PluginBench
Skill
Pass
Audit score 90

hermes-imports

affaan-m/ecc

Convert Hermes workflows into sanitized, reusable ECC skills without leaking credentials or private state.

What is hermes-imports?

This skill transforms local Hermes operator workflows into public-safe ECC skills by removing credentials, personal data, and workspace-specific paths. Use it when a repeated workflow is ready to share across teams without exposing private account names, API keys, or local-only references.

  • Converts local paths to repo-relative paths or placeholders
  • Replaces account names and credentials with role labels and provider names
  • Scans for and removes API keys, tokens, OAuth files, and sensitive data
  • Transforms one-off operator instructions into reusable skill documentation
  • Generates sanitized workflow summaries with public inputs and output contracts
  • Identifies remaining risks and files requiring creation or updates

How to install hermes-imports

npx skills add null --skill hermes-imports
Claude Code
Cursor
Windsurf
Cline

How to use hermes-imports

  1. 1.Identify the repeatable operator loop in your Hermes workflow
  2. 2.Strip private inputs, outputs, credentials, and personal data
  3. 3.Rewrite local paths as repo-relative examples or placeholders
  4. 4.Convert one-off instructions into a 'When To Use' section and process steps
  5. 5.Define concrete output requirements and success criteria
  6. 6.Run a secret and local-path scan before committing

Use cases

Good for
  • Publishing a repeated launch workflow as a shareable ECC skill
  • Converting a private content-review process into a public template
  • Preparing engineering or research workflows for team reuse
  • Sanitizing operator handoff documentation before opening a PR
  • Extracting repeatable patterns from local Hermes jobs into documented skills
Who it's for
  • Hermes operators preparing workflows for public reuse
  • Teams standardizing internal processes into shareable skills
  • Engineering leads documenting repeatable workflows
  • Content and launch teams creating handoff documentation

hermes-imports FAQ

What data should never be included in an imported ECC skill?

Do not ship API keys, tokens, OAuth files, phone numbers, private email addresses, client or family names, revenue/health/CRM details, or raw logs from private systems.

How do I handle credentials in an imported workflow?

Describe credential requirements by provider name only (e.g., 'requires GitHub token') rather than including actual credentials or account names.

Can I include local workspace paths in an ECC skill?

No. Convert absolute paths like `/Users/...` to repo-relative paths or placeholders. Avoid `~/.hermes` paths unless explicitly documenting local setup.

When should I keep a workflow local instead of importing it?

If the workflow requires private state, personal datasets, or sensitive account information to make sense, keep it local rather than attempting to sanitize it.

What should the output of an import include?

Return the candidate ECC skill name, sanitized workflow summary, required public inputs, list of private inputs removed, remaining risks, and files to create or update.

Full instructions (SKILL.md)

Source of truth, from affaan-m/ecc.


name: hermes-imports description: Convert local Hermes operator workflows into sanitized ECC skills and release-pack artifacts. Use when preparing a Hermes workflow for public ECC reuse without leaking private workspace state, credentials, or local-only paths. metadata: origin: ECC

Hermes Imports

Use this skill when turning a repeated Hermes workflow into something safe to ship in ECC.

Hermes is the operator shell. ECC is the reusable workflow layer. Imports should move stable patterns from Hermes into ECC without moving private state.

When To Use

  • A Hermes workflow has repeated enough times to become reusable.
  • A local operator prompt should become a public ECC skill.
  • A launch, content, research, or engineering workflow needs sanitized handoff docs.
  • A workflow mentions local paths, credentials, personal datasets, or private account names that must be removed before publication.

Import Rules

  • Convert local paths to repo-relative paths or placeholders.
  • Replace live account names with role labels such as operator, default profile, or workspace owner.
  • Describe credential requirements by provider name only.
  • Keep examples narrow and operational.
  • Do not ship raw workspace exports, tokens, OAuth files, health data, CRM data, or finance data.
  • If the workflow requires private state to make sense, keep it local.

Sanitization Checklist

Before committing an imported workflow, scan for:

  • absolute paths such as /Users/...
  • ~/.hermes paths unless the doc is explicitly explaining local setup
  • API keys, tokens, cookies, OAuth files, or bearer strings
  • phone numbers, private email addresses, and personal contact graphs
  • client names, family names, or account names that are not already public
  • revenue, health, or CRM details
  • raw logs that include tool output from private systems

Conversion Pattern

  1. Identify the repeatable operator loop.
  2. Strip private inputs and outputs.
  3. Rewrite local paths as repo-relative examples.
  4. Turn one-off instructions into a When To Use section and a short process.
  5. Add concrete output requirements.
  6. Run a secret and local-path scan before opening a PR.

Example: Launch Handoff

Local Hermes prompt:

Read my local workspace files and finalize launch copy.

ECC-safe version:

Use the public release pack under docs/releases/<version>/.
Return one X thread, one LinkedIn post, one recording checklist, and the missing assets list.

Example: Quiet-Hours Operator Job

Local Hermes job:

Run my private inbox, finance, and content checks overnight.

ECC-safe version:

Describe the scheduler policy, the quiet-hours window, the escalation rules, and the categories of checks. Do not include private data sources or credentials.

Output Contract

Return:

  • candidate ECC skill name
  • sanitized workflow summary
  • required public inputs
  • private inputs removed
  • remaining risks
  • files that should be created or updated