON configuration artifacts]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Produces Hermes attestation JSON files, optional sha256 sidecar files, advisory feed verification state, and optional managed cron entries when explicitly applied.]\n\n## Skill Version(s):\n\n0.1.3 (source: frontmatter, changelog, server release evidence; released 2026-05-24)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nFile v0.1.3:skill.json\n\n{\n  \"name\": \"hermes-attestation-guardian\",\n  \"version\": \"0.1.3\",\n  \"description\": \"Hermes-only runtime security attestation and drift detection skill. Generates deterministic posture artifacts, verifies integrity fail-closed, and classifies baseline drift severity.\",\n  \"author\": \"prompt-security\",\n  \"license\": \"AGPL-3.0-or-later\",\n  \"homepage\": \"https://clawsec.prompt.security/\",\n  \"platform\": \"hermes\",\n  \"keywords\": [\n    \"security\",\n    \"hermes\",\n    \"attestation\",\n    \"integrity\",\n    \"drift-detection\",\n    \"posture\"\n  ],\n  \"sbom\": {\n    \"files\": [\n      {\n        \"path\": \"SKILL.md\",\n        \"required\": true,\n        \"description\": \"Skill documentation and operator playbook\"\n      },\n      {\n        \"path\": \"CHANGELOG.md\",\n        \"required\": true,\n        \"description\": \"Version history and release notes\"\n      },\n      {\n        \"path\": \"README.md\",\n        \"required\": true,\n        \"description\": \"Human-oriented overview and quickstart\"\n      },\n      {\n        \"path\": \"lib/attestation.mjs\",\n        \"required\": true,\n        \"description\": \"Attestation schema, canonicalization, digest and validation helpers\"\n      },\n      {\n        \"path\": \"lib/diff.mjs\",\n        \"required\": true,\n        \"description\": \"Baseline comparison and severity classification\"\n      },\n      {\n        \"path\": \"lib/feed.mjs\",\n        \"required\": true,\n        \"description\": \"Hermes-native advisory feed verification and state helpers\"\n      },\n      {\n        \"path\": \"lib/semver.mjs\",\n        \"required\": true,\n        \"description\": \"Advisory version-range parsing and matching helpers\"\n      },\n      {\n        \"path\": \"lib/cron.mjs\",\n        \"required\": true,\n        \"description\": \"Shared managed cron block and cadence helpers\"\n      },\n      {\n        \"path\": \"scripts/generate_attestation.mjs\",\n        \"required\": true,\n        \"description\": \"Generate deterministic Hermes posture attestation artifact\"\n      },\n      {\n        \"path\": \"scripts/verify_attestation.mjs\",\n        \"required\": true,\n        \"description\": \"Verify attestation schema, digest and optional detached signature\"\n      },\n      {\n        \"path\": \"scripts/refresh_advisory_feed.mjs\",\n        \"required\": true,\n        \"description\": \"Fetch, verify, and persist Hermes advisory feed verification state\"\n      },\n      {\n        \"path\": \"scripts/check_advisories.mjs\",\n        \"required\": true,\n        \"description\": \"Display human-readable advisory verification/feed summary\"\n      },\n      {\n        \"path\": \"scripts/guarded_skill_verify.mjs\",\n        \"required\": true,\n        \"description\": \"Advisory-aware guarded skill verification gate with explicit confirmation override\"\n      },\n      {\n        \"path\": \"scripts/setup_attestation_cron.mjs\",\n        \"required\": true,\n        \"description\": \"Optional recurring schedule setup for Hermes attestation runs\"\n      },\n      {\n        \"path\": \"scripts/setup_advisory_check_cron.mjs\",\n        \"required\": true,\n        \"description\": \"Optional recurring schedule setup for Hermes guarded advisory checks\"\n      }\n    ]\n  },\n  \"hermes\": {\n    \"emoji\": \"🛡️\",\n    \"category\": \"security\",\n    \"requires\": {\n      \"bins\": [\n        \"node\"\n      ]\n    },\n    \"runtime\": {\n      \"required_env\": [],\n      \"optional_env\": [\n        \"HERMES_HOME\",\n        \"HERMES_ATTESTATION_OUTPUT_DIR\",\n        \"HERMES_ATTESTATION_BASELINE\",\n        \"HERMES_ATTESTATION_INTERVAL\",\n        \"HERMES_ATTESTATION_FAIL_ON_SEVERITY\",\n        \"HERMES_ATTESTATION_POLICY\",\n        \"HERMES_ADVISORY_FEED_SOURCE\",\n        \"HERMES_ADVISORY_FEED_URL\",\n        \"HERMES_ADVISORY_FEED_SIG_URL\",\n        \"HERMES_ADVISORY_FEED_CHECKSUMS_URL\",\n        \"HERMES_ADVISORY_FEED_CHECKSUMS_SIG_URL\",\n        \"HERMES_LOCAL_ADVISORY_FEED\",\n        \"HERMES_LOCAL_ADVISORY_FEED_SIG\",\n        \"HERMES_LOCAL_ADVISORY_FEED_CHECKSUMS\",\n        \"HERMES_LOCAL_ADVISORY_FEED_CHECKSUMS_SIG\",\n        \"HERMES_ADVISORY_FEED_PUBLIC_KEY\",\n        \"HERMES_ADVISORY_ALLOW_UNSIGNED_FEED\",\n        \"HERMES_ADVISORY_VERIFY_CHECKSUM_MANIFEST\",\n        \"HERMES_ADVISORY_FEED_STATE_PATH\",\n        \"HERMES_ADVISORY_CACHED_FEED\"\n      ]\n    },\n    \"execution\": {\n      \"always\": false,\n      \"persistence\": \"Runs on demand by default. Optional scheduler helper can install a managed schedule block when run with --apply.\",\n      \"network_egress\": \"Optional HTTPS advisory feed fetch via refresh_advisory_feed.mjs; no network required for local-mode verification\"\n    },\n    \"operator_review\": [\n      \"Hermes-only skill: unsupported for OpenClaw runtime hooks.\",\n      \"Verify watch/trust-anchor policy paths before scheduling recurring runs.\",\n      \"Verification fails closed for schema/digest/signature errors and unauthenticated baseline inputs; diff threshold defaults to critical.\",\n      \"Advisory feed verification is fail-closed by default; unsigned bypass must remain temporary and operator-audited.\"\n    ],\n    \"triggers\": [\n      \"generate hermes attestation\",\n      \"verify hermes attestation\",\n      \"hermes runtime drift detection\",\n      \"hermes trust anchor drift\",\n      \"refresh hermes advisory feed\",\n      \"check hermes advisories\",\n      \"guarded hermes skill verification\",\n      \"setup hermes attestation cron\",\n      \"setup hermes advisory check cron\"\n    ]\n  }\n}\n\nArchive v0.1.2: 25 files, 60832 bytes\n\nFiles: CHANGELOG.md (3009b), lib/attestation.mjs (16502b), lib/cron.mjs (5146b), lib/diff.mjs (7725b), lib/feed.mjs (26937b), lib/semver.mjs (5897b), README.md (2360b), scripts/check_advisories.mjs (3165b), scripts/generate_attestation.mjs (4670b), scripts/guarded_skill_verify.mjs (6531b), scripts/refresh_advisory_feed.mjs (3208b), scripts/setup_advisory_check_cron.mjs (5496b), scripts/setup_attestation_cron.mjs (7002b), scripts/verify_attestation.mjs (11353b), skill.json (5261b), SKILL.md (10257b), test/attestation_cli.test.mjs (10377b), test/attestation_diff.test.mjs (2246b), test/attestation_schema.test.mjs (13105b), test/feed_verification.test.mjs (26499b), test/guarded_skill_verify.test.mjs (11172b), test/hermes_attestation_sandbox_regression.sh (11530b), test/setup_advisory_check_cron.test.mjs (11999b), test/setup_attestation_cron.test.mjs (9306b), _meta.json (146b)\n\nFile v0.1.2:SKILL.md\n\n---\nname: hermes-attestation-guardian\nversion: 0.1.2\ndescription: Hermes-only runtime security attestation and drift detection skill for operator-managed Hermes infrastructure.\nhomepage: https://clawsec.prompt.security\nhermes:\n  emoji: \"🛡️\"\n  requires:\n    bins: [node]\n---\n\n# Hermes Attestation Guardian\n\nIMPORTANT SCOPE:\n- This skill targets Hermes infrastructure only (CLI/Gateway/profile-managed deployments).\n- This skill is not an OpenClaw runtime hook package.\n\n\n## Release Artifact Verification\n\nFor standalone installs, verify the signed release manifest before trusting `SKILL.md`, `skill.json`, or the archive. The `skill.json` file is the package metadata/SBOM source, and the release pipeline signs `checksums.json` with the ClawSec release key.\n\n```bash\nset -euo pipefail\n\nSKILL_NAME=\"hermes-attestation-guardian\"\nVERSION=\"0.1.2\"\nREPO=\"prompt-security/clawsec\"\nTAG=\"${SKILL_NAME}-v${VERSION}\"\nBASE=\"https://github.com/${REPO}/releases/download/${TAG}\"\nZIP_NAME=\"${SKILL_NAME}-v${VERSION}.zip\"\nTMP_DIR=\"$(mktemp -d)\"\ntrap 'rm -rf \"$TMP_DIR\"' EXIT\n\nRELEASE_PUBKEY_SHA256=\"711424e4535f84093fefb024cd1ca4ec87439e53907b305b79a631d5befba9c8\"\n\ncurl -fsSL \"$BASE/checksums.json\" -o \"$TMP_DIR/checksums.json\"\ncurl -fsSL \"$BASE/checksums.sig\" -o \"$TMP_DIR/checksums.sig\"\ncurl -fsSL \"$BASE/signing-public.pem\" -o \"$TMP_DIR/signing-public.pem\"\ncurl -fsSL \"$BASE/$ZIP_NAME\" -o \"$TMP_DIR/$ZIP_NAME\"\ncurl -fsSL \"$BASE/SKILL.md\" -o \"$TMP_DIR/SKILL.md\"\ncurl -fsSL \"$BASE/skill.json\" -o \"$TMP_DIR/skill.json\"\n\nACTUAL_PUBKEY_SHA256=\"$(openssl pkey -pubin -in \"$TMP_DIR/signing-public.pem\" -outform DER | shasum -a 256 | awk '{print $1}')\"\nif [ \"$ACTUAL_PUBKEY_SHA256\" != \"$RELEASE_PUBKEY_SHA256\" ]; then\n  echo \"ERROR: signing-public.pem fingerprint mismatch\" >&2\n  exit 1\nfi\n\nopenssl base64 -d -A -in \"$TMP_DIR/checksums.sig\" -out \"$TMP_DIR/checksums.sig.bin\"\nopenssl pkeyutl -verify -rawin -pubin \\\n  -inkey \"$TMP_DIR/signing-public.pem\" \\\n  -sigfile \"$TMP_DIR/checksums.sig.bin\" \\\n  -in \"$TMP_DIR/checksums.json\" >/dev/null\n\nhash_file() {\n  if command -v shasum >/dev/null 2>&1; then\n    shasum -a 256 \"$1\" | awk '{print $1}'\n  else\n    sha256sum \"$1\" | awk '{print $1}'\n  fi\n}\n\nverify_manifest_file() {\n  asset=\"$1\"\n  path=\"$2\"\n  expected=\"$(jq -r --arg asset \"$asset\" '.files[$asset].sha256 // empty' \"$TMP_DIR/checksums.json\")\"\n  if [ -z \"$expected\" ]; then\n    echo \"ERROR: checksums.json missing $asset\" >&2\n    exit 1\n  fi\n  actual=\"$(hash_file \"$path\")\"\n  if [ \"$actual\" != \"$expected\" ]; then\n    echo \"ERROR: checksum mismatch for $asset\" >&2\n    exit 1\n  fi\n}\n\nexpected_archive=\"$(jq -r '.archive.sha256 // empty' \"$TMP_DIR/checksums.json\")\"\nif [ -z \"$expected_archive\" ]; then\n  echo \"ERROR: checksums.json missing archive.sha256\" >&2\n  exit 1\nfi\nactual_archive=\"$(hash_file \"$TMP_DIR/$ZIP_NAME\")\"\nif [ \"$actual_archive\" != \"$expected_archive\" ]; then\n  echo \"ERROR: archive checksum mismatch\" >&2\n  exit 1\nfi\n\nverify_manifest_file \"SKILL.md\" \"$TMP_DIR/SKILL.md\"\nverify_manifest_file \"skill.json\" \"$TMP_DIR/skill.json\"\n\necho \"Signed release manifest, archive, SKILL.md, and skill.json verified.\"\n```\n\nOnly install or extract the archive after this verification succeeds.\n\n## Goal\n\nGenerate deterministic Hermes posture attestations, verify them with fail-closed integrity checks, and compare baseline drift using stable severity mapping.\n\n## Hermes guard trust policy note\n\nWhen installing from community sources, configure Hermes guard to use signature-aware trust (trusted signer fingerprint allowlist) rather than source-name-only trust. Unknown signer fingerprints should stay on community policy, and invalid signatures must remain blocked.\n\n## Commands\n\n```bash\n# Generate attestation (default output: ~/.hermes/security/attestations/current.json)\nnode scripts/generate_attestation.mjs\n\n# Generate with explicit policy + deterministic timestamp\nnode scripts/generate_attestation.mjs \\\n  --policy ~/.hermes/security/attestation-policy.json \\\n  --generated-at 2026-04-15T18:00:00.000Z \\\n  --write-sha256\n\n# Verify schema + canonical digest\nnode scripts/verify_attestation.mjs --input ~/.hermes/security/attestations/current.json\n\n# Verify with baseline diff (baseline must be authenticated)\nnode scripts/verify_attestation.mjs \\\n  --input ~/.hermes/security/attestations/current.json \\\n  --baseline ~/.hermes/security/attestations/baseline.json \\\n  --baseline-expected-sha256 <trusted-baseline-sha256> \\\n  --fail-on-severity high\n\n# Optional detached signature verification\nnode scripts/verify_attestation.mjs \\\n  --input ~/.hermes/security/attestations/current.json \\\n  --signature ~/.hermes/security/attestations/current.json.sig \\\n  --public-key ~/.hermes/security/keys/attestation-public.pem\n\n# Refresh advisory feed verification state (fail-closed by default)\nnode scripts/refresh_advisory_feed.mjs\n\n# Check advisory feed verification + feed summary\nnode scripts/check_advisories.mjs\n\n# Guarded advisory-aware skill verification gate (returns 42 on advisory match without explicit confirm)\nnode scripts/guarded_skill_verify.mjs --skill some-skill --version 1.2.3\n\n# Explicit operator acknowledgement path for advisory matches\nnode scripts/guarded_skill_verify.mjs --skill some-skill --version 1.2.3 --confirm-advisory\n\n# Optional temporary unsigned bypass (dangerous; emergency-only)\nHERMES_ADVISORY_ALLOW_UNSIGNED_FEED=1 node scripts/refresh_advisory_feed.mjs --allow-unsigned\n\n# Preview scheduler config without mutating user schedule state\nnode scripts/setup_attestation_cron.mjs --every 6h --print-only\n\n# Apply managed scheduler block\nnode scripts/setup_attestation_cron.mjs --every 6h --apply\n\n# Preview advisory check scheduler config (guarded flow, print-only default)\nnode scripts/setup_advisory_check_cron.mjs --every 6h --skill some-skill --print-only\n\n# Apply advisory check scheduler block (uses guarded_skill_verify flow)\nnode scripts/setup_advisory_check_cron.mjs --every 6h --skill some-skill --version 1.2.3 --apply\n\n# Emergency-only: unsigned bypass for scheduled advisory checks (do not keep enabled)\nnode scripts/setup_advisory_check_cron.mjs --every 6h --skill some-skill --allow-unsigned --apply\n```\n\nWARNING: `--allow-unsigned` in scheduled commands is incident-response only. Remove it immediately after recovery and restore signed advisory verification.\n\n## Attestation payload (implemented)\n\nThe generator emits:\n- schema_version, platform, generated_at\n- generator metadata (skill + node version)\n- host metadata (hostname/platform/arch)\n- posture.runtime (gateway enabled flags + risky toggles)\n- posture.feed_verification status (verified|unverified|unknown) sourced from `$HERMES_HOME/security/advisories/feed-verification-state.json`\n- posture.integrity watched_files and trust_anchors (existence + sha256)\n- digests.canonical_sha256 over a stable canonical JSON representation\n\n## Fail-closed behavior\n\nVerifier exits non-zero when:\n- schema validation fails\n- canonical digest algorithm is unsupported or digest binding mismatches\n- expected file sha256 mismatches (if configured)\n- detached signature verification fails (if configured)\n- baseline is provided without authenticated trust binding (`--baseline-expected-sha256` and/or baseline signature + public key)\n- baseline authenticity or baseline schema/digest validation fails\n- baseline diff highest severity is at/above `--fail-on-severity` (default: critical)\n\nSeverity messages are emitted as INFO / WARNING / CRITICAL style lines.\n\n## Side effects\n\n- `generate_attestation.mjs` writes one JSON file (and optional `.sha256`) under `$HERMES_HOME/security/attestations`.\n- `verify_attestation.mjs` is read-only.\n- `refresh_advisory_feed.mjs` writes verified feed cache + verification state under `$HERMES_HOME/security/advisories`.\n- `check_advisories.mjs` is read-only.\n- `guarded_skill_verify.mjs` re-runs feed refresh/verification (same advisory cache + state side effects) and then performs advisory-aware gate checks.\n- `setup_attestation_cron.mjs` is read-only unless `--apply` is provided.\n- `setup_attestation_cron.mjs --apply` rewrites only the current user managed schedule block delimited by:\n  - `# >>> hermes-attestation-guardian >>>`\n  - `# <<< hermes-attestation-guardian <<<`\n- `setup_advisory_check_cron.mjs` is read-only unless `--apply` is provided.\n- `setup_advisory_check_cron.mjs --apply` rewrites only the current user advisory-check managed schedule block delimited by:\n  - `# >>> hermes-attestation-guardian-advisory-check >>>`\n  - `# <<< hermes-attestation-guardian-advisory-check <<<`\n  - generated command path uses `guarded_skill_verify.mjs` (advisory-aware gate), not raw `check_advisories.mjs`\n\n## Advisory feed override knobs\n\n- Source selection: `HERMES_ADVISORY_FEED_SOURCE=auto|remote|local`\n- Remote artifacts: `HERMES_ADVISORY_FEED_URL`, `HERMES_ADVISORY_FEED_SIG_URL`, `HERMES_ADVISORY_FEED_CHECKSUMS_URL`, `HERMES_ADVISORY_FEED_CHECKSUMS_SIG_URL`\n- Local artifacts: `HERMES_LOCAL_ADVISORY_FEED`, `HERMES_LOCAL_ADVISORY_FEED_SIG`, `HERMES_LOCAL_ADVISORY_FEED_CHECKSUMS`, `HERMES_LOCAL_ADVISORY_FEED_CHECKSUMS_SIG`\n- Pinned key override: `HERMES_ADVISORY_FEED_PUBLIC_KEY` (default is built-in pinned key)\n- Optional checksum toggle: `HERMES_ADVISORY_VERIFY_CHECKSUM_MANIFEST` (default: enabled)\n- UNSAFE emergency bypass only: `HERMES_ADVISORY_ALLOW_UNSIGNED_FEED=1`\n\n## Notes\n\n- Hermes scan + test context is `.mjs`-based by design:\n  - runtime scripts: `scripts/*.mjs`\n  - shared libraries: `lib/*.mjs`\n  - regression tests: `test/*.test.mjs`\n- Keep `.mjs` paths/extensions stable so scanner scope, SBOM wiring, and test harness references stay valid.\n- Default output root is `~/.hermes/security/attestations/`.\n- No destructive remediation actions (delete/restore/quarantine) are implemented.\n- Advisory feed remote URL allowlisting is not implemented in v0.0.2; operators must explicitly trust configured feed/checksum endpoints.\n- Guarded advisory version matching currently uses a lightweight comparator parser (`>=`, `<=`, `>`, `<`, `=`, `^`, `~`, wildcard `*`) and does not implement full npm semver range grammar (for example, OR ranges and complex comparator sets).\n- Operator policy file is optional JSON with:\n  - `watch_files`: list of file paths\n  - `trust_anchor_files`: list of file paths\n\nFile v0.1.2:README.md\n\n# hermes-attestation-guardian\n\nHermes-only attestation, advisory verification, and guarded verification workflow.\n\nStatus: implemented (v0.1.0), Hermes-only.\n\n## Capabilities\n\nThis skill now covers the full Hermes-side capability set expected from the clawsec-suite parity workstream:\n\n- Deterministic runtime posture attestation generation.\n- Fail-closed attestation verification (schema + canonical digest).\n- Optional detached signature verification for attestation artifacts.\n- Authenticated baseline diffing with stable severity classification.\n- Scoped output-path enforcement under `$HERMES_HOME`.\n- Signed advisory feed verification (Ed25519) with optional checksum-manifest verification.\n- Fail-closed advisory verification state persistence under `$HERMES_HOME/security/advisories`.\n- Advisory-aware guarded skill verification with explicit `--confirm-advisory` override.\n- Optional recurring scheduler helpers for attestation and advisory checks (print-only by default, explicit apply mode).\n- Sandboxed end-to-end regression harness for install + verify + advisory gates.\n\n## Quickstart\n\nCanonical release verification and trust-policy guidance lives in `SKILL.md`:\n- `Mandatory release verification gate (before install)`\n- `Hermes guard trust policy note`\n\nAfter running that gate, use:\n\n```bash\nnode scripts/generate_attestation.mjs\nnode scripts/verify_attestation.mjs --input ~/.hermes/security/attestations/current.json\nnode scripts/refresh_advisory_feed.mjs\nnode scripts/check_advisories.mjs\nnode scripts/guarded_skill_verify.mjs --skill some-skill --version 1.2.3\nnode scripts/setup_attestation_cron.mjs --every 6h --print-only\nnode scripts/setup_advisory_check_cron.mjs --every 6h --skill some-skill --print-only\n```\n\nScheduler safety warning: never leave `--allow-unsigned` enabled in recurring advisory check jobs except during short emergency recovery windows.\n\n## Runtime requirements\n\nRequired:\n- `node`\n\nOptional tooling (for local verification workflows):\n- `openssl`, `bash`, `docker`\n\n## Tests\n\n```bash\nnode test/attestation_schema.test.mjs\nnode test/attestation_diff.test.mjs\nnode test/attestation_cli.test.mjs\nnode test/setup_attestation_cron.test.mjs\nnode test/setup_advisory_check_cron.test.mjs\nnode test/feed_verification.test.mjs\nnode test/guarded_skill_verify.test.mjs\nbash test/hermes_attestation_sandbox_regression.sh\n```\n\nFile v0.1.2:_meta.json\n\n{\n  \"ownerId\": \"kn76m78f01hqrtpgm895s0jsax80jd8v\",\n  \"slug\": \"hermes-attestation-guardian\",\n  \"version\": \"0.1.2\",\n  \"publishedAt\": 1778967863135\n}\n\nFile v0.1.2:CHANGELOG.md\n\n# Changelog\n\n## [0.1.2] - 2026-05-15\n\n### Fixed\n- Included `lib/semver.mjs` and `lib/cron.mjs` in the release SBOM so signed archives contain every runtime library imported by shipped scripts.\n\n## [0.1.1] - 2026-05-13\n\n### Security\n- Added explicit signed release artifact verification instructions for standalone installs, including `checksums.json`, `checksums.sig`, `signing-public.pem`, archive hash verification, and `SKILL.md`/`skill.json` checksum checks.\n\n### Changed\n- Re-release skill payload metadata after excluding test-only files from release SBOMs and archives.\n\n## [0.1.0] - 2026-04-21\n\n- Added mandatory release verification gate guidance before install: `checksums.json`, `checksums.sig`, and pinned signing public-key fingerprint.\n- Added explicit Hermes guard trust-policy note for signature-aware trust (trusted signer fingerprint allowlist) over source-name-only trust.\n- Moved sandbox regression harness into the skill test surface (`test/hermes_attestation_sandbox_regression.sh`) and fixed in-skill default path resolution.\n- Tightened advisory feed verification to require checksum-manifest artifacts when checksum-manifest verification is enabled (fail-closed when missing).\n- Added feed regression coverage for missing local/remote checksum-manifest artifacts under strict verification mode.\n- Refactored cron setup scripts to share managed-block helpers from `lib/cron.mjs`, reducing drift risk.\n- Added explicit `.mjs` scan/test coverage guidance so Hermes-side scanner scope and regression harness context stay aligned with `scripts/*.mjs`, `lib/*.mjs`, and `test/*.test.mjs`.\n- Clarified fresh-node first-run edge-case documentation.\n- Clarified Hermes runtime metadata/frontmatter and README capability coverage for ClawHub publishing.\n- Removed compatibility-report wiki page references in favor of README capability matrix as the primary compatibility surface.\n- Updated skill metadata/docs to v0.1.0 and aligned README quickstart with fail-closed verification expectations.\n\n## [0.0.1] - 2026-04-15\n\n- Implemented deterministic Hermes attestation generator CLI (`scripts/generate_attestation.mjs`).\n- Implemented fail-closed verifier CLI with schema, canonical digest, expected checksum, and optional detached signature checks (`scripts/verify_attestation.mjs`).\n- Implemented meaningful baseline diff engine with stable severity mapping for risky toggle regressions, feed verification regressions, trust anchor drift, and watched file drift (`lib/diff.mjs`).\n- Implemented Hermes-only cron setup helper with print-only default and managed-block apply mode (`scripts/setup_attestation_cron.mjs`).\n- Added shared attestation library for canonicalization, schema validation, digest generation, and policy parsing (`lib/attestation.mjs`).\n- Expanded tests for schema determinism, diff behavior, generator/verifier fail-closed behavior, and cron helper Hermes-only output.\n- Updated metadata/docs to match actual implemented behavior and ClawSec release pipeline expectations.\n\nFile v0.1.2:skill.json\n\n{\n  \"name\": \"hermes-attestation-guardian\",\n  \"version\": \"0.1.2\",\n  \"description\": \"Hermes-only runtime security attestation and drift detection skill. Generates deterministic posture artifacts, verifies integrity fail-closed, and classifies baseline drift severity.\",\n  \"author\": \"prompt-security\",\n  \"license\": \"AGPL-3.0-or-later\",\n  \"homepage\": \"https://clawsec.prompt.security/\",\n  \"platform\": \"hermes\",\n  \"keywords\": [\n    \"security\",\n    \"hermes\",\n    \"attestation\",\n    \"integrity\",\n    \"drift-detection\",\n    \"posture\"\n  ],\n  \"sbom\": {\n    \"files\": [\n      {\n        \"path\": \"SKILL.md\",\n        \"required\": true,\n        \"description\": \"Skill documentation and operator playbook\"\n      },\n      {\n        \"path\": \"CHANGELOG.md\",\n        \"required\": true,\n        \"description\": \"Version history and release notes\"\n      },\n      {\n        \"path\": \"README.md\",\n        \"required\": true,\n        \"description\": \"Human-oriented overview and quickstart\"\n      },\n      {\n        \"path\": \"lib/attestation.mjs\",\n        \"required\": true,\n        \"description\": \"Attestation schema, canonicalization, digest and validation helpers\"\n      },\n      {\n        \"path\": \"lib/diff.mjs\",\n        \"required\": true,\n        \"description\": \"Baseline comparison and severity classification\"\n      },\n      {\n        \"path\": \"lib/feed.mjs\",\n        \"required\": true,\n        \"description\": \"Hermes-native advisory feed verification and state helpers\"\n      },\n      {\n        \"path\": \"lib/semver.mjs\",\n        \"required\": true,\n        \"description\": \"Advisory version-range parsing and matching helpers\"\n      },\n      {\n        \"path\": \"lib/cron.mjs\",\n        \"required\": true,\n        \"description\": \"Shared managed cron block and cadence helpers\"\n      },\n      {\n        \"path\": \"scripts/generate_attestation.mjs\",\n        \"required\": true,\n        \"description\": \"Generate deterministic Hermes posture attestation artifact\"\n      },\n      {\n        \"path\": \"scripts/verify_attestation.mjs\",\n        \"required\": true,\n        \"description\": \"Verify attestation schema, digest and optional detached signature\"\n      },\n      {\n        \"path\": \"scripts/refresh_advisory_feed.mjs\",\n        \"required\": true,\n        \"description\": \"Fetch, verify, and persist Hermes advisory feed verification state\"\n      },\n      {\n        \"path\": \"scripts/check_advisories.mjs\",\n        \"required\": true,\n        \"description\": \"Display human-readable advisory verification/feed summary\"\n      },\n      {\n        \"path\": \"scripts/guarded_skill_verify.mjs\",\n        \"required\": true,\n        \"description\": \"Advisory-aware guarded skill verification gate with explicit confirmation override\"\n      },\n      {\n        \"path\": \"scripts/setup_attestation_cron.mjs\",\n        \"required\": true,\n        \"description\": \"Optional recurring schedule setup for Hermes attestation runs\"\n      },\n      {\n        \"path\": \"scripts/setup_advisory_check_cron.mjs\",\n        \"required\": true,\n        \"description\": \"Optional recurring schedule setup for Hermes guarded advisory checks\"\n      }\n    ]\n  },\n  \"hermes\": {\n    \"emoji\": \"🛡️\",\n    \"category\": \"security\",\n    \"requires\": {\n      \"bins\": [\n        \"node\"\n      ]\n    },\n    \"runtime\": {\n      \"required_env\": [],\n      \"optional_env\": [\n        \"HERMES_HOME\",\n        \"HERMES_ATTESTATION_OUTPUT_DIR\",\n        \"HERMES_ATTESTATION_BASELINE\",\n        \"HERMES_ATTESTATION_INTERVAL\",\n        \"HERMES_ATTESTATION_FAIL_ON_SEVERITY\",\n        \"HERMES_ATTESTATION_POLICY\",\n        \"HERMES_ADVISORY_FEED_SOURCE\",\n        \"HERMES_ADVISORY_FEED_URL\",\n        \"HERMES_ADVISORY_FEED_SIG_URL\",\n        \"HERMES_ADVISORY_FEED_CHECKSUMS_URL\",\n        \"HERMES_ADVISORY_FEED_CHECKSUMS_SIG_URL\",\n        \"HERMES_LOCAL_ADVISORY_FEED\",\n        \"HERMES_LOCAL_ADVISORY_FEED_SIG\",\n        \"HERMES_LOCAL_ADVISORY_FEED_CHECKSUMS\",\n        \"HERMES_LOCAL_ADVISORY_FEED_CHECKSUMS_SIG\",\n        \"HERMES_ADVISORY_FEED_PUBLIC_KEY\",\n        \"HERMES_ADVISORY_ALLOW_UNSIGNED_FEED\",\n        \"HERMES_ADVISORY_VERIFY_CHECKSUM_MANIFEST\",\n        \"HERMES_ADVISORY_FEED_STATE_PATH\",\n        \"HERMES_ADVISORY_CACHED_FEED\"\n      ]\n    },\n    \"execution\": {\n      \"always\": false,\n      \"persistence\": \"Runs on demand by default. Optional scheduler helper can install a managed schedule block when run with --apply.\",\n      \"network_egress\": \"Optional HTTPS advisory feed fetch via refresh_advisory_feed.mjs; no network required for local-mode verification\"\n    },\n    \"operator_review\": [\n      \"Hermes-only skill: unsupported for OpenClaw runtime hooks.\",\n      \"Verify watch/trust-anchor policy paths before scheduling recurring runs.\",\n      \"Verification fails closed for schema/digest/signature errors and unauthenticated baseline inputs; diff threshold defaults to critical.\",\n      \"Advisory feed verification is fail-closed by default; unsigned bypass must remain temporary and operator-audited.\"\n    ],\n    \"triggers\": [\n      \"generate hermes attestation\",\n      \"verify hermes attestation\",\n      \"hermes runtime drift detection\",\n      \"hermes trust anchor drift\",\n      \"refresh hermes advisory feed\",\n      \"check hermes advisories\",\n      \"guarded hermes skill verification\",\n      \"setup hermes attestation cron\",\n      \"setup hermes advisory check cron\"\n    ]\n  }\n}\n\nArchive v0.1.1: 25 files, 60711 bytes\n\nFiles: CHANGELOG.md (2828b), lib/attestation.mjs (16502b), lib/cron.mjs (5146b), lib/diff.mjs (7725b), lib/feed.mjs (26937b), lib/semver.mjs (5897b), README.md (2360b), scripts/check_advisories.mjs (3165b), scripts/generate_attestation.mjs (4670b), scripts/guarded_skill_verify.mjs (6531b), scripts/refresh_advisory_feed.mjs (3208b), scripts/setup_advisory_check_cron.mjs (5496b), scripts/setup_attestation_cron.mjs (7002b), scripts/verify_attestation.mjs (11353b), skill.json (4961b), SKILL.md (10257b), test/attestation_cli.test.mjs (10377b), test/attestation_diff.test.mjs (2246b), test/attestation_schema.test.mjs (13105b), test/feed_verification.test.mjs (26499b), test/guarded_skill_verify.test.mjs (11172b), test/hermes_attestation_sandbox_regression.sh (11530b), test/setup_advisory_check_cron.test.mjs (11999b), test/setup_attestation_cron.test.mjs (9306b), _meta.json (146b)\n\nFile v0.1.1:SKILL.md\n\n---\nname: hermes-attestation-guardian\nversion: 0.1.1\ndescription: Hermes-only runtime security attestation and drift detection skill for operator-managed Hermes infrastructure.\nhomepage: https://clawsec.prompt.security\nhermes:\n  emoji: \"🛡️\"\n  requires:\n    bins: [node]\n---\n\n# Hermes Attestation Guardian\n\nIMPORTANT SCOPE:\n- This skill targets Hermes infrastructure only (CLI/Gateway/profile-managed deployments).\n- This skill is not an OpenClaw runtime hook package.\n\n\n## Release Artifact Verification\n\nFor standalone installs, verify the signed release manifest before trusting `SKILL.md`, `skill.json`, or the archive. The `skill.json` file is the package metadata/SBOM source, and the release pipeline signs `checksums.json` with the ClawSec release key.\n\n```bash\nset -euo pipefail\n\nSKILL_NAME=\"hermes-attestation-guardian\"\nVERSION=\"0.1.1\"\nREPO=\"prompt-security/clawsec\"\nTAG=\"${SKILL_NAME}-v${VERSION}\"\nBASE=\"https://github.com/${REPO}/releases/download/${TAG}\"\nZIP_NAME=\"${SKILL_NAME}-v${VERSION}.zip\"\nTMP_DIR=\"$(mktemp -d)\"\ntrap 'rm -rf \"$TMP_DIR\"' EXIT\n\nRELEASE_PUBKEY_SHA256=\"711424e4535f84093fefb024cd1ca4ec87439e53907b305b79a631d5befba9c8\"\n\ncurl -fsSL \"$BASE/checksums.json\" -o \"$TMP_DIR/checksums.json\"\ncurl -fsSL \"$BASE/checksums.sig\" -o \"$TMP_DIR/checksums.sig\"\ncurl -fsSL \"$BASE/signing-public.pem\" -o \"$TMP_DIR/signing-public.pem\"\ncurl -fsSL \"$BASE/$ZIP_NAME\" -o \"$TMP_DIR/$ZIP_NAME\"\ncurl -fsSL \"$BASE/SKILL.md\" -o \"$TMP_DIR/SKILL.md\"\ncurl -fsSL \"$BASE/skill.json\" -o \"$TMP_DIR/skill.json\"\n\nACTUAL_PUBKEY_SHA256=\"$(openssl pkey -pubin -in \"$TMP_DIR/signing-public.pem\" -outform DER | shasum -a 256 | awk '{print $1}')\"\nif [ \"$ACTUAL_PUBKEY_SHA256\" != \"$RELEASE_PUBKEY_SHA256\" ]; then\n  echo \"ERROR: signing-public.pem fingerprint mismatch\" >&2\n  exit 1\nfi\n\nopenssl base64 -d -A -in \"$TMP_DIR/checksums.sig\" -out \"$TMP_DIR/checksums.sig.bin\"\nopenssl pkeyutl -verify -rawin -pubin \\\n  -inkey \"$TMP_DIR/signing-public.pem\" \\\n  -sigfile \"$TMP_DIR/checksums.sig.bin\" \\\n  -in \"$TMP_DIR/checksums.json\" >/dev/null\n\nhash_file() {\n  if command -v shasum >/dev/null 2>&1; then\n    shasum -a 256 \"$1\" | awk '{print $1}'\n  else\n    sha256sum \"$1\" | awk '{print $1}'\n  fi\n}\n\nverify_manifest_file() {\n  asset=\"$1\"\n  path=\"$2\"\n  expected=\"$(jq -r --arg asset \"$asset\" '.files[$asset].sha256 // empty' \"$TMP_DIR/checksums.json\")\"\n  if [ -z \"$expected\" ]; then\n    echo \"ERROR: checksums.json missing $asset\" >&2\n    exit 1\n  fi\n  actual=\"$(hash_file \"$path\")\"\n  if [ \"$actual\" != \"$expected\" ]; then\n    echo \"ERROR: checksum mismatch for $asset\" >&2\n    exit 1\n  fi\n}\n\nexpected_archive=\"$(jq -r '.archive.sha256 // empty' \"$TMP_DIR/checksums.json\")\"\nif [ -z \"$expected_archive\" ]; then\n  echo \"ERROR: checksums.json missing archive.sha256\" >&2\n  exit 1\nfi\nactual_archive=\"$(hash_file \"$TMP_DIR/$ZIP_NAME\")\"\nif [ \"$actual_archive\" != \"$expected_archive\" ]; then\n  echo \"ERROR: archive checksum mismatch\" >&2\n  exit 1\nfi\n\nverify_manifest_file \"SKILL.md\" \"$TMP_DIR/SKILL.md\"\nverify_manifest_file \"skill.json\" \"$TMP_DIR/skill.json\"\n\necho \"Signed release manifest, archive, SKILL.md, and skill.json verified.\"\n```\n\nOnly install or extract the archive after this verification succeeds.\n\n## Goal\n\nGenerate deterministic Hermes posture attestations, verify them with fail-closed integrity checks, and compare baseline drift using stable severity mapping.\n\n## Hermes guard trust policy note\n\nWhen installing from community sources, configure Hermes guard to use signature-aware trust (trusted signer fingerprint allowlist) rather than source-name-only trust. Unknown signer fingerprints should stay on community policy, and invalid signatures must remain blocked.\n\n## Commands\n\n```bash\n# Generate attestation (default output: ~/.hermes/security/attestations/current.json)\nnode scripts/generate_attestation.mjs\n\n# Generate with explicit policy + deterministic timestamp\nnode scripts/generate_attestation.mjs \\\n  --policy ~/.hermes/security/attestation-policy.json \\\n  --generated-at 2026-04-15T18:00:00.000Z \\\n  --write-sha256\n\n# Verify schema + canonical digest\nnode scripts/verify_attestation.mjs --input ~/.hermes/security/attestations/current.json\n\n# Verify with baseline diff (baseline must be authenticated)\nnode scripts/verify_attestation.mjs \\\n  --input ~/.hermes/security/attestations/current.json \\\n  --baseline ~/.hermes/security/attestations/baseline.json \\\n  --baseline-expected-sha256 <trusted-baseline-sha256> \\\n  --fail-on-severity high\n\n# Optional detached signature verification\nnode scripts/verify_attestation.mjs \\\n  --input ~/.hermes/security/attestations/current.json \\\n  --signature ~/.hermes/security/attestations/current.json.sig \\\n  --public-key ~/.hermes/security/keys/attestation-public.pem\n\n# Refresh advisory feed verification state (fail-closed by default)\nnode scripts/refresh_advisory_feed.mjs\n\n# Check advisory feed verification + feed summary\nnode scripts/check_advisories.mjs\n\n# Guarded advisory-aware skill verification gate (returns 42 on advisory match without explicit confirm)\nnode scripts/guarded_skill_verify.mjs --skill some-skill --version 1.2.3\n\n# Explicit operator acknowledgement path for advisory matches\nnode scripts/guarded_skill_verify.mjs --skill some-skill --version 1.2.3 --confirm-advisory\n\n# Optional temporary unsigned bypass (dangerous; emergency-only)\nHERMES_ADVISORY_ALLOW_UNSIGNED_FEED=1 node scripts/refresh_advisory_feed.mjs --allow-unsigned\n\n# Preview scheduler config without mutating user schedule state\nnode scripts/setup_attestation_cron.mjs --every 6h --print-only\n\n# Apply managed scheduler block\nnode scripts/setup_attestation_cron.mjs --every 6h --apply\n\n# Preview advisory check scheduler config (guarded flow, print-only default)\nnode scripts/setup_advisory_check_cron.mjs --every 6h --skill some-skill --print-only\n\n# Apply advisory check scheduler block (uses guarded_skill_verify flow)\nnode scripts/setup_advisory_check_cron.mjs --every 6h --skill some-skill --version 1.2.3 --apply\n\n# Emergency-only: unsigned bypass for scheduled advisory checks (do not keep enabled)\nnode scripts/setup_advisory_check_cron.mjs --every 6h --skill some-skill --allow-unsigned --apply\n```\n\nWARNING: `--allow-unsigned` in scheduled commands is incident-response only. Remove it immediately after recovery and restore signed advisory verification.\n\n## Attestation payload (implemented)\n\nThe generator emits:\n- schema_version, platform, generated_at\n- generator metadata (skill + node version)\n- host metadata (hostname/platform/arch)\n- posture.runtime (gateway enabled flags + risky toggles)\n- posture.feed_verification status (verified|unverified|unknown) sourced from `$HERMES_HOME/security/advisories/feed-verification-state.json`\n- posture.integrity watched_files and trust_anchors (existence + sha256)\n- digests.canonical_sha256 over a stable canonical JSON representation\n\n## Fail-closed behavior\n\nVerifier exits non-zero when:\n- schema validation fails\n- canonical digest algorithm is unsupported or digest binding mismatches\n- expected file sha256 mismatches (if configured)\n- detached signature verification fails (if configured)\n- baseline is provided without authenticated trust binding (`--baseline-expected-sha256` and/or baseline signature + public key)\n- baseline authenticity or baseline schema/digest validation fails\n- baseline diff highest severity is at/above `--fail-on-severity` (default: critical)\n\nSeverity messages are emitted as INFO / WARNING / CRITICAL style lines.\n\n## Side effects\n\n- `generate_attestation.mjs` writes one JSON file (and optional `.sha256`) under `$HERMES_HOME/security/attestations`.\n- `verify_attestation.mjs` is read-only.\n- `refresh_advisory_feed.mjs` writes verified feed cache + verification state under `$HERMES_HOME/security/advisories`.\n- `check_advisories.mjs` is read-only.\n- `guarded_skill_verify.mjs` re-runs feed refresh/verification (same advisory cache + state side effects) and then performs advisory-aware gate checks.\n- `setup_attestation_cron.mjs` is read-only unless `--apply` is provided.\n- `setup_attestation_cron.mjs --apply` rewrites only the current user managed schedule block delimited by:\n  - `# >>> hermes-attestation-guardian >>>`\n  - `# <<< hermes-attestation-guardian <<<`\n- `setup_advisory_check_cron.mjs` is read-only unless `--apply` is provided.\n- `setup_advisory_check_cron.mjs --apply` rewrites only the current user advisory-check managed schedule block delimited by:\n  - `# >>> hermes-attestation-guardian-advisory-check >>>`\n  - `# <<< hermes-attestation-guardian-advisory-check <<<`\n  - generated command path uses `guarded_skill_verify.mjs` (advisory-aware gate), not raw `check_advisories.mjs`\n\n## Advisory feed override knobs\n\n- Source selection: `HERMES_ADVISORY_FEED_SOURCE=auto|remote|local`\n- Remote artifacts: `HERMES_ADVISORY_FEED_URL`, `HERMES_ADVISORY_FEED_SIG_URL`, `HERMES_ADVISORY_FEED_CHECKSUMS_URL`, `HERMES_ADVISORY_FEED_CHECKSUMS_SIG_URL`\n- Local artifacts: `HERMES_LOCAL_ADVISORY_FEED`, `HERMES_LOCAL_ADVISORY_FEED_SIG`, `HERMES_LOCAL_ADVISORY_FEED_CHECKSUMS`, `HERMES_LOCAL_ADVISORY_FEED_CHECKSUMS_SIG`\n- Pinned key override: `HERMES_ADVISORY_FEED_PUBLIC_KEY` (default is built-in pinned key)\n- Optional checksum toggle: `HERMES_ADVISORY_VERIFY_CHECKSUM_MANIFEST` (default: enabled)\n- UNSAFE emergency bypass only: `HERMES_ADVISORY_ALLOW_UNSIGNED_FEED=1`\n\n## Notes\n\n- Hermes scan + test context is `.mjs`-based by design:\n  - runtime scripts: `scripts/*.mjs`\n  - shared libraries: `lib/*.mjs`\n  - regression tests: `test/*.test.mjs`\n- Keep `.mjs` paths/extensions stable so scanner scope, SBOM wiring, and test harness references stay valid.\n- Default output root is `~/.hermes/security/attestations/`.\n- No destructive remediation actions (delete/restore/quarantine) are implemented.\n- Advisory feed remote URL allowlisting is not implemented in v0.0.2; operators must explicitly trust configured feed/checksum endpoints.\n- Guarded advisory version matching currently uses a lightweight comparator parser (`>=`, `<=`, `>`, `<`, `=`, `^`, `~`, wildcard `*`) and does not implement full npm semver range grammar (for example, OR ranges and complex comparator sets).\n- Operator policy file is optional JSON with:\n  - `watch_files`: list of file paths\n  - `trust_anchor_files`: list of file paths\n\nFile v0.1.1:README.md\n\n# hermes-attestation-guardian\n\nHermes-only attestation, advisory verification, and guarded verification workflow.\n\nStatus: implemented (v0.1.0), Hermes-only.\n\n## Capabilities\n\nThis skill now covers the full Hermes-side capability set expected from the clawsec-suite parity workstream:\n\n- Deterministic runtime posture attestation generation.\n- Fail-closed attestation verification (schema + canonical digest).\n- Optional detached signature verification for attestation artifacts.\n- Authenticated baseline diffing with stable severity classification.\n- Scoped output-path enforcement under `$HERMES_HOME`.\n- Signed advisory feed verification (Ed25519) with optional checksum-manifest verification.\n- Fail-closed advisory verification state persistence under `$HERMES_HOME/security/advisories`.\n- Advisory-aware guarded skill verification with explicit `--confirm-advisory` override.\n- Optional recurring scheduler helpers for attestation and advisory checks (print-only by default, explicit apply mode).\n- Sandboxed end-to-end regression harness for install + verify + advisory gates.\n\n## Quickstart\n\nCanonical release verification and trust-policy guidance lives in `SKILL.md`:\n- `Mandatory release verification gate (before install)`\n- `Hermes guard trust policy note`\n\nAfter running that gate, use:\n\n```bash\nnode scripts/generate_attestation.mjs\nnode scripts/verify_attestation.mjs --input ~/.hermes/security/attestations/current.json\nnode scripts/refresh_advisory_feed.mjs\nnode scripts/check_advisories.mjs\nnode scripts/guarded_skill_verify.mjs --skill some-skill --version 1.2.3\nnode scripts/setup_attestation_cron.mjs --every 6h --print-only\nnode scripts/setup_advisory_check_cron.mjs --every 6h --skill some-skill --print-only\n```\n\nScheduler safety warning: never leave `--allow-unsigned` enabled in recurring advisory check jobs except during short emergency recovery windows.\n\n## Runtime requirements\n\nRequired:\n- `node`\n\nOptional tooling (for local verification workflows):\n- `openssl`, `bash`, `docker`\n\n## Tests\n\n```bash\nnode test/attestation_schema.test.mjs\nnode test/attestation_diff.test.mjs\nnode test/attestation_cli.test.mjs\nnode test/setup_attestation_cron.test.mjs\nnode test/setup_advisory_check_cron.test.mjs\nnode test/feed_verification.test.mjs\nnode test/guarded_skill_verify.test.mjs\nbash test/hermes_attestation_sandbox_regression.sh\n```\n\nFile v0.1.1:_meta.json\n\n{\n  \"ownerId\": \"kn76m78f01hqrtpgm895s0jsax80jd8v\",\n  \"slug\": \"hermes-attestation-guardian\",\n  \"version\": \"0.1.1\",\n  \"publishedAt\": 1778758987920\n}\n\nFile v0.1.1:CHANGELOG.md\n\n# Changelog\n\n## [0.1.1] - 2026-05-13\n\n### Security\n- Added explicit signed release artifact verification instructions for standalone installs, including `checksums.json`, `checksums.sig`, `signing-public.pem`, archive hash verification, and `SKILL.md`/`skill.json` checksum checks.\n\n### Changed\n- Re-release skill payload metadata after excluding test-only files from release SBOMs and archives.\n\n## [0.1.0] - 2026-04-21\n\n- Added mandatory release verification gate guidance before install: `checksums.json`, `checksums.sig`, and pinned signing public-key fingerprint.\n- Added explicit Hermes guard trust-policy note for signature-aware trust (trusted signer fingerprint allowlist) over source-name-only trust.\n- Moved sandbox regression harness into the skill test surface (`test/hermes_attestation_sandbox_regression.sh`) and fixed in-skill default path resolution.\n- Tightened advisory feed verification to require checksum-manifest artifacts when checksum-manifest verification is enabled (fail-closed when missing).\n- Added feed regression coverage for missing local/remote checksum-manifest artifacts under strict verification mode.\n- Refactored cron setup scripts to share managed-block helpers from `lib/cron.mjs`, reducing drift risk.\n- Added explicit `.mjs` scan/test coverage guidance so Hermes-side scanner scope and regression harness context stay aligned with `scripts/*.mjs`, `lib/*.mjs`, and `test/*.test.mjs`.\n- Clarified fresh-node first-run edge-case documentation.\n- Clarified Hermes runtime metadata/frontmatter and README capability coverage for ClawHub publishing.\n- Removed compatibility-report wiki page references in favor of README capability matrix as the primary compatibility surface.\n- Updated skill metadata/docs to v0.1.0 and aligned README quickstart with fail-closed verification expectations.\n\n## [0.0.1] - 2026-04-15\n\n- Implemented deterministic Hermes attestation generator CLI (`scripts/generate_attestation.mjs`).\n- Implemented fail-closed verifier CLI with schema, canonical digest, expected checksum, and optional detached signature checks (`scripts/verify_attestation.mjs`).\n- Implemented meaningful baseline diff engine with stable severity mapping for risky toggle regressions, feed verification regressions, trust anchor drift, and watched file drift (`lib/diff.mjs`).\n- Implemented Hermes-only cron setup helper with print-only default and managed-block apply mode (`scripts/setup_attestation_cron.mjs`).\n- Added shared attestation library for canonicalization, schema validation, digest generation, and policy parsing (`lib/attestation.mjs`).\n- Expanded tests for schema determinism, diff behavior, generator/verifier fail-closed behavior, and cron helper Hermes-only output.\n- Updated metadata/docs to match actual implemented behavior and ClawSec release pipeline expectations.\n\nFile v0.1.1:skill.json\n\n{\n  \"name\": \"hermes-attestation-guardian\",\n  \"version\": \"0.1.1\",\n  \"description\": \"Hermes-only runtime security attestation and drift detection skill. Generates deterministic posture artifacts, verifies integrity fail-closed, and classifies baseline drift severity.\",\n  \"author\": \"prompt-security\",\n  \"license\": \"AGPL-3.0-or-later\",\n  \"homepage\": \"https://clawsec.prompt.security/\",\n  \"platform\": \"hermes\",\n  \"keywords\": [\n    \"security\",\n    \"hermes\",\n    \"attestation\",\n    \"integrity\",\n    \"drift-detection\",\n    \"posture\"\n  ],\n  \"sbom\": {\n    \"files\": [\n      {\n        \"path\": \"SKILL.md\",\n        \"required\": true,\n        \"description\": \"Skill documentation and operator playbook\"\n      },\n      {\n        \"path\": \"CHANGELOG.md\",\n        \"required\": true,\n        \"description\": \"Version history and release notes\"\n      },\n      {\n        \"path\": \"README.md\",\n        \"required\": true,\n        \"description\": \"Human-oriented overview and quickstart\"\n      },\n      {\n        \"path\": \"lib/attestation.mjs\",\n        \"required\": true,\n        \"description\": \"Attestation schema, canonicalization, digest and validation helpers\"\n      },\n      {\n        \"path\": \"lib/diff.mjs\",\n        \"required\": true,\n        \"description\": \"Baseline comparison and severity classification\"\n      },\n      {\n        \"path\": \"lib/feed.mjs\",\n        \"required\": true,\n        \"description\": \"Hermes-native advisory feed verification and state helpers\"\n      },\n      {\n        \"path\": \"scripts/generate_attestation.mjs\",\n        \"required\": true,\n        \"description\": \"Generate deterministic Hermes posture attestation artifact\"\n      },\n      {\n        \"path\": \"scripts/verify_attestation.mjs\",\n        \"required\": true,\n        \"description\": \"Verify attestation schema, digest and optional detached signature\"\n      },\n      {\n        \"path\": \"scripts/refresh_advisory_feed.mjs\",\n        \"required\": true,\n        \"description\": \"Fetch, verify, and persist Hermes advisory feed verification state\"\n      },\n      {\n        \"path\": \"scripts/check_advisories.mjs\",\n        \"required\": true,\n        \"description\": \"Display human-readable advisory verification/feed summary\"\n      },\n      {\n        \"path\": \"scripts/guarded_skill_verify.mjs\",\n        \"required\": true,\n        \"description\": \"Advisory-aware guarded skill verification gate with explicit confirmation override\"\n      },\n      {\n        \"path\": \"scripts/setup_attestation_cron.mjs\",\n        \"required\": true,\n        \"description\": \"Optional recurring schedule setup for Hermes attestation runs\"\n      },\n      {\n        \"path\": \"scripts/setup_advisory_check_cron.mjs\",\n        \"required\": true,\n        \"description\": \"Optional recurring schedule setup for Hermes guarded advisory checks\"\n      }\n    ]\n  },\n  \"hermes\": {\n    \"emoji\": \"🛡️\",\n    \"category\": \"security\",\n    \"requires\": {\n      \"bins\": [\n        \"node\"\n      ]\n    },\n    \"runtime\": {\n      \"required_env\": [],\n      \"optional_env\": [\n        \"HERMES_HOME\",\n        \"HERMES_ATTESTATION_OUTPUT_DIR\",\n        \"HERMES_ATTESTATION_BASELINE\",\n        \"HERMES_ATTESTATION_INTERVAL\",\n        \"HERMES_ATTESTATION_FAIL_ON_SEVERITY\",\n        \"HERMES_ATTESTATION_POLICY\",\n        \"HERMES_ADVISORY_FEED_SOURCE\",\n        \"HERMES_ADVISORY_FEED_URL\",\n        \"HERMES_ADVISORY_FEED_SIG_URL\",\n        \"HERMES_ADVISORY_FEED_CHECKSUMS_URL\",\n        \"HERMES_ADVISORY_FEED_CHECKSUMS_SIG_URL\",\n        \"HERMES_LOCAL_ADVISORY_FEED\",\n        \"HERMES_LOCAL_ADVISORY_FEED_SIG\",\n        \"HERMES_LOCAL_ADVISORY_FEED_CHECKSUMS\",\n        \"HERMES_LOCAL_ADVISORY_FEED_CHECKSUMS_SIG\",\n        \"HERMES_ADVISORY_FEED_PUBLIC_KEY\",\n        \"HERMES_ADVISORY_ALLOW_UNSIGNED_FEED\",\n        \"HERMES_ADVISORY_VERIFY_CHECKSUM_MANIFEST\",\n        \"HERMES_ADVISORY_FEED_STATE_PATH\",\n        \"HERMES_ADVISORY_CACHED_FEED\"\n      ]\n    },\n    \"execution\": {\n      \"always\": false,\n      \"persistence\": \"Runs on demand by default. Optional scheduler helper can install a managed schedule block when run with --apply.\",\n      \"network_egress\": \"Optional HTTPS advisory feed fetch via refresh_advisory_feed.mjs; no network required for local-mode verification\"\n    },\n    \"operator_review\": [\n      \"Hermes-only skill: unsupported for OpenClaw runtime hooks.\",\n      \"Verify watch/trust-anchor policy paths before scheduling recurring runs.\",\n      \"Verification fails closed for schema/digest/signature errors and unauthenticated baseline inputs; diff threshold defaults to critical.\",\n      \"Advisory feed verification is fail-closed by default; unsigned bypass must remain temporary and operator-audited.\"\n    ],\n    \"triggers\": [\n      \"generate hermes attestation\",\n      \"verify hermes attestation\",\n      \"hermes runtime drift detection\",\n      \"hermes trust anchor drift\",\n      \"refresh hermes advisory feed\",\n      \"check hermes advisories\",\n      \"guarded hermes skill verification\",\n      \"setup hermes attestation cron\",\n      \"setup hermes advisory check cron\"\n    ]\n  }\n}\n\nArchive v0.1.0: 25 files, 60326 bytes\n\nFiles: CHANGELOG.md (2444b), lib/attestation.mjs (16502b), lib/cron.mjs (5146b), lib/diff.mjs (7725b), lib/feed.mjs (26937b), lib/semver.mjs (5897b), README.md (2360b), scripts/check_advisories.mjs (3165b), scripts/generate_attestation.mjs (4670b), scripts/guarded_skill_verify.mjs (6531b), scripts/refresh_advisory_feed.mjs (3208b), scripts/setup_advisory_check_cron.mjs (5496b), scripts/setup_attestation_cron.mjs (7002b), scripts/verify_attestation.mjs (11353b), skill.json (6315b), SKILL.md (8850b), test/attestation_cli.test.mjs (10377b), test/attestation_diff.test.mjs (2246b), test/attestation_schema.test.mjs (13105b), test/feed_verification.test.mjs (26499b), test/guarded_skill_verify.test.mjs (11172b), test/hermes_attestation_sandbox_regression.sh (11530b), test/setup_advisory_check_cron.test.mjs (11999b), test/setup_attestation_cron.test.mjs (9306b), _meta.json (146b)\n\nFile v0.1.0:SKILL.md\n\n---\nname: hermes-attestation-guardian\nversion: 0.1.0\ndescription: Hermes-only runtime security attestation and drift detection skill for operator-managed Hermes infrastructure.\nhomepage: https://clawsec.prompt.security\nhermes:\n  emoji: \"🛡️\"\n  requires:\n    bins: [node]\n---\n\n# Hermes Attestation Guardian\n\nIMPORTANT SCOPE:\n- This skill targets Hermes infrastructure only (CLI/Gateway/profile-managed deployments).\n- This skill is not an OpenClaw runtime hook package.\n\n## Goal\n\nGenerate deterministic Hermes posture attestations, verify them with fail-closed integrity checks, and compare baseline drift using stable severity mapping.\n\n## Mandatory release verification gate (before install)\n\nBefore treating any release install instructions as valid, verify all three inputs:\n\n1) `checksums.json`\n2) `checksums.sig`\n3) pinned signing public-key fingerprint\n\n```bash\nBASE=\"https://github.com/prompt-security/clawsec/releases/download/hermes-attestation-guardian-v0.1.0\"\nTMP=\"$(mktemp -d)\"\ntrap 'rm -rf \"$TMP\"' EXIT\n\ncurl -fsSL \"$BASE/checksums.json\" -o \"$TMP/checksums.json\"\ncurl -fsSL \"$BASE/checksums.sig\" -o \"$TMP/checksums.sig\"\ncurl -fsSL \"$BASE/signing-public.pem\" -o \"$TMP/signing-public.pem\"\n\n[ -s \"$TMP/checksums.json\" ] || { echo \"ERROR: missing checksums.json\" >&2; exit 1; }\n[ -s \"$TMP/checksums.sig\" ] || { echo \"ERROR: missing checksums.sig\" >&2; exit 1; }\n\nEXPECTED_PUBKEY_SHA256=\"711424e4535f84093fefb024cd1ca4ec87439e53907b305b79a631d5befba9c8\"\nACTUAL_PUBKEY_SHA256=\"$(openssl pkey -pubin -in \"$TMP/signing-public.pem\" -outform DER | sha256sum | awk '{print $1}')\"\n[ \"$ACTUAL_PUBKEY_SHA256\" = \"$EXPECTED_PUBKEY_SHA256\" ] || {\n  echo \"ERROR: signing-public.pem fingerprint mismatch\" >&2\n  exit 1\n}\n\nopenssl base64 -d -A -in \"$TMP/checksums.sig\" -out \"$TMP/checksums.sig.bin\"\nopenssl pkeyutl -verify -rawin -pubin -inkey \"$TMP/signing-public.pem\" \\\n  -sigfile \"$TMP/checksums.sig.bin\" -in \"$TMP/checksums.json\" >/dev/null\n```\n\n## Hermes guard trust policy note\n\nWhen installing from community sources, configure Hermes guard to use signature-aware trust (trusted signer fingerprint allowlist) rather than source-name-only trust. Unknown signer fingerprints should stay on community policy, and invalid signatures must remain blocked.\n\n## Commands\n\n```bash\n# Generate attestation (default output: ~/.hermes/security/attestations/current.json)\nnode scripts/generate_attestation.mjs\n\n# Generate with explicit policy + deterministic timestamp\nnode scripts/generate_attestation.mjs \\\n  --policy ~/.hermes/security/attestation-policy.json \\\n  --generated-at 2026-04-15T18:00:00.000Z \\\n  --write-sha256\n\n# Verify schema + canonical digest\nnode scripts/verify_attestation.mjs --input ~/.hermes/security/attestations/current.json\n\n# Verify with baseline diff (baseline must be authenticated)\nnode scripts/verify_attestation.mjs \\\n  --input ~/.hermes/security/attestations/current.json \\\n  --baseline ~/.hermes/security/attestations/baseline.json \\\n  --baseline-expected-sha256 <trusted-baseline-sha256> \\\n  --fail-on-severity high\n\n# Optional detached signature verification\nnode scripts/verify_attestation.mjs \\\n  --input ~/.hermes/security/attestations/current.json \\\n  --signature ~/.hermes/security/attestations/current.json.sig \\\n  --public-key ~/.hermes/security/keys/attestation-public.pem\n\n# Refresh advisory feed verification state (fail-closed by default)\nnode scripts/refresh_advisory_feed.mjs\n\n# Check advisory feed verification + feed summary\nnode scripts/check_advisories.mjs\n\n# Guarded advisory-aware skill verification gate (returns 42 on advisory match without explicit confirm)\nnode scripts/guarded_skill_verify.mjs --skill some-skill --version 1.2.3\n\n# Explicit operator acknowledgement path for advisory matches\nnode scripts/guarded_skill_verify.mjs --skill some-skill --version 1.2.3 --confirm-advisory\n\n# Optional temporary unsigned bypass (dangerous; emergency-only)\nHERMES_ADVISORY_ALLOW_UNSIGNED_FEED=1 node scripts/refresh_advisory_feed.mjs --allow-unsigned\n\n# Preview scheduler config without mutating user schedule state\nnode scripts/setup_attestation_cron.mjs --every 6h --print-only\n\n# Apply managed scheduler block\nnode scripts/setup_attestation_cron.mjs --every 6h --apply\n\n# Preview advisory check scheduler config (guarded flow, print-only default)\nnode scripts/setup_advisory_check_cron.mjs --every 6h --skill some-skill --print-only\n\n# Apply advisory check scheduler block (uses guarded_skill_verify flow)\nnode scripts/setup_advisory_check_cron.mjs --every 6h --skill some-skill --version 1.2.3 --apply\n\n# Emergency-only: unsigned bypass for scheduled advisory checks (do not keep enabled)\nnode scripts/setup_advisory_check_cron.mjs --every 6h --skill some-skill --allow-unsigned --apply\n```\n\nWARNING: `--allow-unsigned` in scheduled commands is incident-response only. Remove it immediately after recovery and restore signed advisory verification.\n\n## Attestation payload (implemented)\n\nThe generator emits:\n- schema_version, platform, generated_at\n- generator metadata (skill + node version)\n- host metadata (hostname/platform/arch)\n- posture.runtime (gateway enabled flags + risky toggles)\n- posture.feed_verification status (verified|unverified|unknown) sourced from `$HERMES_HOME/security/advisories/feed-verification-state.json`\n- posture.integrity watched_files and trust_anchors (existence + sha256)\n- digests.canonical_sha256 over a stable canonical JSON representation\n\n## Fail-closed behavior\n\nVerifier exits non-zero when:\n- schema validation fails\n- canonical digest algorithm is unsupported or digest binding mismatches\n- expected file sha256 mismatches (if configured)\n- detached signature verification fails (if configured)\n- baseline is provided without authenticated trust binding (`--baseline-expected-sha256` and/or baseline signature + public key)\n- baseline authenticity or baseline schema/digest validation fails\n- baseline diff highest severity is at/above `--fail-on-severity` (default: critical)\n\nSeverity messages are emitted as INFO / WARNING / CRITICAL style lines.\n\n## Side effects\n\n- `generate_attestation.mjs` writes one JSON file (and optional `.sha256`) under `$HERMES_HOME/security/attestations`.\n- `verify_attestation.mjs` is read-only.\n- `refresh_advisory_feed.mjs` writes verified feed cache + verification state under `$HERMES_HOME/security/advisories`.\n- `check_advisories.mjs` is read-only.\n- `guarded_skill_verify.mjs` re-runs feed refresh/verification (same advisory cache + state side effects) and then performs advisory-aware gate checks.\n- `setup_attestation_cron.mjs` is read-only unless `--apply` is provided.\n- `setup_attestation_cron.mjs --apply` rewrites only the current user managed schedule block delimited by:\n  - `# >>> hermes-attestation-guardian >>>`\n  - `# <<< hermes-attestation-guardian <<<`\n- `setup_advisory_check_cron.mjs` is read-only unless `--apply` is provided.\n- `setup_advisory_check_cron.mjs --apply` rewrites only the current user advisory-check managed schedule block delimited by:\n  - `# >>> hermes-attestation-guardian-advisory-check >>>`\n  - `# <<< hermes-attestation-guardian-advisory-check <<<`\n  - generated command path uses `guarded_skill_verify.mjs` (advisory-aware gate), not raw `check_advisories.mjs`\n\n## Advisory feed override knobs\n\n- Source selection: `HERMES_ADVISORY_FEED_SOURCE=auto|remote|local`\n- Remote artifacts: `HERMES_ADVISORY_FEED_URL`, `HERMES_ADVISORY_FEED_SIG_URL`, `HERMES_ADVISORY_FEED_CHECKSUMS_URL`, `HERMES_ADVISORY_FEED_CHECKSUMS_SIG_URL`\n- Local artifacts: `HERMES_LOCAL_ADVISORY_FEED`, `HERMES_LOCAL_ADVISORY_FEED_SIG`, `HERMES_LOCAL_ADVISORY_FEED_CHECKSUMS`, `HERMES_LOCAL_ADVISORY_FEED_CHECKSUMS_SIG`\n- Pinned key override: `HERMES_ADVISORY_FEED_PUBLIC_KEY` (default is built-in pinned key)\n- Optional checksum toggle: `HERMES_ADVISORY_VERIFY_CHECKSUM_MANIFEST` (default: enabled)\n- UNSAFE emergency bypass only: `HERMES_ADVISORY_ALLOW_UNSIGNED_FEED=1`\n\n## Notes\n\n- Hermes scan + test context is `.mjs`-based by design:\n  - runtime scripts: `scripts/*.mjs`\n  - shared libraries: `lib/*.mjs`\n  - regression tests: `test/*.test.mjs`\n- Keep `.mjs` paths/extensions stable so scanner scope, SBOM wiring, and test harness references stay valid.\n- Default output root is `~/.hermes/security/attestations/`.\n- No destructive remediation actions (delete/restore/quarantine) are implemented.\n- Advisory feed remote URL allowlisting is not implemented in v0.0.2; operators must explicitly trust configured feed/checksum endpoints.\n- Guarded advisory version matching currently uses a lightweight comparator parser (`>=`, `<=`, `>`, `<`, `=`, `^`, `~`, wildcard `*`) and does not implement full npm semver range grammar (for example, OR ranges and complex comparator sets).\n- Operator policy file is optional JSON with:\n  - `watch_files`: list of file paths\n  - `trust_anchor_files`: list of file paths\n\nFile v0.1.0:README.md\n\n# hermes-attestation-guardian\n\nHermes-only attestation, advisory verification, and guarded verification workflow.\n\nStatus: implemented (v0.1.0), Hermes-only.\n\n## Capabilities\n\nThis skill now covers the full Hermes-side capability set expected from the clawsec-suite parity workstream:\n\n- Deterministic runtime posture attestation generation.\n- Fail-closed attestation verification (schema + canonical digest).\n- Optional detached signature verification for attestation artifacts.\n- Authenticated baseline diffing with stable severity classification.\n- Scoped output-path enforcement under `$HERMES_HOME`.\n- Signed advisory feed verification (Ed25519) with optional checksum-manifest verification.\n- Fail-closed advisory verification state persistence under `$HERMES_HOME/security/advisories`.\n- Advisory-aware guarded skill verification with explicit `--confirm-advisory` override.\n- Optional recurring scheduler helpers for attestation and advisory checks (print-only by default, explicit apply mode).\n- Sandboxed end-to-end regression harness for install + verify + advisory gates.\n\n## Quickstart\n\nCanonical release verification and trust-policy guidance lives in `SKILL.md`:\n- `Mandatory release verification gate (before install)`\n- `Hermes guard trust policy note`\n\nAfter running that gate, use:\n\n```bash\nnode scripts/generate_attestation.mjs\nnode scripts/verify_attestation.mjs --input ~/.hermes/security/attestations/current.json\nnode scripts/refresh_advisory_feed.mjs\nnode scripts/check_advisories.mjs\nnode scripts/guarded_skill_verify.mjs --skill some-skill --version 1.2.3\nnode scripts/setup_attestation_cron.mjs --every 6h --print-only\nnode scripts/setup_advisory_check_cron.mjs --every 6h --skill some-skill --print-only\n```\n\nScheduler safety warning: never leave `--allow-unsigned` enabled in recurring advisory check jobs except during short emergency recovery windows.\n\n## Runtime requirements\n\nRequired:\n- `node`\n\nOptional tooling (for local verification workflows):\n- `openssl`, `bash`, `docker`\n\n## Tests\n\n```bash\nnode test/attestation_schema.test.mjs\nnode test/attestation_diff.test.mjs\nnode test/attestation_cli.test.mjs\nnode test/setup_attestation_cron.test.mjs\nnode test/setup_advisory_check_cron.test.mjs\nnode test/feed_verification.test.mjs\nnode test/guarded_skill_verify.test.mjs\nbash test/hermes_attestation_sandbox_regression.sh\n```\n\nFile v0.1.0:_meta.json\n\n{\n  \"ownerId\": \"kn76m78f01hqrtpgm895s0jsax80jd8v\",\n  \"slug\": \"hermes-attestation-guardian\",\n  \"version\": \"0.1.0\",\n  \"publishedAt\": 1776769207586\n}\n\nFile v0.1.0:CHANGELOG.md\n\n# Changelog\n\n## [0.1.0] - 2026-04-21\n\n- Added mandatory release verification gate guidance before install: `checksums.json`, `checksums.sig`, and pinned signing public-key fingerprint.\n- Added explicit Hermes guard trust-policy note for signature-aware trust (trusted signer fingerprint allowlist) over source-name-only trust.\n- Moved sandbox regression harness into the skill test surface (`test/hermes_attestation_sandbox_regression.sh`) and fixed in-skill default path resolution.\n- Tightened advisory feed verification to require checksum-manifest artifacts when checksum-manifest verification is enabled (fail-closed when missing).\n- Added feed regression coverage for missing local/remote checksum-manifest artifacts under strict verification mode.\n- Refactored cron setup scripts to share managed-block helpers from `lib/cron.mjs`, reducing drift risk.\n- Added explicit `.mjs` scan/test coverage guidance so Hermes-side scanner scope and regression harness context stay aligned with `scripts/*.mjs`, `lib/*.mjs`, and `test/*.test.mjs`.\n- Clarified fresh-node first-run edge-case documentation.\n- Clarified Hermes runtime metadata/frontmatter and README capability coverage for ClawHub publishing.\n- Removed compatibility-report wiki page references in favor of README capability matrix as the primary compatibility surface.\n- Updated skill metadata/docs to v0.1.0 and aligned README quickstart with fail-closed verification expectations.\n\n## [0.0.1] - 2026-04-15\n\n- Implemented deterministic Hermes attestation generator CLI (`scripts/generate_attestation.mjs`).\n- Implemented fail-closed verifier CLI with schema, canonical digest, expected checksum, and optional detached signature checks (`scripts/verify_attestation.mjs`).\n- Implemented meaningful baseline diff engine with stable severity mapping for risky toggle regressions, feed verification regressions, trust anchor drift, and watched file drift (`lib/diff.mjs`).\n- Implemented Hermes-only cron setup helper with print-only default and managed-block apply mode (`scripts/setup_attestation_cron.mjs`).\n- Added shared attestation library for canonicalization, schema validation, digest generation, and policy parsing (`lib/attestation.mjs`).\n- Expanded tests for schema determinism, diff behavior, generator/verifier fail-closed behavior, and cron helper Hermes-only output.\n- Updated metadata/docs to match actual implemented behavior and ClawSec release pipeline expectations.\n\nFile v0.1.0:skill.json\n\n{\n  \"name\": \"hermes-attestation-guardian\",\n  \"version\": \"0.1.0\",\n  \"description\": \"Hermes-only runtime security attestation and drift detection skill. Generates deterministic posture artifacts, verifies integrity fail-closed, and classifies baseline drift severity.\",\n  \"author\": \"prompt-security\",\n  \"license\": \"AGPL-3.0-or-later\",\n  \"homepage\": \"https://clawsec.prompt.security/\",\n  \"platform\": \"hermes\",\n  \"keywords\": [\n    \"security\",\n    \"hermes\",\n    \"attestation\",\n    \"integrity\",\n    \"drift-detection\",\n    \"posture\"\n  ],\n  \"sbom\": {\n    \"files\": [\n      {\n        \"path\": \"SKILL.md\",\n        \"required\": true,\n        \"description\": \"Skill documentation and operator playbook\"\n      },\n      {\n        \"path\": \"CHANGELOG.md\",\n        \"required\": true,\n        \"description\": \"Version history and release notes\"\n      },\n      {\n        \"path\": \"README.md\",\n        \"required\": true,\n        \"description\": \"Human-oriented overview and quickstart\"\n      },\n      {\n        \"path\": \"lib/attestation.mjs\",\n        \"required\": true,\n        \"description\": \"Attestation schema, canonicalization, digest and validation helpers\"\n      },\n      {\n        \"path\": \"lib/diff.mjs\",\n        \"required\": true,\n        \"description\": \"Baseline comparison and severity classification\"\n      },\n      {\n        \"path\": \"lib/feed.mjs\",\n        \"required\": true,\n        \"description\": \"Hermes-native advisory feed verification and state helpers\"\n      },\n      {\n        \"path\": \"scripts/generate_attestation.mjs\",\n        \"required\": true,\n        \"description\": \"Generate deterministic Hermes posture attestation artifact\"\n      },\n      {\n        \"path\": \"scripts/verify_attestation.mjs\",\n        \"required\": true,\n        \"description\": \"Verify attestation schema, digest and optional detached signature\"\n      },\n      {\n        \"path\": \"scripts/refresh_advisory_feed.mjs\",\n        \"required\": true,\n        \"description\": \"Fetch, verify, and persist Hermes advisory feed verification state\"\n      },\n      {\n        \"path\": \"scripts/check_advisories.mjs\",\n        \"required\": true,\n        \"description\": \"Display human-readable advisory verification/feed summary\"\n      },\n      {\n        \"path\": \"scripts/guarded_skill_verify.mjs\",\n        \"required\": true,\n        \"description\": \"Advisory-aware guarded skill verification gate with explicit confirmation override\"\n      },\n      {\n        \"path\": \"scripts/setup_attestation_cron.mjs\",\n        \"required\": true,\n        \"description\": \"Optional recurring schedule setup for Hermes attestation runs\"\n      },\n      {\n        \"path\": \"scripts/setup_advisory_check_cron.mjs\",\n        \"required\": true,\n        \"description\": \"Optional recurring schedule setup for Hermes guarded advisory checks\"\n      },\n      {\n        \"path\": \"test/attestation_schema.test.mjs\",\n        \"required\": false,\n        \"description\": \"Schema and determinism tests\"\n      },\n      {\n        \"path\": \"test/attestation_diff.test.mjs\",\n        \"required\": false,\n        \"description\": \"Diff and severity mapping tests\"\n      },\n      {\n        \"path\": \"test/attestation_cli.test.mjs\",\n        \"required\": false,\n        \"description\": \"Generator/verifier CLI behavior tests\"\n      },\n      {\n        \"path\": \"test/setup_attestation_cron.test.mjs\",\n        \"required\": false,\n        \"description\": \"Hermes-only cron setup tests\"\n      },\n      {\n        \"path\": \"test/setup_advisory_check_cron.test.mjs\",\n        \"required\": false,\n        \"description\": \"Hermes-only guarded advisory cron setup tests\"\n      },\n      {\n        \"path\": \"test/feed_verification.test.mjs\",\n        \"required\": false,\n        \"description\": \"Advisory feed signature/checksum verification behavior tests\"\n      },\n      {\n        \"path\": \"test/guarded_skill_verify.test.mjs\",\n        \"required\": false,\n        \"description\": \"Advisory-aware guarded verification gate behavior tests\"\n      },\n      {\n        \"path\": \"test/hermes_attestation_sandbox_regression.sh\",\n        \"required\": false,\n        \"description\": \"Sandboxed end-to-end regression harness for install and verification paths\"\n      }\n    ]\n  },\n  \"hermes\": {\n    \"emoji\": \"🛡️\",\n    \"category\": \"security\",\n    \"requires\": {\n      \"bins\": [\n        \"node\"\n      ]\n    },\n    \"runtime\": {\n      \"required_env\": [],\n      \"optional_env\": [\n        \"HERMES_HOME\",\n        \"HERMES_ATTESTATION_OUTPUT_DIR\",\n        \"HERMES_ATTESTATION_BASELINE\",\n        \"HERMES_ATTESTATION_INTERVAL\",\n        \"HERMES_ATTESTATION_FAIL_ON_SEVERITY\",\n        \"HERMES_ATTESTATION_POLICY\",\n        \"HERMES_ADVISORY_FEED_SOURCE\",\n        \"HERMES_ADVISORY_FEED_URL\",\n        \"HERMES_ADVISORY_FEED_SIG_URL\",\n        \"HERMES_ADVISORY_FEED_CHECKSUMS_URL\",\n        \"HERMES_ADVISORY_FEED_CHECKSUMS_SIG_URL\",\n        \"HERMES_LOCAL_ADVISORY_FEED\",\n        \"HERMES_LOCAL_ADVISORY_FEED_SIG\",\n        \"HERMES_LOCAL_ADVISORY_FEED_CHECKSUMS\",\n        \"HERMES_LOCAL_ADVISORY_FEED_CHECKSUMS_SIG\",\n        \"HERMES_ADVISORY_FEED_PUBLIC_KEY\",\n        \"HERMES_ADVISORY_ALLOW_UNSIGNED_FEED\",\n        \"HERMES_ADVISORY_VERIFY_CHECKSUM_MANIFEST\",\n        \"HERMES_ADVISORY_FEED_STATE_PATH\",\n        \"HERMES_ADVISORY_CACHED_FEED\"\n      ]\n    },\n    \"execution\": {\n      \"always\": false,\n      \"persistence\": \"Runs on demand by default. Optional scheduler helper can install a managed schedule block when run with --apply.\",\n      \"network_egress\": \"Optional HTTPS advisory feed fetch via refresh_advisory_feed.mjs; no network required for local-mode verification\"\n    },\n    \"operator_review\": [\n      \"Hermes-only skill: unsupported for OpenClaw runtime hooks.\",\n      \"Verify watch/trust-anchor policy paths before scheduling recurring runs.\",\n      \"Verification fails closed for schema/digest/signature errors and unauthenticated baseline inputs; diff threshold defaults to critical.\",\n      \"Advisory feed verification is fail-closed by default; unsigned bypass must remain temporary and operator-audited.\"\n    ],\n    \"triggers\": [\n      \"generate hermes attestation\",\n      \"verify hermes attestation\",\n      \"hermes runtime drift detection\",\n      \"hermes trust anchor drift\",\n      \"refresh hermes advisory feed\",\n      \"check hermes advisories\",\n      \"guarded hermes skill verification\",\n      \"setup hermes attestation cron\",\n      \"setup hermes advisory check cron\"\n    ]\n  }\n}\n\nArchive v0.0.1: 14 files, 26157 bytes\n\nFiles: CHANGELOG.md (1011b), lib/attestation.mjs (14844b), lib/diff.mjs (7725b), README.md (1477b), scripts/generate_attestation.mjs (4670b), scripts/setup_attestation_cron.mjs (9839b), scripts/verify_attestation.mjs (11353b), skill.json (3651b), SKILL.md (3719b), test/attestation_cli.test.mjs (9087b), test/attestation_diff.test.mjs (2246b), test/attestation_schema.test.mjs (11851b), test/setup_attestation_cron.test.mjs (7587b), _meta.json (146b)\n\nFile v0.0.1:SKILL.md\n\n---\nname: hermes-attestation-guardian\nversion: 0.0.1\ndescription: Hermes-only runtime security attestation and drift detection skill for operator-managed Hermes infrastructure.\nhomepage: https://clawsec.prompt.security\nclawdis:\n  emoji: \"🛡️\"\n  requires:\n    bins: [node]\n---\n\n# Hermes Attestation Guardian\n\nIMPORTANT SCOPE:\n- This skill targets Hermes infrastructure only (CLI/Gateway/profile-managed deployments).\n- This skill is not an OpenClaw runtime hook package.\n\n## Goal\n\nGenerate deterministic Hermes posture attestations, verify them with fail-closed integrity checks, and compare baseline drift using stable severity mapping.\n\n## Commands\n\n```bash\n# Generate attestation (default output: ~/.hermes/security/attestations/current.json)\nnode scripts/generate_attestation.mjs\n\n# Generate with explicit policy + deterministic timestamp\nnode scripts/generate_attestation.mjs \\\n  --policy ~/.hermes/security/attestation-policy.json \\\n  --generated-at 2026-04-15T18:00:00.000Z \\\n  --write-sha256\n\n# Verify schema + canonical digest\nnode scripts/verify_attestation.mjs --input ~/.hermes/security/attestations/current.json\n\n# Verify with baseline diff (baseline must be authenticated)\nnode scripts/verify_attestation.mjs \\\n  --input ~/.hermes/security/attestations/current.json \\\n  --baseline ~/.hermes/security/attestations/baseline.json \\\n  --baseline-expected-sha256 <trusted-baseline-sha256> \\\n  --fail-on-severity high\n\n# Optional detached signature verification\nnode scripts/verify_attestation.mjs \\\n  --input ~/.hermes/security/attestations/current.json \\\n  --signature ~/.hermes/security/attestations/current.json.sig \\\n  --public-key ~/.hermes/security/keys/attestation-public.pem\n\n# Preview scheduler config without mutating user schedule state\nnode scripts/setup_attestation_cron.mjs --every 6h --print-only\n\n# Apply managed scheduler block\nnode scripts/setup_attestation_cron.mjs --every 6h --apply\n```\n\n## Attestation payload (implemented)\n\nThe generator emits:\n- schema_version, platform, generated_at\n- generator metadata (skill + node version)\n- host metadata (hostname/platform/arch)\n- posture.runtime (gateway enabled flags + risky toggles)\n- posture.feed_verification status (verified|unverified|unknown)\n- posture.integrity watched_files and trust_anchors (existence + sha256)\n- digests.canonical_sha256 over a stable canonical JSON representation\n\n## Fail-closed behavior\n\nVerifier exits non-zero when:\n- schema validation fails\n- canonical digest algorithm is unsupported or digest binding mismatches\n- expected file sha256 mismatches (if configured)\n- detached signature verification fails (if configured)\n- baseline is provided without authenticated trust binding (`--baseline-expected-sha256` and/or baseline signature + public key)\n- baseline authenticity or baseline schema/digest validation fails\n- baseline diff highest severity is at/above `--fail-on-severity` (default: critical)\n\nSeverity messages are emitted as INFO / WARNING / CRITICAL style lines.\n\n## Side effects\n\n- `generate_attestation.mjs` writes one JSON file (and optional `.sha256`) under `$HERMES_HOME/security/attestations`.\n- `verify_attestation.mjs` is read-only.\n- `setup_attestation_cron.mjs` is read-only unless `--apply` is provided.\n- `setup_attestation_cron.mjs --apply` rewrites only the current user managed schedule block delimited by:\n  - `# >>> hermes-attestation-guardian >>>`\n  - `# <<< hermes-attestation-guardian <<<`\n\n## Notes\n\n- Default output root is `~/.hermes/security/attestations/`.\n- No destructive remediation actions (delete/restore/quarantine) are implemented.\n- Operator policy file is optional JSON with:\n  - `watch_files`: list of file paths\n  - `trust_anchor_files`: list of file paths\n\nFile v0.0.1:README.md\n\n# hermes-attestation-guardian\n\nHermes-only security attestation and drift detection skill.\n\nStatus: implemented (v0.0.1), Hermes-only.\n\n## What it does\n\n- Generates deterministic Hermes runtime posture attestations.\n- Verifies attestation schema + canonical digest with fail-closed semantics.\n- Optionally verifies detached signatures using a provided public key.\n- Fails closed on baseline diffing unless baseline authenticity is verified (trusted digest and/or detached signature).\n- Restricts attestation output writes to Hermes attestation scope (`$HERMES_HOME/security/attestations`).\n- Compares baseline vs current attestations with stable severity classification.\n- Provides an optional Hermes-oriented cron setup helper (print-only by default).\n\n## Scope boundaries\n\nIn scope:\n- Hermes environment posture snapshots\n- deterministic baseline diffing\n- fail-closed verification semantics\n- Hermes optional scheduling helper\n\nOut of scope / unsupported (v0.0.1):\n- OpenClaw runtime hooks (unsupported)\n- destructive auto-remediation\n- automatic rollback of runtime configuration\n\n## Quickstart\n\n```bash\nnode scripts/generate_attestation.mjs\nnode scripts/verify_attestation.mjs --input ~/.hermes/security/attestations/current.json\nnode scripts/setup_attestation_cron.mjs --every 6h --print-only\n```\n\n## Tests\n\n```bash\nnode test/attestation_schema.test.mjs\nnode test/attestation_diff.test.mjs\nnode test/attestation_cli.test.mjs\nnode test/setup_attestation_cron.test.mjs\n```\n\nFile v0.0.1:_meta.json\n\n{\n  \"ownerId\": \"kn76m78f01hqrtpgm895s0jsax80jd8v\",\n  \"slug\": \"hermes-attestation-guardian\",\n  \"version\": \"0.0.1\",\n  \"publishedAt\": 1776351852235\n}\n\nFile v0.0.1:CHANGELOG.md\n\n# Changelog\n\n## [0.0.1] - 2026-04-15\n\n- Implemented deterministic Hermes attestation generator CLI (`scripts/generate_attestation.mjs`).\n- Implemented fail-closed verifier CLI with schema, canonical digest, expected checksum, and optional detached signature checks (`scripts/verify_attestation.mjs`).\n- Implemented meaningful baseline diff engine with stable severity mapping for risky toggle regressions, feed verification regressions, trust anchor drift, and watched file drift (`lib/diff.mjs`).\n- Implemented Hermes-only cron setup helper with print-only default and managed-block apply mode (`scripts/setup_attestation_cron.mjs`).\n- Added shared attestation library for canonicalization, schema validation, digest generation, and policy parsing (`lib/attestation.mjs`).\n- Expanded tests for schema determinism, diff behavior, generator/verifier fail-closed behavior, and cron helper Hermes-only output.\n- Updated metadata/docs to match actual implemented behavior and ClawSec release pipeline expectations.\n\nFile v0.0.1:skill.json\n\n{\n  \"name\": \"hermes-attestation-guardian\",\n  \"version\": \"0.0.1\",\n  \"description\": \"Hermes-only runtime security attestation and drift detection skill. Generates deterministic posture artifacts, verifies integrity fail-closed, and classifies baseline drift severity.\",\n  \"author\": \"prompt-security\",\n  \"license\": \"AGPL-3.0-or-later\",\n  \"homepage\": \"https://clawsec.prompt.security/\",\n  \"platform\": \"hermes\",\n  \"keywords\": [\n    \"security\",\n    \"hermes\",\n    \"attestation\",\n    \"integrity\",\n    \"drift-detection\",\n    \"posture\"\n  ],\n  \"sbom\": {\n    \"files\": [\n      {\n        \"path\": \"SKILL.md\",\n        \"required\": true,\n        \"description\": \"Skill documentation and operator playbook\"\n      },\n      {\n        \"path\": \"CHANGELOG.md\",\n        \"required\": true,\n        \"description\": \"Version history and release notes\"\n      },\n      {\n        \"path\": \"README.md\",\n        \"required\": true,\n        \"description\": \"Human-oriented overview and quickstart\"\n      },\n      {\n        \"path\": \"lib/attestation.mjs\",\n        \"required\": true,\n        \"description\": \"Attestation schema, canonicalization, digest and validation helpers\"\n      },\n      {\n        \"path\": \"lib/diff.mjs\",\n        \"required\": true,\n        \"description\": \"Baseline comparison and severity classification\"\n      },\n      {\n        \"path\": \"scripts/generate_attestation.mjs\",\n        \"required\": true,\n        \"description\": \"Generate deterministic Hermes posture attestation artifact\"\n      },\n      {\n        \"path\": \"scripts/verify_attestation.mjs\",\n        \"required\": true,\n        \"description\": \"Verify attestation schema, digest and optional detached signature\"\n      },\n      {\n        \"path\": \"scripts/setup_attestation_cron.mjs\",\n        \"required\": true,\n        \"description\": \"Optional recurring schedule setup for Hermes attestation runs\"\n      },\n      {\n        \"path\": \"test/attestation_schema.test.mjs\",\n        \"required\": false,\n        \"description\": \"Schema and determinism tests\"\n      },\n      {\n        \"path\": \"test/attestation_diff.test.mjs\",\n        \"required\": false,\n        \"description\": \"Diff and severity mapping tests\"\n      },\n      {\n        \"path\": \"test/attestation_cli.test.mjs\",\n        \"required\": false,\n        \"description\": \"Generator/verifier CLI behavior tests\"\n      },\n      {\n        \"path\": \"test/setup_attestation_cron.test.mjs\",\n        \"required\": false,\n        \"description\": \"Hermes-only cron setup tests\"\n      }\n    ]\n  },\n  \"hermes\": {\n    \"emoji\": \"🛡️\",\n    \"category\": \"security\",\n    \"requires\": {\n      \"bins\": [\n        \"node\"\n      ]\n    },\n    \"runtime\": {\n      \"required_env\": [],\n      \"optional_env\": [\n        \"HERMES_HOME\",\n        \"HERMES_ATTESTATION_OUTPUT_DIR\",\n        \"HERMES_ATTESTATION_BASELINE\",\n        \"HERMES_ATTESTATION_INTERVAL\",\n        \"HERMES_ATTESTATION_FAIL_ON_SEVERITY\",\n        \"HERMES_ATTESTATION_POLICY\"\n      ]\n    },\n    \"execution\": {\n      \"always\": false,\n      \"persistence\": \"Runs on demand by default. Optional scheduler helper can install a managed schedule block when run with --apply.\",\n      \"network_egress\": \"None\"\n    },\n    \"operator_review\": [\n      \"Hermes-only skill: unsupported for OpenClaw runtime hooks.\",\n      \"Verify watch/trust-anchor policy paths before scheduling recurring runs.\",\n      \"Verification fails closed for schema/digest/signature errors and unauthenticated baseline inputs; diff threshold defaults to critical.\"\n    ],\n    \"triggers\": [\n      \"generate hermes attestation\",\n      \"verify hermes attestation\",\n      \"hermes runtime drift detection\",\n      \"hermes trust anchor drift\",\n      \"setup hermes attestation cron\"\n    ]\n  }\n}","readmeExcerpt":"Skill: hermes-attestation-guardian Owner: davida-ps Summary: Hermes-only runtime security attestation and drift detection skill for operator-managed Hermes infrastructure. Tags: latest:0.1.3 Version history: v0.1.3 | 2026-05-24T18:48:08.071Z | user Release 0.1.3 via CI v0.1.2 | 2026-05-16T21:44:23.135Z | user Release 0.1.2 via CI v0.1.1 | 2026-05-14T11:43:07.920Z | user Release 0.1.1 via CI v0.1.0 | 2026-04-21T11:00:","codeSnippets":[],"executableExamples":[{"language":"bash","snippet":"curl -fsSL \"$BASE/checksums.json\" -o \"$TMP_DIR/checksums.json\""},{"language":"bash","snippet":"curl -fsSL \"$BASE/checksums.sig\" -o \"$TMP_DIR/checksums.sig\""},{"language":"bash","snippet":"curl -fsSL \"$BASE/signing-public.pem\" -o \"$TMP_DIR/signing-public.pem\""},{"language":"bash","snippet":"curl -fsSL \"$BASE/$ZIP_NAME\" -o \"$TMP_DIR/$ZIP_NAME\""},{"language":"bash","snippet":"curl -fsSL \"$BASE/SKILL.md\" -o \"$TMP_DIR/SKILL.md\""},{"language":"bash","snippet":"curl -fsSL \"$BASE/skill.json\" -o \"$TMP_DIR/skill.json\""}],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[{"path":"SKILL.md","content":"---\nname: hermes-attestation-guardian\nversion: 0.1.3\ndescription: Hermes-only runtime security attestation and drift detection skill for operator-managed Hermes infrastructure.\nhomepage: https://clawsec.prompt.security\nhermes:\n  emoji: \"🛡️\"\n  requires:\n    bins: [node]\n---\n\n# Hermes Attestation Guardian\n\nIMPORTANT SCOPE:\n- This skill targets Hermes infrastructure only (CLI/Gateway/profile-managed deployments).\n- This skill is not an OpenClaw runtime hook package.\n\n\n## Release Artifact Verification\n\nFor standalone installs, verify the signed release manifest before trusting `SKILL.md`, `skill.json`, or the archive. The `skill.json` file is the package metadata/SBOM source, and the release pipeline signs `checksums.json` with the ClawSec release key.\n\n```bash\nset -euo pipefail\n\nSKILL_NAME=\"hermes-attestation-guardian\"\nVERSION=\"0.1.3\"\nREPO=\"prompt-security/clawsec\"\nTAG=\"${SKILL_NAME}-v${VERSION}\"\nBASE=\"https://github.com/${REPO}/releases/download/${TAG}\"\nZIP_NAME=\"${SKILL_NAME}-v${VERSION}.zip\"\nTMP_DIR=\"$(mktemp -d)\"\ntrap 'rm -rf \"$TMP_DIR\"' EXIT\n\nRELEASE_PUBKEY_SHA256=\"711424e4535f84093fefb024cd1ca4ec87439e53907b305b79a631d5befba9c8\"\n\ncurl -fsSL \"$BASE/checksums.json\" -o \"$TMP_DIR/checksums.json\"\ncurl -fsSL \"$BASE/checksums.sig\" -o \"$TMP_DIR/checksums.sig\"\ncurl -fsSL \"$BASE/signing-public.pem\" -o \"$TMP_DIR/signing-public.pem\"\ncurl -fsSL \"$BASE/$ZIP_NAME\" -o \"$TMP_DIR/$ZIP_NAME\"\ncurl -fsSL \"$BASE/SKILL.md\" -o \"$TMP_DIR/SKILL.md\"\ncurl -fsSL \"$BASE/skill.json\" -o \"$TMP_DIR/skill.json\"\n\nACTUAL_PUBKEY_SHA256=\"$(openssl pkey -pubin -in \"$TMP_DIR/signing-public.pem\" -outform DER | shasum -a 256 | awk '{print $1}')\"\nif [ \"$ACTUAL_PUBKEY_SHA256\" != \"$RELEASE_PUBKEY_SHA256\" ]; then\n  echo \"ERROR: signing-public.pem fingerprint mismatch\" >&2\n  exit 1\nfi\n\nopenssl base64 -d -A -in \"$TMP_DIR/checksums.sig\" -out \"$TMP_DIR/checksums.sig.bin\"\nopenssl pkeyutl -verify -rawin -pubin \\\n  -inkey \"$TMP_DIR/signing-public.pem\" \\\n  -sigfile \"$TMP_DIR/checksums.sig.bin\" \\\n  -in \"$TMP_DIR/checksums.json\" >/dev/null\n\nhash_file() {\n  if command -v shasum >/dev/null 2>&1; then\n    shasum -a 256 \"$1\" | awk '{print $1}'\n  else\n    sha256sum \"$1\" | awk '{print $1}'\n  fi\n}\n\nverify_manifest_file() {\n  asset=\"$1\"\n  path=\"$2\"\n  expected=\"$(jq -r --arg asset \"$asset\" '.files[$asset].sha256 // empty' \"$TMP_DIR/checksums.json\")\"\n  if [ -z \"$expected\" ]; then\n    echo \"ERROR: checksums.json missing $asset\" >&2\n    exit 1\n  fi\n  actual=\"$(hash_file \"$path\")\"\n  if [ \"$actual\" != \"$expected\" ]; then\n    echo \"ERROR: checksum mismatch for $asset\" >&2\n    exit 1\n  fi\n}\n\nexpected_archive=\"$(jq -r '.archive.sha256 // empty' \"$TMP_DIR/checksums.json\")\"\nif [ -z \"$expected_archive\" ]; then\n  echo \"ERROR: checksums.json missing archive.sha256\" >&2\n  exit 1\nfi\nactual_archive=\"$(hash_file \"$TMP_DIR/$ZIP_NAME\")\"\nif [ \"$actual_archive\" != \"$expected_archive\" ]; then\n  echo \"ERROR: archive checksum mismatch\" >&2\n  exit 1\nfi\n\nverify_manifest_file \"SKILL.md\" \"$TMP_DIR/SKILL.md\"\nverify_manifest_file \"skill"},{"path":"README.md","content":"# hermes-attestation-guardian\n\nHermes-only attestation, advisory verification, and guarded verification workflow.\n\nStatus: implemented (v0.1.0), Hermes-only.\n\n## Capabilities\n\nThis skill now covers the full Hermes-side capability set expected from the clawsec-suite parity workstream:\n\n- Deterministic runtime posture attestation generation.\n- Fail-closed attestation verification (schema + canonical digest).\n- Optional detached signature verification for attestation artifacts.\n- Authenticated baseline diffing with stable severity classification.\n- Scoped output-path enforcement under `$HERMES_HOME`.\n- Signed advisory feed verification (Ed25519) with optional checksum-manifest verification.\n- Fail-closed advisory verification state persistence under `$HERMES_HOME/security/advisories`.\n- Advisory-aware guarded skill verification with explicit `--confirm-advisory` override.\n- Optional recurring scheduler helpers for attestation and advisory checks (print-only by default, explicit apply mode).\n- Sandboxed end-to-end regression harness for install + verify + advisory gates.\n\n## Quickstart\n\nCanonical release verification and trust-policy guidance lives in `SKILL.md`:\n- `Mandatory release verification gate (before install)`\n- `Hermes guard trust policy note`\n\nAfter running that gate, use:\n\n```bash\nnode scripts/generate_attestation.mjs\nnode scripts/verify_attestation.mjs --input ~/.hermes/security/attestations/current.json\nnode scripts/refresh_advisory_feed.mjs\nnode scripts/check_advisories.mjs\nnode scripts/guarded_skill_verify.mjs --skill some-skill --version 1.2.3\nnode scripts/setup_attestation_cron.mjs --every 6h --print-only\nnode scripts/setup_advisory_check_cron.mjs --every 6h --skill some-skill --print-only\n```\n\nScheduler safety warning: never leave `--allow-unsigned` enabled in recurring advisory check jobs except during short emergency recovery windows.\n\n## Runtime requirements\n\nRequired:\n- `node`\n\nOptional tooling (for local verification workflows):\n- `openssl`, `bash`, `docker`\n\n## Tests\n\n```bash\nnode test/attestation_schema.test.mjs\nnode test/attestation_diff.test.mjs\nnode test/attestation_cli.test.mjs\nnode test/setup_attestation_cron.test.mjs\nnode test/setup_advisory_check_cron.test.mjs\nnode test/feed_verification.test.mjs\nnode test/guarded_skill_verify.test.mjs\nbash test/hermes_attestation_sandbox_regression.sh\n```"},{"path":"_meta.json","content":"{\n  \"ownerId\": \"kn76m78f01hqrtpgm895s0jsax80jd8v\",\n  \"slug\": \"hermes-attestation-guardian\",\n  \"version\": \"0.1.3\",\n  \"publishedAt\": 1779648488071\n}"},{"path":"CHANGELOG.md","content":"# Changelog\n\n## [0.1.3] - 2026-05-24\n\n### Changed\n- Documented that the default signed advisory feed is consolidated and may include NVD CVEs, approved community advisories, and provisional GHSA-without-CVE records while Hermes matching remains package-scoped.\n\n## [0.1.2] - 2026-05-15\n\n### Fixed\n- Included `lib/semver.mjs` and `lib/cron.mjs` in the release SBOM so signed archives contain every runtime library imported by shipped scripts.\n\n## [0.1.1] - 2026-05-13\n\n### Security\n- Added explicit signed release artifact verification instructions for standalone installs, including `checksums.json`, `checksums.sig`, `signing-public.pem`, archive hash verification, and `SKILL.md`/`skill.json` checksum checks.\n\n### Changed\n- Re-release skill payload metadata after excluding test-only files from release SBOMs and archives.\n\n## [0.1.0] - 2026-04-21\n\n- Added mandatory release verification gate guidance before install: `checksums.json`, `checksums.sig`, and pinned signing public-key fingerprint.\n- Added explicit Hermes guard trust-policy note for signature-aware trust (trusted signer fingerprint allowlist) over source-name-only trust.\n- Moved sandbox regression harness into the skill test surface (`test/hermes_attestation_sandbox_regression.sh`) and fixed in-skill default path resolution.\n- Tightened advisory feed verification to require checksum-manifest artifacts when checksum-manifest verification is enabled (fail-closed when missing).\n- Added feed regression coverage for missing local/remote checksum-manifest artifacts under strict verification mode.\n- Refactored cron setup scripts to share managed-block helpers from `lib/cron.mjs`, reducing drift risk.\n- Added explicit `.mjs` scan/test coverage guidance so Hermes-side scanner scope and regression harness context stay aligned with `scripts/*.mjs`, `lib/*.mjs`, and `test/*.test.mjs`.\n- Clarified fresh-node first-run edge-case documentation.\n- Clarified Hermes runtime metadata/frontmatter and README capability coverage for ClawHub publishing.\n- Removed compatibility-report wiki page references in favor of README capability matrix as the primary compatibility surface.\n- Updated skill metadata/docs to v0.1.0 and aligned README quickstart with fail-closed verification expectations.\n\n## [0.0.1] - 2026-04-15\n\n- Implemented deterministic Hermes attestation generator CLI (`scripts/generate_attestation.mjs`).\n- Implemented fail-closed verifier CLI with schema, canonical digest, expected checksum, and optional detached signature checks (`scripts/verify_attestation.mjs`).\n- Implemented meaningful baseline diff engine with stable severity mapping for risky toggle regressions, feed verification regressions, trust anchor drift, and watched file drift (`lib/diff.mjs`).\n- Implemented Hermes-only cron setup helper with print-only default and managed-block apply mode (`scripts/setup_attestation_cron.mjs`).\n- Added shared attestation library for canonicalization, schema validation, digest generation, and policy parsing (`li"},{"path":"skill-card.md","content":"## Description:\n\nHermes-only runtime security attestation and drift detection skill for operator-managed Hermes infrastructure.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[davida-ps](https://clawhub.ai/user/davida-ps)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and operators use this skill to generate deterministic Hermes posture attestations, verify attestation integrity fail-closed, compare authenticated baseline drift, and run advisory-aware guarded verification for Hermes-managed infrastructure.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Attestations may expose watched file paths, trust anchor paths, and hashes from Hermes security state.\n\nMitigation: Review watch_files and trust_anchor_files before use, protect ~/.hermes, and limit access to generated attestation artifacts.\n\nRisk: Recurring scheduler setup can mutate the current user's cron state when --apply is used.\n\nMitigation: Preview scheduler entries with --print-only, avoid running scheduled jobs as root, and apply only the managed Hermes schedule blocks intentionally.\n\nRisk: Unsigned advisory feed bypass weakens fail-closed verification.\n\nMitigation: Use --allow-unsigned only during a short audited emergency window and remove it immediately after recovery.\n\nRisk: Using the skill outside Hermes infrastructure can produce unsupported trust and attestation assumptions.\n\nMitigation: Install and operate the skill only for Hermes CLI, Gateway, or profile-managed deployments.\n\n## Reference(s):\n\n- [ClawSec Homepage](https://clawsec.prompt.security)\n- [ClawHub Skill Page](https://clawhub.ai/davida-ps/skills/hermes-attestation-guardian)\n- [Skill Operator Playbook](artifact/SKILL.md)\n- [Capability Overview](artifact/README.md)\n- [Release Changelog](artifact/CHANGELOG.md)\n\n## Skill Output:\n\n**Output Type(s):** [text, markdown, code, shell commands, configuration, guidance]\n\n**Output Format:** [Markdown guidance with shell commands and JSON configuration artifacts]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Produces Hermes attestation JSON files, optional sha256 sidecar files, advisory feed verification state, and optional managed cron entries when explicitly applied.]\n\n## Skill Version(s):\n\n0.1.3 (source: frontmatter, changelog, server release evidence; released 2026-05-24)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment."}],"languages":[],"docsSourceLabel":"CLAWHUB","editorialOverview":"Hermes-only runtime security attestation and drift detection skill for operator-managed Hermes infrastructure. Skill: hermes-attestation-guardian Owner: davida-ps Summary: Hermes-only runtime security attestation and drift detection skill for operator-managed Hermes infrastructure. Tags: latest:0.1.3 Version history: v0.1.3 | 2026-05-24T18:48:08.071Z | user Release 0.1.3 via CI v0.1.2 | 2026-05-16T21:44:23.135Z | user Release 0.1.2 via CI v0.1.1 | 2026-05-14T11:43:07.920Z | user Release 0.1.1 via CI v0.1.0 | 2026-04-21T11:00:","editorialQuality":{"score":100,"threshold":65,"status":"ready","wordCount":1334,"uniquenessScore":46,"reasons":[]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-10-10T22:09:15.455Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-10-10T22:09:15.455Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-11T00:33:21.942Z","emptyReason":null},"items":[{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-10-09T19:11:12.944Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}