Security policy
Tell us privately. We will answer.
If you have found a way to make hermes-mordred leak, run open, or lie in its status output, that is the bug we most want to hear about. Do not open a public issue for it.
- Include
- Version, platform, refusal message, and the smallest reproduction you have.
- Omit
- Your audit log, your keys, and anything belonging to a third party.
- Credit
- Given by name if you want it, withheld if you do not.
What happens after you send it.
Within 72h
A human acknowledges the report and says whether we can reproduce it.
Within 7 days
A severity assessment and a target date, or an explanation of why it is out of scope.
Within 90 days
A fix ships, or we tell you why it cannot and what we are doing instead.
Disclosure
Published in the GitHub release notes under SECURITY once a fixed release is out.
In scope
- Extraction or cross-purpose use of native wrapping-key material.
- An integrated Hermes transport bypassing a strict protected-route decision.
- A strict provider, endpoint, or declared-harness check that can be bypassed.
- Plaintext sent in a Slack or Discord context already bound to mandatory E2E.
- Status reporting protected state that is inconsistent with the underlying files or helpers.
Out of scope
- Findings that require root or a compromised OS.
- Vulnerabilities in hermes-agent itself — report those upstream.
- Traffic-analysis observations already listed in the threat model.
- Scanner output with no demonstrated impact.
Supported versions
In alpha, only the latest release gets fixes. Backports start at 1.0.
| Version | Status | Security fixes |
|---|---|---|
| 0.1.0a20 | current | yes |
| ≤ 0.1.0a19 | superseded | no — upgrade |