
Hermes Traffic Guardian
FreeMonitor and secure your Hermes runtime traffic.
Free · Opens the source repo
What Hermes Traffic Guardian does
Hermes Traffic Guardian is designed to establish a baseline for traffic monitoring within the Hermes runtime environment. This skill focuses on enabling opt-in proxy inspection, egress detection, and attestation-aware traffic posture without shipping a proxy or runtime implementation at this stage. It provides a structured approach for builders to implement runtime traffic monitoring capabilities, ensuring that they can effectively manage traffic while adhering to security best practices.
The skill allows for operator-scoped HTTP proxy inspection and optional HTTPS inspection, contingent on the operator providing per-process CA trust configurations. It emphasizes outbound exfiltration and inbound injection detection, while also allowing for the generation of redacted local threat logs. This ensures that sensitive information is protected while still providing valuable insights into traffic behavior. Additionally, it supports status export for integration with the hermes-attestation-guardian, allowing for seamless attestation and monitoring.
Safety is a key consideration for Hermes Traffic Guardian. The skill operates on an opt-in basis, meaning that users have full control over what gets monitored. By default, it detects and logs traffic without making any automatic changes to the system's CA or proxy settings. This approach minimizes risks associated with unintentional exposure or disruption of services. The skill also ensures that all sensitive data is redacted before being logged or exported, maintaining the confidentiality of the information being processed.
Developers and security engineers looking to enhance their traffic monitoring capabilities within the Hermes environment will find this skill particularly useful. It serves as a foundational tool for building a secure traffic posture and can be tailored to meet specific operational needs as implementations evolve over time.
When to use it
Use Hermes Traffic Guardian when you need to implement traffic monitoring and inspection for the Hermes runtime while maintaining strict security protocols.
When not to use it
This skill may not be suitable if you require a fully operational proxy or runtime implementation out of the box, as it currently provides only a baseline specification.
What you can build with it
Integrating Traffic Monitoring
Use Hermes Traffic Guardian to set up traffic monitoring for your Hermes applications, ensuring secure and compliant data handling.
Detecting Egress Threats
Implement the skill to identify potential egress threats in your network traffic, allowing for timely responses to security incidents.
Attestation Integration
Utilize the skill's posture export capabilities to integrate with `hermes-attestation-guardian`, enhancing your overall security posture.
How to install Hermes Traffic Guardian
View source1. Install with the skills CLI
npx skills add prompt-security/clawsec/hermes-traffic-guardian --agent claude-code2. Or install it manually
Download the skill folder and drop it into ~/.claude/skills/ for all projects, or .claude/skills/ to scope it to one repo. Restart Claude Code so it picks up the new skill.
Anthropic's agentic coding CLI, and the reference implementation of Agent Skills. Drop a skill folder into ~/.claude/skills and Claude Code loads it automatically whenever a task matches the skill's description. Claude Code docs
Inside SKILL.md
Written by prompt-securityHermes Traffic Guardian
This is a baseline specification skill. It intentionally does not ship a proxy or runtime implementation yet.
Vercel Skills Installation
Install with the Vercel Skills CLI for this harness:
npx skills add prompt-security/clawsec --skill hermes-traffic-guardian -a hermes-agent -y
Release Artifact Verification
For standalone installs, verify the signed release manifest before trusting SKILL.md, skill.json, or the archive. The skill.json file is the package metadata/SBOM source, and the release pipeline signs checksums.json with the ClawSec release key.
set -euo pipefail
SKILL_NAME="hermes-traffic-guardian"
VERSION="0.0.1-beta5"
REPO="prompt-security/clawsec"
TAG="${SKILL_NAME}-v${VERSION}"
BASE="https://github.com/${REPO}/releases/download/${TAG}"
ZIP_NAME="${SKILL_NAME}-v${VERSION}.zip"
TMP_DIR="$(mktemp -d)"
trap 'rm -rf "$TMP_DIR"' EXIT
RELEASE_PUBKEY_SHA256="711424e4535f84093fefb024cd1ca4ec87439e53907b305b79a631d5befba9c8"
curl -fsSL "$BASE/checksums.json" -o "$TMP_DIR/checksums.json"
curl -fsSL "$BASE/checksums.sig" -o "$TMP_DIR/checksums.sig"
curl -fsSL "$BASE/signing-public.pem" -o "$TMP_DIR/signing-public.pem"
curl -fsSL "$BASE/$ZIP_NAME" -o "$TMP_DIR/$ZIP_NAME"
curl -fsSL "$BASE/SKILL.md" -o "$TMP_DIR/SKILL.md"
curl -fsSL "$BASE/skill.json" -o "$TMP_DIR/skill.json"
ACTUAL_PUBKEY_SHA256="$(openssl pkey -pubin -in "$TMP_DIR/signing-public.pem" -outform DER | shasum -a 256 | awk '{print $1}')"
if [ "$ACTUAL_PUBKEY_SHA256" != "$RELEASE_PUBKEY_SHA256" ]; then
echo "ERROR: signing-public.pem fingerprint mismatch" >&2
exit 1
fi
openssl base64 -d -A -in "$TMP_DIR/checksums.sig" -out "$TMP_DIR/checksums.sig.bin"
openssl pkeyutl -verify -rawin -pubin \
-inkey "$TMP_DIR/signing-public.pem" \
-sigfile "$TMP_DIR/checksums.sig.bin" \
-in "$TMP_DIR/checksums.json" >/dev/null
hash_file() {
if command -v shasum >/dev/null 2>&1; then
shasum -a 256 "$1" | awk '{print $1}'
else
sha256sum "$1" | awk '{print $1}'
fi
}
verify_manifest_file() {
asset="$1"
path="$2"
expected="$(jq -r --arg asset "$asset" '.files[$asset].sha256 // empty' "$TMP_DIR/checksums.json")"
if [ -z "$expected" ]; then
echo "ERROR: checksums.json missing $asset" >&2
exit 1
fi
actual="$(hash_file "$path")"
if [ "$actual" != "$expected" ]; then
echo "ERROR: checksum mismatch for $asset" >&2
exit 1
fi
}
expected_archive="$(jq -r '.archive.sha256 // empty' "$TMP_DIR/checksums.json")"
if [ -z "$expected_archive" ]; then
echo "ERROR: checksums.json missing archive.sha256" >&2
exit 1
fi
actual_archive="$(hash_file "$TMP_DIR/$ZIP_NAME")"
if [ "$actual_archive" != "$expected_archive" ]; then
echo "ERROR: archive checksum mismatch" >&2
exit 1
fi
verify_manifest_file "SKILL.md" "$TMP_DIR/SKILL.md"
verify_manifest_file "skill.json" "$TMP_DIR/skill.json"
echo "Signed release manifest, archive, SKILL.md, and skill.json verified."
Only install or extract the archive after this verification succeeds.
Scope
Builders should use this skill as the Hermes landing zone for runtime traffic monitoring:
- operator-scoped HTTP proxy inspection
- optional HTTPS inspection with per-process CA trust
- outbound exfiltration detection
- inbound injection detection
- redacted local threat logs
- status export for
hermes-attestation-guardian
Do not add proxy runtime ownership to hermes-attestation-guardian. That skill should attest this monitor's status and configuration, not run it.
Safety Contract
- Opt-in only.
- Detect-and-log by default.
- No automatic system CA installation.
- No global proxy environment changes.
- No blocking in the first implementation.
- Redact secrets before logs, summaries, or attestation-linked outputs.
- Keep all state under
HERMES_TRAFFIC_GUARDIAN_HOMEor$HERMES_HOME/security/traffic-guardian.
Builder Entry Points
Read SPEC.md before implementing. Use the placeholder folders as follows:
| Path | Intended use |
|---|---|
lib/ | Detector rules, redaction, posture export, report formatting |
scripts/ | Start, stop, status, config validation, log query, attestation export helpers |
test/ | Unit tests, proxy fixture tests, redaction tests, attestation export tests |
Required First Implementation Behavior
- Validate config without starting the proxy.
- Start monitor in foreground or explicit background mode.
- Scope proxy environment variables to the target Hermes service or CLI process.
- Inspect HTTP request/response text up to a bounded byte limit.
- Support optional HTTPS MITM only when the operator supplies per-process trust configuration.
- Emit JSONL findings with redacted snippets.
- Export a small posture JSON file that
hermes-attestation-guardiancan include as a trust anchor or watched file.
Out of Scope for v0.0.1 Implementation
- automatic system trust-store mutation
- transparent network interception
- default blocking
- sending traffic to external services
- collecting full request/response bodies
Frequently asked questions about Hermes Traffic Guardian
Similar skills
GitHub Actions Hardening
Enhance the security of your GitHub Actions workflows.
Sensitive Logging Audit
Audit and fix sensitive data exposure in Python logging.
Android App Static Analysis
Automate security assessments of Android apps with MobSF.
Integrating DAST with OWASP ZAP
Seamlessly integrate dynamic security testing into CI/CD pipelines.
Implementing Runtime Security with Tetragon
Enhance Kubernetes security with eBPF-based observability.
Implementing Mobile Application Management
Secure enterprise data on mobile devices with app-level controls.
