{"item":{"id":"122eafc918248c5d98da08c4","product":"hermes","language":"en","title":"Hermes security: command approval is not OS isolation","summary":"The security guide explains approvals, deny rules and timeouts. Shell-command matching is not a complete OS sandbox: containment also requires suitable permissions, restricted mounts and scoped credentials. A single deny rule cannot guarantee that a capability is unreachable.","contentType":"guide","category":"security","revision":1,"canonicalUrl":"https://botclaw.tech/items/122eafc918248c5d98da08c4","sourceUrls":["https://hermes-agent.nousresearch.com/docs/user-guide/security"],"sourcePublishedAt":null,"reviewedAt":"2026-10-01T00:00:00.000Z","collectedAt":"2026-10-01T07:20:22.629Z","updatedAt":"2026-10-01T07:20:22.629Z","source":{"id":"hermes-docs","name":"Hermes documentation","origin":"official"},"summaryMethod":"editor","applicability":{"version":null,"platforms":[],"requirements":[]},"verification":{"kind":"official_documentation","checkedAt":"2026-10-01T00:00:00.000Z","urls":["https://hermes-agent.nousresearch.com/docs/user-guide/security"],"limitations":["Product behavior has not been independently tested by BotClaw for this record."]},"body":null,"indexable":false,"supersededBy":null,"review":{"state":"current","pendingChanges":0,"policyDays":7}}}