Inspect a skill before installing and testing it
Review files, commands, permissions and outbound destinations before adding a skill. Keep a reversible install record and verify removal in a new session.
- Published
- Oct 1, 2026
- Reviewed
- Oct 1, 2026
- Content updated
- Oct 1, 2026
- Applicable version
- Not pinned; check current documentation
- Platforms
- Supported Hermes host
Before you start
- A disposable workspace and an identified skill source
Treat a skill as third-party code and instructions. Its popularity is not execution evidence. Choose a small read-only skill for the first trial and keep the scope narrower than your normal work environment.
Before installation
- List candidates with the current Hermes skills CLI and inspect the exact skill files and source revision.
- Identify shell commands, downloads, filesystem writes, model usage and account connections. Reject unexplained privileged commands.
- Write one allowed task and one operation that must be denied. Use fake input and empty destinations.
Install, test, remove
Use the documented install command for the chosen source. Run only the allowed task and retain tool output plus file differences. Remove the skill using the current CLI, restart the session and check that it is no longer available. Do not assume removal reverses files or account changes already made by a skill.
hermes skills list --source hub
hermes skills --helpSuccess and failure criteria
Accept the trial only when the allowed task produces its expected artifact and the denied operation remains denied. A loaded skill name alone is insufficient. Unexpected network access, privilege requests or writes outside the test folder mean the trial needs review.
Evidence and limits
Official documentation checked
- Original BotClaw acceptance procedure based on linked official documentation. Product commands were not executed; check your installed version.
Sources
Cite or read with tools
https://botclaw.tech/items/wf-skill-review