NousResearch hermes-agent Skills Guard Multi-Word Prompt Injection Bypass Vulnerability

Vulnerability

A critical prompt injection vulnerability has been identified in NousResearch hermes-agent versions through 2026.4.23. The issue resides in the Skills Guard Multi-Word Prompt Handler, specifically within the file agent/skills_guard.py. The vulnerability allows remote exploitation by manipulating the THREAT_PATTERNS argument, leading to injection that bypasses critical detection filters. This could enable the installation of malicious skills that alter the AI agent's core behaviors.

Impact

Exploitation of this vulnerability allows for unauthorized manipulation of the AI agent's execution logic by bypassing a critical severity check. This could result in the installation of a malicious skill that is loaded into the system prompt for all future sessions, potentially instructing the agent to perform harmful actions or override policies without the user's awareness.

Reproduction

The vulnerability can be reproduced by enabling the community skills installation feature or by passing an untrusted skill definition to the skills_guard.py mechanism. Once these conditions are met, the injection bypass can be achieved by inserting extra words into the payload, circumventing the rigid regular expression patterns that are supposed to block such injections.

Added: May 26, 2026, 8:59 PM
Updated: May 26, 2026, 8:59 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
8.7
remediation
0.0
relevance
9.3
threat
6.4
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.