▸ solutions

Built for agents that act.

A firewall for what your agent does, not just another prompt filter. Start free: one command maps your agent’s blast radius locally, read-only, in minutes.

pip install hermes-shield-scanner

then hermes-shield demo · live on PyPI · v0.8.2 · PyPI · GitHub

then run hermes-shield scan in your own repo · Enterprise? request a security review

6CONTROL PRIMITIVES
12FRAMEWORKS AUDITED
8,447ACTION SURFACES MAPPED
542INSTALL-LIABILITY SURFACES
596REACHABLE-IN-REPO
▸ the primitives

Six controls. One action firewall.

Each primitive sits between your agent and the outside world, at the moment of execution, where it counts. The free scanner maps these surfaces today; the live controls ship with the paid Shield tier (coming).

Kill Switch
STOP RISKY OUTBOUND ACTION ACROSS ALL AGENT TOOLS.
▸ BLAST RADIUS596 reachable-in-repo

Action Integrity

Verify content, approval and state before execution.

0 INHERITED ATTACK SURFACES
Threat Shield
FENCE, SCAN AND CONTAIN PROMPT INJECTION AND OTHER UNTRUSTED CONTENT.

Tool Governance

Map, classify and constrain every tool that can act.

Audit & Visibility

Full audit trail, dashboards and clear operator insight.

Security Review Track

We map your agent’s action surface and hand you the evidence.

▸ the suite

One suite, three stages.

From finding the risk, to fixing it, to standing guard: Scanner → Repairer → Shield. Start with the free scanner; the paid tiers are coming.

▸ SCANNER · FREE · LIVE

Find your blast radius

Scan your agent’s codebase: a local, read-only static + AI-assisted scanner for AI-agent repos. See exactly what your agent could do, a count, not a vibe. hermes-shield scan.

▸▸ REPAIRER · COMING

Fix what we find

After the report, harden the findings: Action Gates and Threat Shield configured to your result. Paid tier, coming. Join the waitlist.

▸▸▸ SHIELD · COMING

Stand guard, always

Live Kill Switch, Action Gates and Audit Trail with drift monitoring and ongoing support. Paid runtime, coming. Enterprise: custom, per team.

▸ why it matters

Your agent inherits more than you shipped.

We mapped 8,447 action surfaces across 12 frameworks. Two distinct tiers matter: 542 install-liability surfaces you inherit the moment you install, and 596 reachable-in-repo surfaces an actual running agent can hit. Install-liability is real, and much of it is reachable. This is the risk the industry now names OWASP LLM06 — Excessive Agency: an agent able to act beyond what you intended.

OWASP LLM06 · EXCESSIVE AGENCY
0 FRAMEWORKS AUDITED
The ones teams build on
WE AUDITED THE AGENT FRAMEWORKS TEAMS ACTUALLY BUILD ON — 361K+ COMBINED GITHUB STARS ACROSS THE FRAMEWORKS WE SCAN.
0 INSTALL-LIABILITY SURFACES
Install-liability tier
SURFACES YOUR AGENT PICKS UP FROM ITS DEPENDENCIES THE MOMENT YOU INSTALL.
0 REACHABLE-IN-REPO
The blast radius tier
REACHABLE FROM A RUNNING AGENT — WHEN ONE TOOL CALL GOES WRONG. SEE CVE-2023-39662.
▸ the line we hold

Prompt filters stop text.
Agents need action control.

Detection tells you something looked wrong. Action control stops the send, the write, the payment, at the moment of execution.

MAPTRACEPROVEBLOCKPATCH
▸ the free scanner

Put a firewall between your agent and the outside world.

A default scan runs fully local and reads your code read-only; nothing is sent anywhere. The optional --ai tier uses your own local Claude CLI; that’s the only mode that sends code text, and it goes to Anthropic’s API under your own account. We were customer zero: our own agent got prompt-injected, so we built the control layer we needed. Independently security-reviewed by an industry professional.

pip install hermes-shield-scanner

then hermes-shield demo · live on PyPI · v0.8.2 · PyPI · GitHub

then run hermes-shield scan in your own repo · Enterprise? request a security review

FREE SCANNER, LIVE NOW
Hermes Shield Solutions — Kill Switches, Action Gates and Audit Evidence