Security
الأمان
Start with meaning, then move to detail.
This lesson explains Security as part of operating Hermes with explicit security boundaries. You will learn what it does, when it matters, and the smallest safe test that proves it works.
If you are new, do not memorize names. Focus on three questions: what problem does this solve, what access does it need, and how can you verify the result?
For practice, inspect the first example, identify its effects, run it on test data, and compare the result with the source claim.
For advanced readers, inspect Overview, Dangerous Command Approval, Approval Modes, then verify failure modes and version compatibility.
You only need to know which files and accounts the agent may access.
A clear outcome before you read.
- Understand Security without assumed prior knowledge.
- Separate the source description from what still needs testing in your environment.
- Read the first command and identify its inputs and outputs before copying it.
Short definitions before the details.
- Gateway
- The process that connects Hermes to channels such as Telegram or Discord and routes messages.
- Approval & sandbox
- Approval pauses a sensitive action before execution; sandboxing limits impact if something goes wrong.
Security model, dangerous command approval, user authorization, container isolation, and production deployment best practices
What does the source say, and in what order?
- 01Overview
Start here to understand the core idea or structure.
- 02Dangerous Command Approval
Read this after the foundation, then connect it to the previous step.
- 03Approval Modes
Read this after the foundation, then connect it to the previous step.
- 04YOLO Mode
Read this after the foundation, then connect it to the previous step.
- 05Hardline Blocklist (Always-On Floor)
Read this after the foundation, then connect it to the previous step.
- 06User-Defined Deny Rules (approvals.deny)
Read this after the foundation, then connect it to the previous step.
- 07Approval Timeout
Read this after the foundation, then connect it to the previous step.
- 08What Triggers Approval
Read this after the foundation, then connect it to the previous step.
- 09Approval Flow (CLI)
Read this after the foundation, then connect it to the previous step.
- 10Approval Flow (Gateway/Messaging)
Finish here to verify the result and special cases.
Copy only after you understand the effect.
approvals:
mode: smart # smart | manual | off
timeout: 300 # seconds to wait for user response (default: 300)
cron_mode: deny # deny | approve — what cron jobs do when they hit a dangerous command
mcp_reload_confirm: true # /reload-mcp asks before invalidating the MCP tool cache
destructive_slash_confirm: true # /clear, /new, /reset, /undo prompt before discarding state> /yolo
⚡ YOLO mode ON — all commands auto-approved. Use with caution.
> /yolo
⚠ YOLO mode OFF — dangerous commands will require approval.approvals:
deny:
- "git push --force*"
- "*curl*|*sh*"
- "dd if=* of=/dev/*"Read the first command and identify its inputs and outputs before copying it.
Match every command to your installed Hermes version, review the files and accounts it can reach, and use non-sensitive data for the first test. If this explanation differs from the source, the official source wins.