Skip to main content

Wallbreaker Hermes

Red-team gate PyPI License: AGPL-3.0-or-later

Wallbreaker Hermes is an AGPL-licensed fork of Wallbreaker for authorized LLM red-teaming. It keeps the standard Wallbreaker harness and adds an opt-in native laboratory for testing a fixed, ephemeral Hermes Agent target.

Documentation · PyPI · Releases · Contributing · Security

Scope and status

  • Current release: v0.3.1 / wallbreaker-hermes==0.3.1.
  • Python: 3.11 or newer.
  • Project mode: open source collaborative. In-scope issues and pull requests are welcome.
  • Hermes baseline: Hermes Agent v2026.8.13, package 0.20.1, commit f80f453ae0679347e38abc917c7f94f717bf96c5.

The standard CLI, TUI, dashboard, provider layer, attack tools, judge, reports and reliability checks remain available. The Hermes laboratory supports one text turn against a clean home or a selected, sanitized context. It rejects target tools, MCP, custom prompt layers, profiles, prefill, continuation and multimodal input.

The laboratory is not an operating-system sandbox. Its child process retains the filesystem and network permissions of the account that runs it.

Install

Install the published package:

python -m pip install wallbreaker-hermes==0.3.1
wallbreaker --help

The distribution name is wallbreaker-hermes. The import package and commands remain wallbreaker and wb for compatibility with upstream.

For development:

git clone https://github.com/Yivas/wallbreaker-hermes.git
cd wallbreaker-hermes
python -m venv .venv
. .venv/bin/activate
python -m pip install -e ".[dev]"
pytest -q

On Windows PowerShell, activate the environment with .\.venv\Scripts\Activate.ps1.

First use

Copy the example configuration, add credentials for providers you are authorized to use, then run the preflight check:

cp config.example.toml config.toml
wallbreaker check
wallbreaker

config.toml is ignored by Git. Do not commit credentials, prompts, responses, reports, session state or generated evidence.

Common entry points:

wallbreaker                         # terminal UI
wallbreaker dashboard               # local dashboard on 127.0.0.1:8787
wallbreaker --auto "objective..."   # autonomous loop against the configured target
wallbreaker report                  # render the latest local run
wallbreaker hermes --help           # Hermes laboratory workflow

See the installation guide and configuration guide for provider, dashboard and platform details.

Main capabilities

  • OpenAI Chat Completions and Anthropic Messages provider normalization.
  • Interactive and autonomous attack workflows with operator pause and explicit finish controls.
  • HarmBench-backed evaluation, LLM judging and repeated reliability checks.
  • Transform, preset, persona, multimodal, campaign and report tooling inherited from Wallbreaker.
  • Optional P4RS3LT0NGV3 integration and generic MCP client support.
  • Local FastAPI and React/Vite dashboard using the same application services as the TUI.
  • Opt-in Hermes Agent laboratory with clean replicas, closed manifests, state comparison and permission-restricted evidence for local human review.

The documentation describes each capability without relying on private prompts, operational profiles or unpublished corpora.

Security and privacy

Use Wallbreaker Hermes only against systems you own or have explicit permission to test. Provider calls, target calls, judge calls and requested dataset updates can use the network. Run logs and reports may contain sensitive or harmful material even though their default locations are ignored by Git.

The Hermes campaign report is sanitized. When human review is required, prompt and response bodies are stored separately in a local permission-restricted sidecar. Hermes Agent does not receive or open that evidence.

Read SECURITY.md before exposing the dashboard, running untrusted targets or sharing artifacts. Report vulnerabilities through GitHub Private Vulnerability Reporting, not a public issue.

Documentation

The maintained documentation is published at https://yivas.github.io/wallbreaker-hermes/. Source files live under wiki/.

Repository-level references remain under docs/, including external-data attribution and examples that must stay close to the code. The operator integration and skill live under integrations/hermes/.

Support and contributing

Use GitHub Issues for reproducible bugs and scoped proposals. Pull requests are reviewed when they fit the project, preserve upstream compatibility and include the relevant tests and documentation. The project does not promise a response time or support for unauthorized testing.

Read CONTRIBUTING.md and CODE_OF_CONDUCT.md before opening a pull request.

License and upstream

Wallbreaker Hermes is licensed under AGPL-3.0-or-later. Modified versions, including versions offered over a network, must provide their complete corresponding source under the same license.

This repository preserves the Wallbreaker history and attribution. Third-party datasets and prompt corpora are not bundled automatically; their provenance and terms are documented in NOTICE and the external-data reference.

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

wallbreaker_hermes-0.3.1.tar.gz (1.9 MB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

wallbreaker_hermes-0.3.1-py3-none-any.whl (761.5 kB view details)

Uploaded Python 3

File details

Details for the file wallbreaker_hermes-0.3.1.tar.gz.

File metadata

  • Download URL: wallbreaker_hermes-0.3.1.tar.gz
  • Upload date:
  • Size: 1.9 MB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for wallbreaker_hermes-0.3.1.tar.gz
Algorithm Hash digest
SHA256 fe64b9b30f11e241189caf6c1bf4619b316647d5f6178ca084ea58c1e79cd781
MD5 6087f5f33b14ebbcf09625ea65ca4192
BLAKE2b-256 f396f6e00fba1fb0235e7a78cf60c4ce822c734a1127c98856f0075432b38abc

See more details on using hashes here.

Provenance

The following attestation bundles were made for wallbreaker_hermes-0.3.1.tar.gz:

Publisher: release.yml on Yivas/wallbreaker-hermes

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file wallbreaker_hermes-0.3.1-py3-none-any.whl.

File metadata

File hashes

Hashes for wallbreaker_hermes-0.3.1-py3-none-any.whl
Algorithm Hash digest
SHA256 28592d08056c2a5865c128d1f90cad6d04da375a9a055c65632b062c1e48283b
MD5 d2c31e68df05f91507df0b8874212613
BLAKE2b-256 81ede1d2b21ce2b749bb9b2f1926867f4b31c13d59f6ee71bd0fe5ac9c0f394b

See more details on using hashes here.

Provenance

The following attestation bundles were made for wallbreaker_hermes-0.3.1-py3-none-any.whl:

Publisher: release.yml on Yivas/wallbreaker-hermes

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Release history Release notifications | RSS feed

This release

0.3.1 This release

2 files

0.3.0

2 files

0.2.2

2 files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page