{"item":{"id":"wf-skill-review","product":"hermes","language":"en","title":"Inspect a skill before installing and testing it","summary":"Review files, commands, permissions and outbound destinations before adding a skill. Keep a reversible install record and verify removal in a new session.","contentType":"guide","category":"integration","revision":2,"canonicalUrl":"https://botclaw.tech/items/wf-skill-review","sourceUrls":["https://hermes-agent.nousresearch.com/docs/user-guide/features/skills","https://hermes-agent.nousresearch.com/docs/user-guide/security"],"sourcePublishedAt":"2026-10-01T13:51:23.773Z","reviewedAt":"2026-10-01T00:00:00.000Z","collectedAt":"2026-10-01T13:51:23.773Z","updatedAt":"2026-10-01T13:51:29.241Z","source":{"id":"botclaw-editorial","name":"BotClaw","origin":"editorial"},"summaryMethod":"editor","applicability":{"version":null,"platforms":["Supported Hermes host"],"requirements":["A disposable workspace and an identified skill source"]},"verification":{"kind":"official_documentation","checkedAt":"2026-10-01T00:00:00.000Z","urls":["https://hermes-agent.nousresearch.com/docs/user-guide/features/skills","https://hermes-agent.nousresearch.com/docs/user-guide/security"],"limitations":["Original BotClaw acceptance procedure based on linked official documentation. Product commands were not executed; check your installed version."]},"body":{"introduction":"Treat a skill as third-party code and instructions. Its popularity is not execution evidence. Choose a small read-only skill for the first trial and keep the scope narrower than your normal work environment.","sections":[{"heading":"Before installation","paragraphs":[],"steps":["List candidates with the current Hermes skills CLI and inspect the exact skill files and source revision.","Identify shell commands, downloads, filesystem writes, model usage and account connections. Reject unexplained privileged commands.","Write one allowed task and one operation that must be denied. Use fake input and empty destinations."]},{"heading":"Install, test, remove","paragraphs":["Use the documented install command for the chosen source. Run only the allowed task and retain tool output plus file differences. Remove the skill using the current CLI, restart the session and check that it is no longer available. Do not assume removal reverses files or account changes already made by a skill."],"code":"hermes skills list --source hub\nhermes skills --help"},{"heading":"Success and failure criteria","paragraphs":["Accept the trial only when the allowed task produces its expected artifact and the denied operation remains denied. A loaded skill name alone is insufficient. Unexpected network access, privilege requests or writes outside the test folder mean the trial needs review."]}]},"indexable":true,"supersededBy":null,"review":{"state":"current","pendingChanges":0,"policyDays":7}}}