Skip to content

[codex] Add Hermes MCP guard#5

Merged
RedBeret merged 1 commit into
mainfrom
codex/hermes-mcp-guard
Apr 29, 2026
Merged

[codex] Add Hermes MCP guard#5
RedBeret merged 1 commit into
mainfrom
codex/hermes-mcp-guard

Conversation

@RedBeret
Copy link
Copy Markdown
Owner

Summary

  • add components/hermes/hermes-mcp-guard, an offline scanner for Hermes mcp_servers: config
  • flag literal credentials, insecure HTTP endpoints, unallowlisted remote hosts, broad tool exposure, unpinned stdio launchers, and unconstrained sampling
  • add installer, component docs, and smoke-test coverage
  • include the component in isolated setup testing and public docs

Validation

  • bash scripts/smoke-test.sh
  • bash scripts/test-components-isolated.sh -> 28 ok, 0 skipped, 0 failed
  • bash components/hermes/hermes-mcp-guard/mcp-guard.sh ~/.hermes/config.yaml -> no mcp_servers block found, exit 0
  • bash scripts/publish-check.sh -> passed with existing advisory warnings for historical author review and missing local dependency audit tool

@RedBeret RedBeret merged commit 112ab0b into main Apr 29, 2026
3 checks passed
@RedBeret RedBeret deleted the codex/hermes-mcp-guard branch April 29, 2026 02:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant