Introduction

The DeepSeek Harness (DSH) ecosystem emphasizes modularity and feature extensibility. When Hermes Agent is running on a Linux server, the agent usually has elevated system permissions. If the host environment itself contains security vulnerabilities (such as viruses, mining processes, or Rootkits), the agent’s runtime environment will also be directly exposed to risk. Therefore, after deploying DSH plugins or Hermes Agent, performing a security audit on the underlying server is a necessary operational procedure.

Plugin Overview

axelfreeman/hermes-security-audit is a security audit skill designed specifically for Hermes Agent. Based on an open-source toolset, it aims to help users check whether a Linux server contains malware, backdoors, cryptocurrency mining programs, or other security risks. The plugin integrates multiple detection mechanisms to perform a comprehensive health check of the server environment.

Core Capabilities

The plugin includes the following 10 security detection features:

  • Virus scanning: Uses ClamAV to scan specified directories for viruses.
  • Rootkit detection: Uses the dual mechanism of rkhunter and chkrootkit to detect Rootkits and backdoors.
  • Cryptocurrency mining detection: Identifies suspected mining processes through process auditing.
  • Exposed credential scanning: Scans the file system for plaintext-stored API keys, tokens, or private keys.
  • Port auditing: Checks open ports to identify unnecessary network services.
  • SSH brute-force detection: Analyzes logs to identify SSH brute-force behavior.
  • Docker escape detection: Audits container configurations, checking privileged mode and port exposure.
  • Cron job auditing: Checks scheduled tasks for all users to discover potentially malicious scheduled jobs.
  • SUID/SGID vulnerability detection: Detects executable files with elevated privileges to identify privilege escalation vectors.
  • Outbound connection auditing: Checks active network connections to identify abnormal data exfiltration behavior.

Installation and Enablement

Installation can be completed using Hermes Agent’s built-in skill loading command. The plugin is open sourced under the MIT License.

hermes skill load hermes-security-audit

Typical Usage

After installation, you can trigger the audit by interacting directly with Hermes Agent through natural language. The Agent invokes the underlying detection tools and reports the scan results after execution is completed.

Example conversation instruction:

“run a security audit on my server”

Notes

  • Runtime environment: This plugin is developed for Linux server environments.
  • Scan scope: By default, the scan covers key directories such as /tmp, /opt, and /root.
  • Permission requirements: Running this plugin requires appropriate system permissions. Make sure the current process has permission to read target files and execute system commands.
  • License: The plugin code follows the MIT License and can be freely used and modified.