install-buzz-hermes
Install or verify Block Buzz and Nous Research Hermes Agent on macOS only, with Buzz as the orchestration workspace and Hermes as its ACP execution runtime. Use for macOS fresh installs, upgrades, repair, recovery, or integration checks; do not use on Linux, Windows, or for unrelated products nam...
Install this skill
or
95/100
Security score
The install-buzz-hermes skill was audited on Sep 4, 2026 and we found 1 security issue across 1 threat category. Review the findings below before installing.
Categories Tested
Security Issues
medium line 24
Access to home directory dotfiles
SourceSKILL.md
| 22 | - Run the script without `--execute` first. Report the selected sources and planned changes. |
| 23 | - Before `--execute`, obtain authorization because the script downloads and runs upstream software and writes outside the workspace. |
| 24 | - Never import an existing `~/.buzz`, `~/.hermes`, relay directory, launch agent, identity, key, or configuration unless the user explicitly requests migration. |
| 25 | - A clean Buzz reset must also audit `~/Library/WebKit/xyz.block.buzz.app`; its local storage can retain the active community URL after the app and Application Support directory are removed. With authorization, quit Buzz and remove that WebKit directory when the user requests a fresh configuration. Keep macOS Keychain identities unless the user explicitly asks to delete them. |
| 26 | - Do not expose tokens, Nostr private keys, `.env` contents, or Hermes authentication files in output. |
Scanned on Sep 4, 2026
View Security Dashboard