
Agentic pentest profile for Hermes: 31 playbooks for authorised recon, web/access-control attacks, safe exploit validation, and evidence-driven reporting with guard gates.
35 playbooks · 19 references · 14 templates · required execution guard · Hermes-native
Violin is a Hermes-native agentic pentest profile for supervised, authorised penetration tests — from reconnaissance through safe exploit validation to reporting. It uses Hermes' built-in toolsets, seven routed skills, and the required violin-guard plugin at the target-execution boundary. The standalone CLI supports release checks, diagnostics, and administrative recovery; target commands run through the plugin. Violin adds no profile-specific credentials and inherits the provider and tool backends already configured in Hermes.
Quick start · Workflow · Guard tools · Benchmarks · Landing page · Discussions · Development
Following Violin? Star the repository to keep it easy to find and help other security engineers discover supervised agentic pentesting.
Violin is listed in community-curated collections including awesome-ai-security, awesome-hermes-skills, awesome-hermes-agent, and awesome-infosec.
Third-party coverage: Starlog technical analysis and “Violin: Supervised Agentic Penetration Testing Profile for Hermes Agent”.
For independent evaluation, use the reviewer kit, which collects the benchmark path, known limits, review context, and a factual comparison with autonomous pentest-agent designs.
| Guarded target execution | Scope, phase, PTT, skill, hypothesis, history, and synchronization checks run before a target command starts. |
| Persistent engagement state | PTT tasks, hypotheses, command history, checkpoints, evidence, and reports survive context compression. |
| Evidence-backed findings | A typed submission binds each validated finding to authenticated execution receipts. |
| Routed methodology | A pentest orchestrator selects focused web, identity, API, business-logic, LLM-security, and misconfiguration playbooks. |
| Bounded execution | Single commands, command bursts, background processes, batch review, heartbeat checks, and cancellation share one state model. |
| Verifiable releases | Plugin registration, schemas, skill snapshots, documentation contracts, lint, formatting, and the full test suite are release-gated. |
hermes profile install https://github.com/Strategic-Automation/violin
hermes -p violin
Then start with an authorized target and let Violin collect the scope before any target interaction:
Run an authorized penetration test against example.com.
uv for local developmentViolin does not select a model or provider. Configure those in Hermes. For a capable default, use Qwen3.8 27B locally or DeepSeek V4 Flash through a hosted provider.
flowchart LR
S[Scope] --> R[Recon]
R --> V[Vulnerability research]
V --> E[Exploit validation]
E --> P[Reporting]
P --> X[Retrospective]
G[Violin Guard] -. validates .-> R
G -. validates .-> V
G -. validates .-> E
scope/scope.yaml.violin_record_ptt.violin_exec or violin_exec_burst.violin_review_batch.The complete phase model is:
SCOPING → RECON → VULN_RESEARCH → EXPLOITATION
→ POST_EXPLOITATION / PRIVESC / FLAGS
→ REPORTING → RETROSPECTIVE
Starting work in a new phase requires a PTT task under that phase. Existing tasks are not moved between phase sections.
The plugin registers twelve Hermes tools from one typed registry:
| Tool | Purpose |
|---|---|
violin_record_ptt | Create, start, refresh, close, or cancel a PTT task |
violin_record_hypothesis | Create or update a scoped hypothesis |
violin_submit_finding | Submit a validated finding bound to its signed execution receipts |
violin_exec | Execute one guarded command |
violin_exec_burst | Execute a bounded command file |
violin_exec_status | Read background execution status |
violin_exec_cancel | Cancel tracked background execution |
violin_review_batch | Review a completed batch and settle state |
violin_rebind_pending_batch | Rebind a pending batch after confirmation |
violin_heartbeat_done | Clear a completed heartbeat review |
violin_target | Resolve the approved assessment target |
violin_status | Explain current tasks, skills, and blockers |
violin_exec is the generic target-command boundary. There are no
tool-specific execution adapters or binary allowlists. Installed
non-interactive tools may run only after the engagement gates pass.
The raw-terminal hook is a best-effort safety net, not network containment.
Use terminal only for host-local preparation and administration.