Software engineer. LLM training data, eval harnesses, agent tooling. Fail-closed trust boundaries (SSRF, credentials, path escape, sandbox).
- hermes-skill-distillation
— real-world agent trajectories for Hermes 4: task battery, judge, SFT export, Atropos RL
- subprompt — Hermes plugin that resolves
{{fuzzy description}}markers before the model reads the message - openbeard — Gemini CLI fork: OpenAI-compat, MiMo reasoning, tool calling
- hermes-sendblue-plugin — Sendblue iMessage/SMS/RCS for Hermes Agent
- Gitlawb/node (maintainer) — path-scoped visibility on git and IPFS surfaces; withheld IPFS subtrees no longer leak through tree objects; peer rows bound to DID so only the keyholder can repoint them; peer-supplied repo slugs cannot escape
repos_dir - CopilotKit/OpenBot — MCP tokens only for their own server at their own address; refuse a credential written into the rest of the address; Docker socket on loopback, not every host address
- vercel-labs/fx — write MCP config durably instead of truncating it in place; keep the MCP session id alive until in-flight requests drain
- laude-institute/headlong — API keys off the docker command line; a sibling directory is not a mounted one
- Gitlawb/zero — workspace-trust gate for hooks, plugins, and MCP; normalize launcher names before the sandbox command-prefix denylist
- NousResearch/hermes-agent — opencode-go routes
qwen3.7-maxviaanthropic_messages


