Source-checked · September 26, 2026

Hermes Agent Skills: Browse the Skills Hub, Install, Review, and Share

Start with the current Skills Hub to browse, search, inspect, and install skills. Then verify the source and requirements, test in a narrow scope, approve agent-authored changes, and share only what your team can review.

BrowseInspectInstallReviewUpdate

Current Skills Hub

Browse → search → inspect → install

Hermes now exposes a first-class Skills Hub for official optional skills, skills.sh, well-known endpoints, GitHub sources, and community registries. Installed skills still land in the profile's~/.hermes/skills/directory, which the current Hermes documentation describes as the primary local source of truth.

Direct answer

For a new skill, browse or search first, inspect the resolved source before installation, then use check, update, and audit to maintain installed Hub skills.

Official CLI flow

Browsehermes skills browse
Searchhermes skills search react --source skills-sh
Inspecthermes skills inspect openai/skills/k8s
Installhermes skills install openai/skills/k8s
Checkhermes skills check
Updatehermes skills update
Audithermes skills audit

Source-checked against current Hermes documentation on September 26, 2026. Agent Skills Hub did not execute these commands during this editorial refresh.

Source + safety

Know what Hermes is resolving

Official optional
Browse Hermes-maintained optional skills with --source official.
skills.sh
Search the public directory, inspect the resolved source, then review before install.
Well-known endpoint
Discover skills published from a site through /.well-known/skills/.
GitHub or tap
Install a known owner/repo/path directly or add a curated GitHub tap.
Direct URL / marketplace
Treat community sources as third-party input and review scanner findings.

Install boundary

Current Hermes docs say Hub installs are security-scanned. --force may override non-dangerous policy findings, but it does not override a dangerous verdict.

The skills lifecycle

One reviewable path from discovery to team reuse

A skill is executable procedure, not just a prompt. Treat origin, requirements, permissions, and change history as part of the artifact.

Direct answer

Install only after you can explain what the skill reads, writes, calls, and asks the agent to remember.

01 / Discover

List and open the skill

Use the Skills System, a GitHub tap, ClawHub, a direct URL, or an external directory. Record the origin before copying anything.

02 / Inspect

Review source and requirements

Read SKILL.md, referenced files, commands, environment variables, network targets, and the tools the procedure expects.

03 / Install

Place it in a known scope

Hermes reads local skills from ~/.hermes/skills/. Prefer a narrow, reversible install before sharing it across machines.

04 / Test

Run one bounded task

Use the least-privileged environment that still exercises the workflow. Confirm both the expected output and the stop path.

05 / Approve

Review agent-authored changes

When write approval is enabled, proposed skill changes can remain staged under ~/.hermes/pending/skills/ before they become active.

06 / Share

Publish the evidence with the skill

Share the source, requirements, tested environment, and known limits—not just a Markdown file that happens to run.

SKILL.md anatomy

Readable procedure, explicit boundary

Hermes follows the Agent Skills-compatible SKILL.md pattern. Frontmatter makes the skill discoverable; the body should explain when to use it, what to inspect, which steps to follow, and where to stop.

---
name: review-repository-change
description: Inspect a proposed change before it is accepted.
---

1. Read the source and referenced files.
2. Identify permissions and external calls.
3. Test the smallest reversible case.
4. Stop when evidence is incomplete.

Approval + safety

Do not confuse “installed” with “trusted”

Hermes can help write and improve skills, but the operator still owns the permission boundary and the final acceptance decision.

Agent-authored change flow

Stage first. Accept later.

When skills.write_approval is enabled, proposed changes can be held in ~/.hermes/pending/skills/ for review.

  1. 01

    Proposed

    The agent prepares a new or changed skill.

  2. 02

    Staged

    Files remain pending instead of active.

  3. 03

    Reviewed

    The operator checks the source, permissions, and diff.

  4. 04

    Accepted

    Only the approved version enters the active skills directory.

Supported source routes

Origin is part of the evidence

Hermes documents several ways to obtain skills. The route changes what you need to verify.

Official optional
Browse Hermes-maintained optional skills with --source official.
skills.sh
Search the public directory, inspect the resolved source, then review before install.
Well-known endpoint
Discover skills published from a site through /.well-known/skills/.
GitHub or tap
Install a known owner/repo/path directly or add a curated GitHub tap.
Direct URL / marketplace
Treat community sources as third-party input and review scanner findings.

Security boundary

In-process checks are heuristics. Use OS-level isolation when the model or skill may be adversarial.

Primary sources + quick answers

Check the source date before you copy the workflow

Quick answers

Where do Hermes skills live?

The default local skills directory is ~/.hermes/skills/.

Can Hermes create or edit a skill?

Yes. The documented skill_manage tool supports creating and changing skill files. When write approval is enabled, proposed changes can be staged for review.

Does installing a skill mean it is safe?

No. Review the origin, referenced files, required tools, permissions, external calls, and isolation boundary before activation.

Agent Skills Hub · evidence-first guide