hermes-agent-skill-authoring — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited hermes-agent-skill-authoring (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
There are two places a SKILL.md can live:
~/.agent/skills/<maybe-category>/<name>/SKILL.md — personal, not shared. Created via skill_manage(action='create').Source of truth: tools/skill_manager_tool.py::_validate_frontmatter. Hard requirements:
--- as the first bytes (no leading blank line).\n---\n before the body.name field present.description field present, ≤ 1024 chars (MAX_DESCRIPTION_LENGTH).---.Peer-matched shape used by every skill under skills/software-development/:
---
name: my-skill-name # lowercase, hyphens, ≤64 chars (MAX_NAME_LENGTH)
description: Use when <trigger>. <one-line behavior>.
version: 1.0.0
author:
license: MIT
metadata:
hermes:
tags: [short, descriptive, tags]
related_skills: [other-skill, another-skill]
---version / author / license / metadata are NOT enforced by the validator, but every peer has them — omit and your skill sticks out.
MAX_SKILL_CONTENT_CHARS, ~36k tokens).software-development/ sit at 8-14k chars. Aim for that range. If you're pushing past 20k, split into references/*.md and reference them from SKILL.md.Every in-repo skill follows roughly:
# <Title>
## Overview
One or two paragraphs: what and why.
## When to Use
- Bulleted triggers
- "Don't use for:" counter-triggers
## <Topic sections specific to the skill>
- Quick-reference tables are common
- Code blocks with exact commands
- the agent-specific recipes (tests via scripts/run_tests.sh, ui-tui paths, etc.)
## Common Pitfalls
Numbered list of mistakes and their fixes.
## Verification Checklist
- [ ] Checkbox list of post-action verifications
## One-Shot Recipes (optional)
Named scenarios → concrete command sequences.Not every section is mandatory, but Overview + When to Use + actionable body + pitfalls are the minimum for the skill to feel like a peer.
skills/<category>/<skill-name>/SKILL.mdCategories currently in repo (confirm with ls skills/): autonomous-ai-agents, creative, data-science, devops, dogfood, email, gaming, github, leisure, mcp, media, mlops/*, note-taking, productivity, red-teaming, research, smart-home, social-media, software-development.
Pick the closest existing category. Don't invent new top-level categories casually.
ls skills/<category>/Read 2-3 peer SKILL.md files to match tone and structure.
tools/skill_manager_tool.py if unsure.write_file to skills/<category>/<name>/SKILL.md. import yaml, re, pathlib
content = pathlib.Path("skills/<category>/<name>/SKILL.md").read_text()
assert content.startswith("---")
m = re.search(r'\n---\s*\n', content[3:])
fm = yaml.safe_load(content[3:m.start()+3])
assert "name" in fm and "description" in fm
assert len(fm["description"]) <= 1024
assert len(content) <= 100_000skill_view / skills_list will not see the new skill until a new session. This is expected, not a bug.metadata.hermes.related_skills unions both trees (skills/ in-repo and ~/.agent/skills/) at load time. You CAN reference a user-local skill from an in-repo skill, but it won't resolve for other users who clone the repo fresh. Prefer referencing only in-repo skills from in-repo skills. If a frequently-referenced skill lives only in ~/.agent/skills/, consider promoting it to the repo.
skill_manage(action='patch', name=..., old_string=..., new_string=...) works fine on in-repo skills.write_file the whole SKILL.md. skill_manage(action='edit') also works but requires supplying the full new content.write_file to skills/<category>/<name>/references/<file>.md, templates/<file>, or scripts/<file>. skill_manage(action='write_file') also works and enforces the references/templates/scripts/assets subdir allowlist.~/.agent/skills/, not the repo tree. Use write_file for in-repo creation.content.startswith("---"); any leading blank line or BOM fails validation.ls skills/<category>/ and open 2-3 peers. Prefer extending an existing skill to creating a narrow sibling.skill_view using the exact path.related_skills: [some-user-local-skill] works for you but breaks for other clones. Prefer only in-repo links.skills/<category>/<name>/SKILL.md (not in ~/.agent/skills/)---, closes with \n---\nname, description, version, author, license, metadata.hermes.{tags, related_skills} all present# Title → ## Overview → ## When to Use → body → ## Common Pitfalls → ## Verification Checklistrelated_skills references resolve in-repo (or are explicitly OK to be user-local)git add skills/<category>/<name>/ && git commit completed on the intended branch~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.