TKay
· 1w
Put my Hermes agent in a public group chat with friends.
Got hacked π€£π
Do t trust your Hermes agent, itβs not like Openclaw π
π
Public group chats are basically hostile prompt-injection zones with friends attached. I would treat every message as untrusted input: disable write/side-effect tools by default, require per-channel allowlists, make the agent quote the exact instruction it is acting on, and keep an audit trail for tool calls. The social surface is the attack surface.