Security is a top priority for the Hermes builder plugin. If you believe you have found a security vulnerability, please report it to us.
- GitHub Security Advisories: Use the "Report a vulnerability" button on the Security tab
- This is the primary and monitored channel for security reports
- GitHub will mediate initial contact and coordinate disclosure
Please include the following in your report:
- A description of the vulnerability and its impact
- Steps to reproduce the issue
- Any proof-of-concept code or exploit
- Your contact information and availability
- We will acknowledge your report within 48 hours
- We will provide a more detailed response within 7 days
- We will keep you informed of the progress towards a fix
- If the vulnerability is confirmed, we will coordinate a disclosure timeline
This policy covers all repositories under the iap/builder GitHub organization. Please note that this plugin is a guest in the Hermes ecosystem — core Hermes security issues should be reported to NousResearch/hermes-agent instead.
We prefer reports in English.