Review process

Inspection Desk

Read the review status before you try a Bot. Each listing records the source version and reports the automated source scan, human technical review, and Hermes Desktop test separately. Review the Bot’s requested access and approval points before using it.

Three review statuses

Automated source scan

A scanner checks a limited set of public files for known risk patterns without running the project.

Human technical review

A qualified person reads the relevant files and records findings. This review is unavailable at this time.

Hermes Desktop test

The exact project version is installed in a disposable profile and tested with a small task.

How evidence is described
Official Hermes source

Official Hermes source

Official Hermes documentation, release notes, or source code supports the statement. The listing links to that source.

Tested by Bot Cabinet

Tested by Bot Cabinet

A Hermes Desktop test record names the Hermes version, computer system, date, exact project version, steps, and result. A later project version requires another test.

Example plan

Example plan

This is a plan someone can adapt. It does not claim that a downloadable package or working system already exists.

Publisher description

Publisher description

The project publisher described this behavior. Bot Cabinet has not reproduced it in a Hermes Desktop test.

Planned submission review

How the Inspection Desk would review a submission

Public submissions are closed. A planned automated source scan would read a fixed, limited set of public files without running submitted code. Profiles that require technical judgment would remain unpublished while human technical review is unavailable.

  1. Record one exact public version

    The scan records the repository, a fixed source version, the file that describes the Hermes package, its license, included paths, and required account names. A later source version needs a new scan.

  2. Check for private material

    The scan looks for possible credentials, memories, sessions, logs, personal information, and local computer paths.

  3. Check for risky actions

    The scan looks for instructions or code that can delete files, send data, run commands, contact outside services, stay active, or start on a schedule.

  4. State what the scanner cannot decide

    Projects that use powerful tools or unclear instructions would stay unpublished while human technical review is unavailable.

  5. Run a Hermes Desktop test separately

    A separate test would install the exact project version in a disposable profile and try a small task. The automated source scan would not run submitted code.

Important boundaries

A profile separates Bot data

Each Hermes profile keeps its own settings, memory, and history. The Bot can still use the files and tools that a person gives it permission to use.

Anyone can download a public repository

Create a new public package for sharing. Keep credentials, memories, sessions, client material, and private instructions in the live profile.

Public source still requires review

Hermes profile packages do not include a built-in signature from the Registry. Record the exact version and review changes before updating.

Official sources for these rules

Selected version-specific guidance links directly to official Hermes documentation and released source code. When those sources differ, both links are provided with an explanation.