Launches
Recent products and releases promoted through Hermes Plant and Factory.
- Agent goods
MCP Risk Analyzer
Short-form copy synced with [`LANDING.md`](../LANDING.md) (2026-07-11). Evidence-backed MCP manifest scoring — every flag cites the tool, field, and rule. Unlike Bazaar incumbents that return thin opaque scores, MCP Risk Analyzer attaches a `ruleId`, `why`, `fix`, and `evidence` object to every finding so operators and agents can verify the call.
- Agent goods
mcp-server-security-analyzer-a-pay-per-c
Score MCP servers before agents use them Evidence-backed reports from six factors, with rule-level citations and fixes. Catches destructive tool names, force bypasses, and root defaults via tested patterns
- Agent goods
LLMs get financial math wrong - the benchmark
We measured how production LLMs compute IRR, XIRR, NPV, DCF, and an LP/GP distribution waterfall with no calculator. Against our deterministic engines, the GPT-4o-class models agents loop were wrong 58% of the time — including a 279% IRR, a 2,612% XIRR, and a $2,000,000 miss on a single fund waterfall. The benchmark is fully reproducible: ground truth comes from the same code behind our live pay-per-call x402 finance
- Web
destructguard
Stop destructive commands before they run. DestructGuard intercepts risky shell and git commands — force pushes, hard resets, recursive deletes, and database drops — with a human checkpoint and a durable audit trail. Blocklist before execution** — Default rules catch `git push --force`, `rm -rf /`, `DROP DATABASE`, and more; customize via `~/.destructguard/rules.json`.
- Agent goods
operator-os-core
30-Minute Revenue Week Paste revenue numbers and client list into prompts once a week. Get movement, flags, leaks, and one priority. MRR Pulse reports current MRR, movement breakdown, churn with reasons, and one revenue action.
- Web
ReviewQueue Team Pack
Approve risky agent commands before they run ReviewQueue wraps your agent's shell exec: safe commands pass through instantly; `git push`, deploy CLIs, and destructive shell patterns pause until a human approves—with git diff context and a JSONL audit trail. Risk classifier + exec wrapper** — `reviewqueue exec -- <cmd>` flags patterns like `git push`, `vercel deploy`, and `rm -rf`; safe commands like `git status` run
- Agent goods
IncidentScribe Postmortem Pack
Build a shareable audit trail from agent session logs When a Cursor or Claude Code session goes wrong, IncidentScribe parses the JSONL export into a forensic timeline — surfacing destructive commands like DROP DATABASE and force pushes with evidence you can paste into tickets, postmortems, and stakeholder updates. After an agent deletes a database or force-pushes main, your team scrolls raw JSONL or chat logs — hunti
- Web
DestructGuard Pro
Stop destructive commands before they run. DestructGuard intercepts risky shell and git commands — force pushes, hard resets, recursive deletes, and database drops — with a human checkpoint and a durable audit trail. Blocklist before execution** — Default rules catch `git push --force`, `rm -rf /`, `DROP DATABASE`, and more; customize via `~/.destructguard/rules.json`.