PocketClawvol. 1 · 2026
Safe defaultauto-tracked

Hermes Agent

Post-OpenClaw safe default. Docker-sandboxed by default, multi-LLM, opinionated. The agent we'd hand a colleague today.

GitHub stars
0
Last release
2026.4.4
2026-04-25
CVEs (open / total)
0 / 2
Sandbox default
yes
12-week star trend
+23K stars over 12 weeks

Overview

Hermes shipped in February 2026 with sandbox-on-by-default, explicit network and filesystem allowlists, and a clean approval flow. 1.4 GB Docker image is the main downside. Threat model is publicly documented.

Quick verdict

Best for

  • New self-hosted AI deployments without specific constraints
  • Multi-user environments needing real auth
  • Teams wanting safe-by-default with minimal config

Not for

  • Highly resource-constrained hosts (try Nanobot)
  • Strict no-cloud (use ZeroClaw)
  • Compliance-mandated regulated industries (use IronClaw)

Security posture

Sandbox by defaultyes
Auth on dashboardyes
Threat model documentedyes
Multi-LLM supportyes
CVEs disclosed (lifetime)2
CVEs open right now0

Links

Run Hermes Agent on portable hardware

Verified working on these portable hosts (with the standard caveats — see the per-device pages for power, RAM headroom, browser-tool support):

Raspberry Pi 5
€80–110 · 5–12 W
Intel NUC 13 / Mini PC
€300–600 · 15–55 W
Mac Mini M4 / M4 Pro
€699–2200 · 11–60 W
Framework Laptop 13 / 16
€1100–2200 · 15–80 W
Geekom IT13 / generic Intel mini PC
€450–550 · 20–55 W
Orange Pi 5 Plus
€110–250 · 8–15 W
Mac Studio M3 Ultra
€4,500–7,000 · 30–215 W
MacBook Air M3 / M4
€1,299–2,099 · 10–25 W
Lenovo ThinkCentre M75q (used)
€150–250 used · 15–35 W
Minisforum UM790 Pro
€700–900 · 25–65 W
Khadas Edge2 Pro
€220–280 · 8–15 W
Dell OptiPlex 3070 / 5070 Micro (used)
€100–180 used · 15–35 W
Geekom Mini Air 12
€280–340 · 6–15 W

Compare Hermes Agent with others

Hermes Agent vs OpenClaw
Legacy / migrate
Hermes Agent vs Nanobot
Specialist pick
Hermes Agent vs NanoClaw
Specialist pick

Stats refreshed continuously from public sources (GitHub API, NVD CVE feed, project releases). See our methodology for the full tracking pipeline.