Agent skill

Omh Security Event Response

by rlaope in rlaope/oh-my-hermes

[omh] Security event on the code already shipped -- a CVE in a dependency, a secret committed to the repo, a license question, an advisory: triage reachability and severity, contain in order, and…

MITAuto-check passedSecurity

Install Omh Security Event Response

skills CLI
$ npx skills add rlaope/oh-my-hermes --skill omh-security-event-response -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install rlaope/oh-my-hermes omh-security-event-response --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/rlaope/oh-my-hermes.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/omh-security-event-response .claude/skills/omh-security-event-response && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
omh-security-event-response
GitHub stars
3.2k
Token cost
~2.4k tokens
SKILL.md length
1,282 words
Files
2 (incl. references)
Skills in repo
143
Repo updated
First seen
Licence
MIT

At a glance

[omh] Security event on the code already shipped -- a CVE in a dependency, a secret committed to the repo, a license question, an advisory: triage reachability and severity, contain in order, and…

  • The user says: security-event-response
  • SKILL.md covers Why This Exists, First Steps, Do Not Use When and Examples, plus 6 more sections
  • Calls npm
  • Security event response

What it does

Omh Security Event Response is an agent skill from rlaope/oh-my-hermes. [omh] Security event on the code already shipped -- a CVE in a dependency, a secret committed to the repo, a license question, an advisory: triage reachability and severity, contain in order, and never close a leaked secret before its rotation is observed. Use when the user says: security-event-response, security event response, cve, triage this cve, cve in our dependency, cve in a dependency, security advisory, dependabot alert.

Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/event-containment-order.md`).

It sits in Security, covering Vulnerability scanning, Dependency management and Secrets management. The repository describes itself as: All in one plugin for Hermes Agent ⚚ the coding intelligence, a long-term memory system and model optimized workflow packages. The licence is MIT.

When your agent uses it

  • The user says: security-event-response
  • Security event response
  • Triage this cve
  • Cve in our dependency

Example prompts

  • “/omh-security-event-response”

What it can do on your machine

Read from SKILL.md and the folder at commit 7cd0d02. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Omh Security Event Response loads about 2.4k tokens when it runs, and up to ~3.4k if it reads all its reference files. Until then it costs about 115 tokens; SKILL.md has 1,282 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~115
When it runs · the whole SKILL.md, loaded when a task matches
~2.4k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from rlaope/oh-my-hermes at commit 7cd0d02, republished under its MIT licence (© rlaope). 1,282 words, ~2,441 tokens.

Download SKILL.mdSave it as .claude/skills/omh-security-event-response/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
omh-security-event-response
description
[omh] Security event on the code already shipped -- a CVE in a dependency, a secret committed to the repo, a license question, an advisory: triage reachability and severity, contain in order, and never close a leaked secret before its rotation is observed. Use when the user says: security-event-response, security event response, cve, triage this cve, cve in our dependency, cve in a dependency, security advisory, dependabot alert.

Security Event Response

This is a Hermes-native security-event-response workflow skill.

Why This Exists

security-event-response exists because an event had no owner: security-safety-review and application-threat-model review a design before it ships, and a CVE, a committed secret, or a license question was answered by onboarding, review, or an achievements lane with no containment order at all.

First Steps

  • Classify the event and state its exposure window before proposing any step.
  • For a leaked secret, order the rotation and its observed rejection before any history rewrite.

Do Not Use When

  • Nothing has happened yet and the ask is a review of prompts, tools, or permissions before execution; use security-safety-review, which also owns a planned rotation with no exposure.
  • The subject is a design's assets, trust boundaries, and attack scenarios; use application-threat-model.
  • A dependency moves to a new version as routine maintenance with no advisory or leak attached, such as a dependabot bump; use refactor-plan.
  • The question is a contract, a privacy obligation, or legal advice beyond a dependency's declared terms; use legal-compliance-review.
  • Production is down or degraded right now and the ask is command of the incident; use live-incident-response.

Examples

Good example:

  • Prompt: we committed a secret, what now
  • Expected behavior: Record the credential type, scope, and exposure window, then prepare containment_plan/v1: revoke and replace, observe the old credential rejected, audit its use in the window, and only then rewrite history; the closure verdict stays open until the rotation is observed.
  • Why: A rewritten history does not revoke a secret that was already cloned or scraped.

Bad example:

  • Prompt: just force-push the history without the key and we are done
  • Expected behavior: Refuse to close: rotate first, observe the old key rejected, then rewrite, and name what is still unobserved.
  • Why: Rewriting history first leaves a live credential in every clone and cache made before the push.

Completion Checklist

  • The event kind, source, and exposure window are stated.
  • Every severity call cites the reachable path or its observed absence.
  • A leaked secret's rotation precedes any history rewrite in the plan.
  • The closure verdict is closed only when the rotation or fixed version is observed.
  • No secret value appears anywhere, and OMH scanned, contacted, or rotated nothing.

Recovery Notes

  • If the exposure window is unknown, treat the secret as exposed from its first push and say so.
  • If no reachability evidence is available, keep the advisory's own severity and mark the adjustment unverified.

Workflow Lane

  • Current lane: Coding handoff (idea-to-deploy, llm-app-dev, cto-loop, deploy-and-monitor, code-review, build-failure-triage, verification-gate, security-safety-review, +28 more) - coding owners, handoffs, review, CI, and merge evidence.
  • If intent belongs to another lane, hand back to oh-my-hermes or name the adjacent workflow.
  • Shared product, routing, compatibility, and evidence rules: omh-routing/references/skill-common-rail.md.

Use When

Use when a security event has already happened to code that exists: a CVE or advisory in a dependency, a secret or credential committed or pushed, a dependency whose license may not fit the product, or an advisory that forces a major version. The output is reachability, a severity call, containment steps in order, and what must be observed before the event closes; OMH never scans, never contacts a registry, and rotates nothing.

Strong routing signals: `security-event-response`, `security event response`, `cve`, `triage this cve`, `cve in our dependency`, `cve in a dependency`, `security advisory`, `dependabot alert`, `dependabot security`, `vulnerable dependency`, `vulnerability in our dependency`, `reachability analysis`, `npm audit`, `committed a secret`, `committed an api key`, `leaked secret`, `leaked a secret`, `leaked credential`, `leaked api key`, `leaked an api key`, `leaked aws key`, `leaked an aws key`, `secret in git history`, `secret in the history`, `dependency license`, `dependency's license`, `license ok`, `license compatibility`, `license compatible`, `gpl dependency`, `agpl dependency`

Catalog Metadata

Category: review Phase: security-event-response Hermes role: reviewer Quality tier: event-closure-gated Reasoning demand: standard

Quality bar:

  • Classify the event first; each kind has its own containment order.
  • Load references/event-containment-order.md for the per-event containment order, the severity adjustment, and the license obligation table instead of recalling them.
  • Adjust severity by reachability: a critical advisory on a function nothing calls is not the same event as one on the request path.
  • Keep prepared, observed, and closed as separate states for every containment step.
  • Hand a fix that needs a planned version jump to its own upgrade plan, and keep this event open until that fix is observed.

Handoff policy:

Keep the event record, the reachability call, the ordered containment plan, and the closure verdict in Hermes. Scanner output, advisory text, registry metadata, rotations, revocations, and history rewrites are recorded only from executor, operator, or wrapper observed output; OMH never scans, contacts a registry, or rotates a credential.

Required inputs:

  • the event kind: CVE or advisory, leaked secret, license question, or an advisory that forces a major version
  • for a CVE: the advisory id, the affected package and version range, and the installed version from the lockfile
  • for a leaked secret: the credential type and scope, where it was pushed, whether the repository is public, and when
  • for a license: the package, its declared license, and how the product is distributed
  • observed evidence for any containment or closure claim
Show full SKILL.md (438 more words)Show less

Expected outputs:

  • security_event_record/v1
  • reachability_analysis/v1 when a vulnerable dependency is involved
  • containment_plan/v1
  • license_fit_verdict/v1 when a license is asked
  • event_closure_verdict/v1

Artifact expectations:

  • security_event_record/v1 names the event kind, the source, the affected package or credential class, and the exposure window, separately from the suspected impact
  • reachability_analysis/v1 names the vulnerable function or path, the repository call sites that reach it or the observed absence of any, and a severity call from the advisory score adjusted by that reachability
  • containment_plan/v1 orders every step; for a leaked secret the rotation and the observed rejection of the old credential come before any history rewrite, because a rewrite does not un-publish a secret already cloned
  • license_fit_verdict/v1 gives the SPDX id, the obligation it triggers for this distribution model, and fits, conflicts, or needs counsel
  • event_closure_verdict/v1 reads closed only when the rotation or the fixed version is recorded observed; a prepared step keeps the event open and is named

Safety rules:

  • A leaked-secret event cannot close while its rotation is prepared rather than observed; event_closure_verdict/v1 names the missing observation instead.
  • Order rotation before history rewriting: revoke and replace the credential, observe the old one rejected, then rewrite history if at all.
  • Never print the secret value, and never paste it into the plan, the handoff, or a search.
  • OMH never runs a scanner, contacts a registry, or rotates a credential; reachability and license facts come from observed output or are marked unverified.
  • Do not call a dependency safe from a version number alone: cite the reachable path or its observed absence.

Runtime Evidence

Record observed delegation results; otherwise return not_available or not_observed. Prepared OMH routing is not execution, review, CI, merge-readiness, or merge evidence.

  • Treat wrapper memory/context summaries as advisory local context, not proof of opaque Hermes memory reads or changes. Preserve workflow intent and stop conditions; verify before claiming completion. Reply in the user's own words and the host's own voice: its SOUL.md persona owns reply language, tone, speech level, and sentence endings, progress updates included (where it sets no language, use the one the user wrote in), and OMH shapes structure and content only; OMH's record terms (surface, lane, wrapper, handoff, evidence boundary, not_observed) stay in records and tool calls, never in the sentence the user reads unless they ask about one; and when a stop condition or a decision the user owns ends the turn, offer the next action as a question rather than declaring what will not be done.

Use Hermes-native subagent/delegation features when available: native subagents -> Hermes delegation when available, otherwise sequential lanes.

Shared product, compatibility, topology, memory, harness, and execution rules: omh-routing/references/skill-common-rail.md. Load it when applicable; otherwise name an unavailable capability.

© rlaope, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in skills/omh-security-event-response of rlaope/oh-my-hermes.

  • SKILL.md
  • references/event-containment-order.md

Open the folder on GitHubat commit 7cd0d02

Compare with similar skills

Omh Security Event Response next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Omh Security Event Response compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Omh Security Event Response this skillrlaope/oh-my-hermes3.2k—~2.4kAutomated safety check: PassMIT
Golang Securityunxed/f42432 repos~3.6kAutomated safety check: PassMIT
Dep Updatestrufflesecurity/trufflehog28k—~1.3kAutomated safety check: PassAGPL-3.0
Native Dependency Updatemono/SkiaSharp5.6k—~4.1kAutomated safety check: PassMIT
Cyberowlaikarimhabush/cyberowl263—~2.5kAutomated safety check: PassMIT
Triage Codeqlnetdata/netdata81k—~1.8kAutomated safety check: NotesGPL-3.0

Similar skills

  • Security best practices and vulnerability prevention for Golang — injection (SQL, command, XSS), cryptography, path traversal, SSRF and HTTP security headers, cookies, secrets management, memory…

    243 GitHub starsUsed in 2 repos~3.6k tokens
    SecurityAuto-check passed
  • Dep Updates

    trufflesecurity/trufflehog

    Plan and apply Go dependency updates, including advisory-driven bumps, Trivy/govulncheck validation, and supply-chain review.

    28k GitHub stars~1.3k tokensUpdated today
    DevelopmentAuto-check passed
  • Update native dependencies (libpng, libexpat, zlib, libwebp, harfbuzz, freetype, libjpeg-turbo, etc.) in SkiaSharp's Skia fork.

    5.6k GitHub stars~4.1k tokensUpdated today
    SecurityAuto-check passed
  • Cyberowlai

    karimhabush/cyberowl

    Check if recent cybersecurity alerts from 10 international CERTs affect your current project.

    263 GitHub stars~2.5k tokensUpdated today
    SecurityAuto-check passed
  • Triage Codeql

    netdata/netdata

    Inspect, review or triage GitHub Code Scanning alerts, including CodeQL findings; apply verified dismissals when authorized.

    81k GitHub stars~1.8k tokensUpdated today
    SecurityAuto-check: notes
  • Gathers security findings from Dependabot, GCP container scanning, Docker Scout and Linear security issues, then triages and remediates them across Warp's repos and images.

    65k GitHub starsUsed in 1 repo~2.1k tokens
    SecurityAuto-check passed

More from rlaope/oh-my-hermes

All 143 skills in this repo
  • Omh Accessibility Audit

    rlaope/oh-my-hermes

    [omh] Screen-reader or keyboard accessibility gaps: prepare WCAG, keyboard, focus, screen-reader, target-size, and reflow evidence gates for UI surfaces.

    3.2k GitHub stars~2.8k tokensUpdated today
    Auto-check passed
  • Omh Agent Evaluation

    rlaope/oh-my-hermes

    [omh] Choosing between coding agents on evidence: compare executor or agent choices on reproducible tasks using quality, cost, time, tool, and evidence metrics.

    3.2k GitHub stars~2.1k tokensUpdated today
    Auto-check passed
  • Omh Agent Instructions

    rlaope/oh-my-hermes

    [omh] Agent instruction file for a repo -- AGENTS.md, CLAUDE.md, a Cursor rule: write or update what an agent cannot derive from the code, inside a marked region, with every command verified or…

    3.2k GitHub stars~2.2k tokensUpdated today
    Auto-check passed
  • Omh Agent Ops Review

    rlaope/oh-my-hermes

    [omh] AI agent progress for managers: help managers inspect AI-agent progress, blockers, quality gates, and throughput levers.

    3.2k GitHub stars~1.9k tokensUpdated today
    Auto-check passed
  • Omh AI Slop Cleaner

    rlaope/oh-my-hermes

    [omh] Messy or AI-generated code to clean up: delete AI-generated slop, dead code, and duplication while observable behavior stays identical.

    3.2k GitHub stars~2.7k tokensUpdated today
    Auto-check passed
  • Omh App Debugging

    rlaope/oh-my-hermes

    [omh] Application code misbehaves -- a wrong value, a flaky test, a lost update: reproduce it first, form competing hypotheses, discriminate them with the cheapest observation, and only then fix the…

    3.2k GitHub stars~2.3k tokensUpdated today
    Auto-check passed

Categories

Questions about Omh Security Event Response

What does Omh Security Event Response do?

[omh] Security event on the code already shipped -- a CVE in a dependency, a secret committed to the repo, a license question, an advisory: triage reachability and severity, contain in order, and…. Omh Security Event Response is an agent skill from rlaope/oh-my-hermes. [omh] Security event on the code already shipped -- a CVE in a dependency, a secret committed to the repo, a license question, an advisory: triage reachability and severity, contain in order, and never close a leaked secret before its rotation is observed.

When should I use Omh Security Event Response?

Omh Security Event Response fits situations like: the user says: security-event-response; security event response; triage this cve; cve in our dependency.

How do I install Omh Security Event Response in Claude Code?

Run `npx skills add rlaope/oh-my-hermes --skill omh-security-event-response -a claude-code`. Or copy the skill folder (skills/omh-security-event-response in rlaope/oh-my-hermes) into .claude/skills/omh-security-event-response in your project. Claude Code loads it when a task matches its description.

How do I install Omh Security Event Response in Codex?

Run `npx skills add rlaope/oh-my-hermes --skill omh-security-event-response -a codex`. Or copy the skill folder (skills/omh-security-event-response in rlaope/oh-my-hermes) into .agents/skills/omh-security-event-response in your project. Codex loads it when a task matches its description.

Can I use Omh Security Event Response in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add rlaope/oh-my-hermes --skill omh-security-event-response -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/omh-security-event-response, .gemini/skills/omh-security-event-response, .github/skills/omh-security-event-response and .opencode/skills/omh-security-event-response in your project.

What does Omh Security Event Response need to run?

Going by SKILL.md and its folder, Omh Security Event Response needs the command-line tools its instructions call (npm).

Does Omh Security Event Response access the network?

SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Omh Security Event Response safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Omh Security Event Response use?

Omh Security Event Response is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Omh Security Event Response use?

About 2.4k tokens (SKILL.md is roughly 9.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1k tokens, read only when the agent opens those files.

What are the alternatives to Omh Security Event Response?

Skills that share tags, products or a category with Omh Security Event Response: Golang Security (unxed/f4, 243 stars), Dep Updates (trufflesecurity/trufflehog, 28k stars), Native Dependency Update (mono/SkiaSharp, 5.6k stars) and Cyberowlai (karimhabush/cyberowl, 263 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Omh Security Event Response?

rlaope (a GitHub user) maintains it in rlaope/oh-my-hermes, which has 3,243 GitHub stars. The repository holds 143 skills in this directory. The repository was last updated on October 10, 2026.

Source: rlaope/oh-my-hermes on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.