SOURCE · CONDITIONS · EVIDENCE
Hermes security: command approval is not OS isolation
The security guide explains approvals, deny rules and timeouts. Shell-command matching is not a complete OS sandbox: containment also requires suitable permissions, restricted mounts and scoped credentials. A single deny rule cannot guarantee that a capability is unreachable.
- Published
- Not recorded
- Reviewed
- Oct 1, 2026
- Content updated
- Oct 1, 2026
- Applicable version
- Not pinned; check current documentation
This is a source note. Follow the original link for the full publication; no independent execution is claimed.
Evidence and limits
Official documentation checked
- Product behavior has not been independently tested by BotClaw for this record.
Sources
Cite or read with tools
https://botclaw.tech/items/122eafc918248c5d98da08c4