oh-my-hermes is an operating layer for Hermes Agent that organizes requests into workflows for planning, research, creation, coding handoffs, operations, and project memory. Hermes users run these workflows through the desktop app, CLI, or messenger app, while the catalogue add-ons extend its native capabilities.
Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add rlaope/oh-my-hermes --skill review-sweepgit clone --depth 1 https://github.com/rlaope/oh-my-hermesWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/rlaope/oh-my-hermes/review-sweep)<a href="https://agentmods.dev/skills/rlaope/oh-my-hermes/review-sweep"><img src="https://agentmods.dev/badge/skills/rlaope/oh-my-hermes/review-sweep/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/rlaope/oh-my-hermes/review-sweep"><img src="https://agentmods.dev/badge/skills/rlaope/oh-my-hermes/review-sweep.svg" alt="Reviewed on agentmods" width="80" height="20"></a>- NVIDIA SkillSpector pass
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00058 | $0.00377 |
| Opus 5 | $0.00029 | $0.00188 |
| Sonnet 5 | $0.00012 | $0.00075 |
| Haiku 4.5 | $0.00006 | $0.00038 |
Grade A, and why
review-sweep scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 13d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
Review sweep
The procedure lives in docs/REVIEW-SWEEP.md.
Read that file and follow it.
It is kept there rather than here because Codex, Hermes handoffs, and generic
executor profiles run the same sweep, and AGENTS.md requires that no single
executor own a shared surface. This file exists so the procedure is reachable
as /review-sweep; it deliberately holds no rules of its own, so there is
nothing here to drift out of sync with the real one.
Start by reading, in this order:
cat docs/REVIEW-SWEEP.md
cat REVIEW.md
Two things worth knowing before you open the procedure, because they are what the sweep gets wrong most often:
- Never review from the diff alone. This repo's defects are about consistency with code that is not in the diff, so the procedure checks the PR out into a worktree and runs the gates.
- The default is a dry run. A review is a public, notifying write to
someone else's work; print the findings and stop for confirmation unless the
invocation carried
--apply.
Arguments pass through verbatim: a bare number reviews one PR, --drafts and
--mine widen the sweep, --apply posts.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 13d ago First seen · 41 lines · 58 tokens per session scan A 1adb0a360c24
review-sweep is a skill published in the GitHub repository rlaope/oh-my-hermes (1,677 stars, last pushed today), licensed MIT. It adds 58 tokens to every session and 377 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
reviewing-changes
Use when a review package asks you to review a plan step's change set (todo.startReview): you are the REVIEWER, not the author. How to judge an agent-written diff, file findings with addreviewcomment, and settle with exactly one reviewverdict.
reflecting-findings
Use when a reflection package hands you another agent's review findings to verify (before they become a fix request): you are the REFLECTOR, an independent skeptic. Judge each finding against the real code and settle it with reflectfinding — kept or refuted.
nlpm-audit
Audit SKILL.md, AGENTS.md, prompts, hooks, and plugin manifests for instruction conflicts, quality, broken references, and manifest-to-disk drift.
api-design-reviewer
Use when reviewing API designs for consistency, usability, versioning, error semantics, security, backward compatibility, and developer experience before implementation or release.
pr-review-expert
Review GitHub PRs or GitLab MRs for correctness, security, compatibility, and affected test coverage, with actionable evidence tied to the diff.
gh-address-comments
Use when addressing GitHub PR review comments or issue comments on the current branch with gh CLI, including auth checks, comment triage, edits, verification, and replies.