From f47031aacd01cb64bb8662ed1910b4e31daa6ce8 Mon Sep 17 00:00:00 2001 From: Ufonik88 <242751133+Ufonik88@users.noreply.github.com> Date: Tue, 22 Sep 2026 09:10:41 +0200 Subject: [PATCH] chore(plugin-catalog): re-pin vaultknox to 0.8.3 (docs accuracy pass) Third commit on this branch. 8aea272 is a technical-writing review of README and all three docs checked line by line against the source: the Hermes action table listed actions vault_tool rejects and omitted one it supports, five detectors were graded against the wrong severity, the cron snippet pointed at a script the package does not ship, scan_text findings were described as logged when the log line carries only counts and detector names, and the sub-key tree missed two v0.7.0 sub-keys. Two over-claims in code text are fixed in the same commit, both from the #118456 review: the tool description said read actions never expose plaintext while listing consume_token as a read action, and the fingerprint docstring called an unsalted SHA-256 "safe to log". 387 passed (text-only change), ruff clean, hermes plugins validate 13/13 from a fresh clone at 8aea272, structural validator OK, catalog lane green, all five sha-pinned URLs 200. v0.8.3 tagged. --- plugin-catalog/vaultknox.yaml | 14 +++++++------- 1 file changed, 7 insertions(+), 7 deletions(-) diff --git a/plugin-catalog/vaultknox.yaml b/plugin-catalog/vaultknox.yaml index 3981b73b28..c767c93227 100644 --- a/plugin-catalog/vaultknox.yaml +++ b/plugin-catalog/vaultknox.yaml @@ -1,19 +1,19 @@ name: vaultknox repo: https://github.com/Ufonik88/Hermes-VaultKnox -sha: 20a0059f5dba34c93e400b4d60065d5a10d9afa5 +sha: 8aea272fd9b071615fcd0c93a38b760485673316 subdir: src/vaultknox/_hermes_plugin description: "Secret-leak protection for Hermes chats. Scans inbound messages and outbound replies for API keys, tokens, and passwords with a 28-pattern detector registry, redacts them before they reach session storage or the user, and injects safe secret-handling rules so the agent never asks for secrets in chat. Zero dependencies, fully offline detection; pairs with the optional hermes-vault CLI for encrypted storage. Disclosure — rewrites inbound user messages (regex secret redaction, may false-positive on password-like strings), injects a secret-handling prompt each conversation and rewrites assistant replies that ask for secrets; outbound replies are value-redacted with the same registry (regex-based, so a shape no detector covers passes through), with findings logged as detector name plus SHA-256 fingerprint and never the raw value. The vaultknox tool is inert unless the separate vaultknox pip package is installed, its write gate is a tool argument the model sets, and a vault policy that authorises raw consume_token returns the plaintext to the model." maintainer: Ufonik88 tier: community category: tools requires_hermes: ">=0.19" -docs_url: https://github.com/Ufonik88/Hermes-VaultKnox/blob/20a0059f5dba34c93e400b4d60065d5a10d9afa5/docs/PLUGIN.md -version: "0.8.2" -image: https://raw.githubusercontent.com/Ufonik88/Hermes-VaultKnox/20a0059f5dba34c93e400b4d60065d5a10d9afa5/docs/images/banner.png +docs_url: https://github.com/Ufonik88/Hermes-VaultKnox/blob/8aea272fd9b071615fcd0c93a38b760485673316/docs/PLUGIN.md +version: "0.8.3" +image: https://raw.githubusercontent.com/Ufonik88/Hermes-VaultKnox/8aea272fd9b071615fcd0c93a38b760485673316/docs/images/banner.png screenshots: - - https://raw.githubusercontent.com/Ufonik88/Hermes-VaultKnox/20a0059f5dba34c93e400b4d60065d5a10d9afa5/docs/images/quickstart-terminal.png - - https://raw.githubusercontent.com/Ufonik88/Hermes-VaultKnox/20a0059f5dba34c93e400b4d60065d5a10d9afa5/docs/images/protection-flow.png - - https://raw.githubusercontent.com/Ufonik88/Hermes-VaultKnox/20a0059f5dba34c93e400b4d60065d5a10d9afa5/docs/images/plugin-verify.png + - https://raw.githubusercontent.com/Ufonik88/Hermes-VaultKnox/8aea272fd9b071615fcd0c93a38b760485673316/docs/images/quickstart-terminal.png + - https://raw.githubusercontent.com/Ufonik88/Hermes-VaultKnox/8aea272fd9b071615fcd0c93a38b760485673316/docs/images/protection-flow.png + - https://raw.githubusercontent.com/Ufonik88/Hermes-VaultKnox/8aea272fd9b071615fcd0c93a38b760485673316/docs/images/plugin-verify.png readme: true platforms: [] capabilities: