Giving an AI agent security skills instead of coding tasks: a passive recon experiment with Hermes
techlatest_net · reddit · 2026-10-08
Instead of the usual "give the agent a coding task" workflow, the author tested Hermes Agent's official domain-intel skill on a tightly scoped passive-recon task against example.com, covering subdomain discovery via Certificate Transparency, SSL/TLS inspection, WHOIS, DNS, source attribution, and failed-lookup handling.
Notable observations:
- When the first subdomain lookup failed, Hermes recognized the failure, retried, and continued the investigation rather than skipping it.
- The final report separated raw observations from higher-level interpretation.
The author remains cautious about the last mile: how much should we trust an agent's interpretation of security data without independent verification? He invites others to share their approaches to security workflows with AI agents.
More from coding & agent
- User credits Hermes coding agent with promotion, SaaS launch and a new local business — Teknium · 2026-10-08
- Hack: run coding agents in Grok's cloud computer to burn unused Code Plan credits — op7418 · 2026-10-08
- Grok bot surfaces $25,730 in live GitHub bounties, top one pays $10k — prasenx · 2026-10-08
- Talk: how to RL-train an agent running inside a harness you didn't write — SergioPaniego · 2026-10-08
- 8 open-source AI agent tools to know, from computer-use to browser automation — nikola_mr64990 · 2026-10-08
- Test quality follows module design: test larger units instead of banning AI tests — mattpocockuk · 2026-10-08