Hermes Agent is an open-source agent from Nous Research that can use a terminal, search the web and answer through messaging apps. Searches such as "hermes agent security" and "is Hermes Agent safe" come down to two questions: what can it run on your Mac, and where can its traffic go. This article answers both from the project’s own documentation and from published reporting, then explains how FireAI, a network firewall for macOS developed by HisnLabs, watches its connections.
What Hermes Agent is and how it runs on a Mac
The repository describes a self-improving agent with a built-in learning loop that creates skills from experience. It is built by Nous Research, written mainly in Python with Node.js components for its web interface, and released under the MIT licence. On macOS it installs with a one-line script (curl -fsSL https://hermes-agent.nousresearch.com/install.sh | bash). It works with Nous Portal, OpenRouter, OpenAI, Anthropic and custom endpoints, and its messaging gateway supports Telegram, Discord, Slack, WhatsApp, Signal and email.
What it can access
The README lists more than 40 integrated tools, including web search and terminal access, and seven terminal backends: local, Docker, SSH, Singularity, Modal, Daytona and Vercel Sandbox. On the local backend, commands run with the permissions of the account that started Hermes.
The documented permission model
The security documentation describes defence in depth.
- Approvals have three modes: smart (a model assesses risk), manual (always ask) and off. YOLO mode bypasses prompts, but a hardline blocklist for catastrophic commands still applies.
- Containerised backends such as Docker, Modal and Daytona isolate commands; dangerous-command checks are skipped there because the container is the boundary.
- Gateway access is denied by default, with DM pairing codes the operator approves, and platform and global allowlists.
- Network controls include SSRF protection that blocks private ranges, loopback and cloud metadata endpoints.
- Protected paths such as
~/.ssh/and~/.aws/are hard-blocked from writes, and subprocesses receive a filtered environment.
These are vendor statements, not independent test results. The documentation does not publish a fixed list of domains Hermes contacts; they depend on the model provider and messaging platforms you configure.
Documented incidents
The GitHub Advisory Database lists CVE-2026-9366, a moderate injection issue in versions before 0.15.0, patched in 0.15.0 (advisory). Separately, Hunt.io and Unit 42 reported attackers running Hermes Agent in YOLO mode against other people’s servers (Hunt.io) (BleepingComputer). Those cases concern attackers choosing the tool, not a reported defect in it. Details are in our incident summary.
Watching Hermes Agent with FireAI
FireAI is an on-device firewall for macOS developed by HisnLabs. Its Agent profile feature lists Hermes Agent among the 19 AI agents it recognises, and because Hermes Agent runs under python, it identifies it by the script the runtime runs, as Agent profile does for node, bun, deno and python agents. The agent’s child processes, such as a shell, git or curl it launches, are attributed to it by walking up the parent processes. FireAI then learns, for the first 3 days, which destinations Hermes Agent normally contacts, grouped by domain, and flags nothing during that period. After that, a first-ever destination is flagged in Suggestions, in the AI agents card and in Quick Review. An upload spike is flagged too: an hour in which the agent uploaded at least 4 times its busiest hour so far, and never less than 25 MB.
FireAI uses metadata only, host names and byte counts, and never reads the payload of a connection. By default it flags and leaves the decision to you. In the Agent profile security mode it goes further: once learning has finished, a connection to a destination outside the baseline is blocked until you press Allow, and Keep blocked turns that block into a rule that holds in every mode.
Setup, step by step
- Install FireAI and finish its first-run setup, following Install and finish setup.
- Use Hermes Agent as you normally do for 3 days. FireAI learns its destinations in the background and flags nothing yet.
- Open Suggestions and find the AI agents card. When a flag appears, read the plain-words sentence, then swipe left in Quick Review to block or right for "It’s fine".
- If you want the agent kept to places it already uses, choose Agent profile in the security mode menu, next to Home, Coffee shop, Paranoid and Under attack.
- When something is blocked, open the AI agents card and choose Allow to add it to the baseline, or Keep blocked to create a block rule.
Limits
- FireAI does not prevent prompt injection. It limits the damage by flagging, and letting you block, the path data would take out of your Mac.
- FireAI cannot see Hermes Agent’s prompts, the contents of MCP tools, skills, or which files it reads, because TLS hides the payload and FireAI is not inside the agent.
- Hermes Agent is matched by script name, so FireAI labels it rather than verifying it: only Claude Code, Claude and Cursor are checked against their developer’s signature.
- Commands that Hermes runs in a Docker or remote backend happen outside your Mac’s process tree, so FireAI sees the connection from the Docker or SSH process, not from the command inside.
- FireAI does not replace Hermes’s own approvals, allowlists or sandbox, and does not review the skills it creates.
- During the 3-day learning period nothing is flagged, and upload spikes are flagged, not blocked.
- A new server under a domain the agent already uses is treated as known, because destinations are grouped by domain.
The full feature description is in the Agent profile documentation. A related guide covers OpenClaw.
Other agents FireAI recognises have their own guides: Claude Code, Claude desktop app, Cursor, ChatGPT Mac app, OpenAI Codex CLI, OpenClaw, Gemini CLI, GitHub Copilot CLI, Amp, Qwen Code, opencode, Aider, Goose, Crush, Windsurf, Kiro, Trae, Muse from Meta, any AI agent run by Python or Node.
How FireAI and HisnLabs fit in
Hermes Agent can run terminal commands as you. FireAI shows, and can block, where it connects next.
FireAI is HisnLabs’ own product: an on-device AI firewall for Mac. It shows every connection your apps make, in plain language, and lets you decide what leaves your Mac — its AI runs locally, so your traffic is never sent to us or anyone else. HisnLabs’ security research team is the group that keeps that decision-making accurate: cataloguing which domains are ordinary telemetry versus a real product, tracking the country and network behind a connection, and training the on-device model (its FireAI Pilot feature) on real traffic patterns, all without any of it leaving your Mac.
You can read the technical decisions behind it, or try FireAI for 17 days, at FireAI, by HisnLabs.
