Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add DevvGwardo/brain-mcp --skill brain-mcp-hermes-hardeninggit clone --depth 1 https://github.com/DevvGwardo/brain-mcpWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/devvgwardo/brain-mcp/brain-mcp-hermes-hardening)<a href="https://agentmods.dev/skills/devvgwardo/brain-mcp/brain-mcp-hermes-hardening"><img src="https://agentmods.dev/badge/skills/devvgwardo/brain-mcp/brain-mcp-hermes-hardening/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/devvgwardo/brain-mcp/brain-mcp-hermes-hardening"><img src="https://agentmods.dev/badge/skills/devvgwardo/brain-mcp/brain-mcp-hermes-hardening.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00071 | $0.00845 |
| Opus 5 | $0.00036 | $0.00423 |
| Sonnet 5 | $0.00014 | $0.00169 |
| Haiku 4.5 | $0.00007 | $0.00085 |
Grade A, and why
brain-mcp-hermes-hardening scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 12d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 69 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Brain MCP Hermes Hardening
Use Hermes as an external reviewer for brain-mcp, then implement the chosen fix locally in the repo. Keep the Hermes pass read-only, keep the local write set small, and treat commit/push as the last step after validation.
Workflow
1. Gather Repo State
- Run
git status --short --branchbefore planning any edits. - Read
README.md,ANALYSIS.md, andARCHITECTURE.mdwhen they exist. - Read
references/brain-mcp-hotspots.mdfor the highest-value starting points in this repo. - Detect whether the tree is already dirty. If it is, isolate your work and do not revert or stage unrelated changes.
2. Run a Hermes Audit First
- Use Hermes for the first-pass audit, not for broad autonomous editing.
- Ask for the single highest-leverage weakness, exact files/functions, the failure mode, and the smallest credible fix worth shipping first.
- Keep the prompt short enough that Hermes can inspect the repo on disk instead of receiving a massive inline context dump.
Example prompt:
hermes chat -q "Audit the current brain-mcp repo. Stay read-only. Find the single highest-leverage reliability or maintainability weakness, cite exact files or functions, explain the user-visible failure mode, and recommend the smallest fix worth shipping first." -Q
- If Hermes returns multiple issues, prioritize the one backed by existing code, logs, or documentation over speculative cleanup.
3. Choose a Bounded Fix
- Prefer concrete failures over structural polish.
- Prefer one or two files over a broad rewrite.
- Prefer reliability fixes in spawn, watchdog, gate, or session-state handling.
- Avoid large decomposition work such as splitting
src/index.tsunless the user explicitly asks for refactoring instead of hardening. - Avoid files that already have unrelated local edits unless the fix truly belongs there.
4. Implement Locally
- Make code changes with local editing tools after the Hermes review.
- Keep Hermes as reviewer/orienter, not primary patch generator.
- Preserve existing project conventions and avoid “cleanup” changes that are not required for the fix.
- Update docs only when behavior, commands, or operator expectations actually change.
What ships with it
2 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 12d ago First seen · 69 lines · 71 tokens per session scan A efc538255866
brain-mcp-hermes-hardening is a skill published in the GitHub repository DevvGwardo/brain-mcp (8 stars, last pushed 1mo ago), licensed MIT. It adds 71 tokens to every session and 845 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
adversarial-reviewer
Adversarial code review that assumes bugs exist and hunts for them. Use when asked to review code, find bugs, audit for correctness, stress-test a PR, or when someone says "tear this apart" or "what's wrong with this". Give no benefit of the doubt — every line is guilty until proven innocent.
gsd-ns-review
Route to the appropriate quality / review skill based on the user's intent. gsd-code-review-fix was absorbed by gsd-code-review --fix in #2790.
issue
Use when starting a chain from a GitHub issue — turning an issue URL or number into a triaged, planned, dispatched, and reviewed pull request. Classifies the thread (bug → root-cause discipline, feature → plan chain, question → drafted reply), synthesizes a spec from the issue's own acceptance criteria, then runs the…
gitnexus
A code-graph analysis add-on for examining an existing codebase, including symbols, call paths, execution flows, and effects across repositories. It can query GitNexus through its command-line or MCP interfaces.
cleanup-code-inspections
Reduce technical debt and improve code quality by systematically resolving static analysis warnings.
sonarqube-mcp
Provides SonarQube and SonarCloud integration patterns via the Model Context Protocol (MCP) server. Enables quality gate monitoring, issue discovery and triaging, pre-push code analysis, and rule education directly in the agent workflow. Use when the user wants to check quality gates, search for Sonar issues, analyze…