Skip to main content

ocas-vesper

Generates concise daily briefings by aggregating signals and outcomes, enhancing decision-making without exposing internal processes.

Install this skill

or
85/100

Security score

The ocas-vesper skill was audited on Oct 4, 2026 and we found 3 security issues across 1 threat category. Review the findings below before installing.

Categories Tested

Security Issues

medium line 224

Access to home directory dotfiles

SourceSKILL.md
222**Procedure**: See `references/update-procedure.md` for the full update workflow including conflict resolution and profile sync. Key points:
223- If local modifications block `git pull`: stash, move conflicting untracked files, pull, stash pop, resolve conflicts
224- After pulling: sync the profile copy (`~/.hermes/profiles/indigo/skills/ocas-vesper/`) — sessions load from there, not the git repo
225
226## Visibility
medium line 270

Access to home directory dotfiles

SourceSKILL.md
268| `references/jsonl-debug.md` | When briefings.jsonl has corrupted entries — diagnosis and repair of bracket mismatches |
269| `scripts/dup_guard.py` | **First thing in every generator run.** Exit 3 = today's briefing for this type already generated and delivered; skip generation and re-delivery. Guards against the cron double-fire that resets the delivered flag and emails a duplicate. |
270| `scripts/quality_check.py` | After generating a briefing file — automated validation. Run with absolute path: `python3 ~/.hermes/profiles/indigo/skills/ocas-vesper/scripts/quality_check.py <briefing.json>`. Returns `PASS` or `FAIL` with specific terms/sctions that need fixing. |
271| `references/delivery-channel.md` | **Before touching delivery** — briefings are EMAIL ONLY, never Telegram. Read the code, not the docstring. |
272| `scripts/delivery_check.py` | During delivery-check cron runs — scans individual files + `briefings.jsonl` for undelivered briefings (applies the dual delivery-flag/desync rules), and with `--deliver` sends by email, then updates both records with a surgical line edit (preserves corrupted sibling JSONL lines byte-for-byte). Run `python3 ~/.hermes/profiles/indigo/skills/ocas-vesper/scripts/delivery_check.py --type morning --deliver`. |
medium line 272

Access to home directory dotfiles

SourceSKILL.md
270| `scripts/quality_check.py` | After generating a briefing file — automated validation. Run with absolute path: `python3 ~/.hermes/profiles/indigo/skills/ocas-vesper/scripts/quality_check.py <briefing.json>`. Returns `PASS` or `FAIL` with specific terms/sctions that need fixing. |
271| `references/delivery-channel.md` | **Before touching delivery** — briefings are EMAIL ONLY, never Telegram. Read the code, not the docstring. |
272| `scripts/delivery_check.py` | During delivery-check cron runs — scans individual files + `briefings.jsonl` for undelivered briefings (applies the dual delivery-flag/desync rules), and with `--deliver` sends by email, then updates both records with a surgical line edit (preserves corrupted sibling JSONL lines byte-for-byte). Run `python3 ~/.hermes/profiles/indigo/skills/ocas-vesper/scripts/delivery_check.py --type morning --deliver`. |
273
274## Support Files
Scanned on Oct 4, 2026
View Security Dashboard