Violin is a supervised, agentic profile for the Hermes Agent designed to orchestrate authorized penetration tests from reconnaissance through safe exploit validation to final reporting. It functions as a senior pentester persona, utilizing a structured methodology to track tasks and findings while enforcing strict scope boundaries through a custom execution guard.
Key Features
- 31 methodology-driven playbooks covering 24 vulnerability classes and 7 operational phases.
- Multi-layered safety model with interactive scoping, approval gates, and AST-based command validation.
- Integrated Pentesting Task Tree (PTT) for structured artifact tracking and hypothesis linking.
- Built-in support for Kali Linux and Parrot OS toolsets, including a Dockerized Kali fallback.
- Automated evidence compilation including screenshots, tool output, and CVSS 3.1/4.0 scoring.
- Native Hermes integration requiring no additional API keys or external credential stores.
Use Cases
- Automating initial reconnaissance and passive OSINT for authorized attack surface analysis.
- Validating vulnerability hypotheses through safe, non-destructive proof-of-concept execution.
- Standardizing red team workflows to ensure consistent evidence collection and methodology adherence.
- Accelerating the reporting phase by automatically generating finding summaries and remediation patches.




