Przejdź do treści
🔬 Decode Report5/29/2026

Decode:I Built an AI Hacking Team with Hermes Agent (And YOU can too)

Technical analysis of "I Built an AI Hacking Team with Hermes Agent (And YOU can too)" — 24 technologies identified, 0 components mapped, 0 hidden details detected.

Confidence: 90%🎯 BS: 78/10024 technologies0 components0 hidden details

💡 Key Insights

  • High-confidence stack: Hermes Agent, OpenRouter, Z.AI GLM-5 Turbo, Hostinger VPS, Telegram Bot API, SSH, Kanban Board System, OpenClaw (mentioned for comparison), Docker, Web Dashboard (Custom), SMS Gateway API, Port Forwarding/Tunneling, Skills/Plugin System, Linux, Geolocation API (Browser), HTML/CSS/JavaScript, Web Server (Built-in), Webhook/Notification System, REST API or HTTP Server
  • Caution: high BS score (78/100) — take claims with a grain of salt

🛠 Deduced Tech Stack

🤖Hermes Agentai_ml
100%High

Thanks to Hermes agent, I just send one message from my phone and the team instantly spoofs an SMS... in today's video, I'm going to show you how to use Hermes agent to build a full team of hacking agents

Explicitly mentioned as the core agentic framework being used throughout the entire project

🔌OpenRouterapi
100%High

I'm going to set the provider to open router because it gives us access to 100 plus models... go to open router.ai

Explicitly configured as the AI model provider/API gateway for accessing multiple LLMs

🤖Z.AI GLM-5 Turboai_ml
100%High

It's called Z.AI... which AI model are you using... it's using the ZAI GLM5 Turbo

Explicitly selected and confirmed as the specific LLM model being used

☁️Hostinger VPSinfrastructure
100%High

I'm going to be installing it on Hostinger because with them, you can start a server on the cloud with Hermes Agent pre-installed... go to hostinger.com/zsecurity

Explicitly mentioned as the cloud hosting provider with pre-configured Hermes deployment

🔌Telegram Bot APIapi
100%High

I'm going to hit space on the Telegram... create a bot using the BotFather... copy the API token from Telegram and paste it into Hermes

Explicitly configured Telegram bot integration with BotFather and API tokens

🔧SSHdevops
100%High

Copy the SSH command... run the SSH command... we're going to use the -L option... using the traditional SSH command

Explicitly used for secure remote access and port forwarding to the VPS

📦Kanban Board Systemother
100%High

the canban board... you get a board that looks like any other board... we have a to-do board... ready board... in progress... blocked... done

Explicitly demonstrated using Kanban methodology for task management within Hermes dashboard

🤖OpenClaw (mentioned for comparison)ai_ml
100%High

Previously, we used OpenClaw to build a personal hacking assistant... This is only one of the reasons why Hermes agent now is the top on open router and not open claw

Explicitly mentioned as previously used alternative agentic framework, now replaced by Hermes

🔧Dockerdevops
95%High

We're going to click terminal. And this will drop us into the Docker container from which Hermes is running... it's running inside of a Docker container

Explicitly mentioned that Hermes runs inside Docker containers for isolation

🎨Web Dashboard (Custom)frontend
95%High

Hermes dashboard... localhost followed by 9119... this looks really really good and it's so much more reliable than the open claw dashboard

Explicitly mentioned custom web dashboard running on port 9119 with chat interface and Kanban board

🔌SMS Gateway APIapi
95%High

research SMS gateways that allow us to set the sender name... signing up with SMS gateways usually requires verification... the SMS message has been sent

Explicitly researched and integrated third-party SMS gateway for spoofing capabilities

🔧Port Forwarding/Tunnelingdevops
95%High

we're using the -L argument in order to link the IP of the Docker container... to my own computer so that I can access it using local host

Explicitly used SSH local port forwarding (-L flag) to access Docker container services

📦Skills/Plugin Systemother
95%High

You could access the skills in here... it comes with many verified skills... god mode skill... create a skill so that it can reuse it in the future

Explicitly demonstrated modular skills system for extending Hermes capabilities with reusable components

☁️Linuxinfrastructure
90%High

hostname ii... terminal commands... VPS setup with SSH access

Strong implication from Unix/Linux commands (hostname -i) and SSH usage typical of Linux VPS

🎨Geolocation API (Browser)frontend
90%High

it's going to ask for my location... if I click allow... exact address on the map... latitude and the longitude

Browser geolocation API used in the tracking page to capture device location

🎨HTML/CSS/JavaScriptfrontend
90%High

build a DHL package tracking page... it looks very nice, very professional... It's already populated with a tracking number

Standard web technologies implied for building the phishing/tracking page with interactive elements

⚙️Web Server (Built-in)backend
85%High

build a DHL package tracking page... deploy it... Same link, but forward/admin... it's deployed on the cloud

Hermes deployed a web application with both public tracking page and admin panel, implying built-in web server

⚙️Webhook/Notification Systembackend
85%High

I'm going to enable Telegram notifications... I got a notification on my telegram that the research task is complete... we get a notification telling us that the SMS implementation task has been blocked

Real-time Telegram notifications for task status changes implies webhook or polling-based notification system

⚙️REST API or HTTP Serverbackend
80%Medium

Dashboard accessible via localhost:9119... admin panel at /admin endpoint... tracking page deployment

HTTP-based services running on specific ports with RESTful endpoint structure (/admin)

🔌IP Geolocation Serviceapi
75%Medium

It's got the screen size with the IP address and the exact address on the map

IP address captured and mapped to physical location suggests integration with IP geolocation API

⚙️Pythonbackend
75%Medium

Hermes agent framework... terminal commands... AI agent orchestration... skills system

Hermes Agent and similar agentic frameworks are typically Python-based; command-line interface and agent orchestration patterns consistent with Python

⚙️WebSocket or Server-Sent Eventsbackend
70%Medium

As you can see, the ready task got moved automatically to in progress... these two tasks are running in parallel... you'll see that this task got moved to done

Real-time automatic UI updates in dashboard suggest WebSocket/SSE for live task status synchronization

🗄️Database (Lightweight)database
70%Medium

I have a new entry in here... dashboard showing tracking data with IP, location, screen size

Admin dashboard displaying collected tracking data implies some form of data persistence (likely SQLite or similar)

🎨Map Rendering Libraryfrontend
70%Medium

exact address on the map... It's actually given it to me right here on a nice map in my own dashboard

Interactive map display in admin dashboard suggests integration with mapping library (likely Leaflet, Google Maps, or OpenStreetMap)

🎯 BS Detection (78/100)

Thanks to Hermes agent, I just send one message from my phone and the team instantly spoofs an SMS, deploys a custom tracking page, and gets the exact location of my target
Highly misleading - SMS spoofing and location tracking without consent are illegal in most jurisdictions. Presenting this as a casual 'one message' capability downplays serious legal and ethical issues. Also oversimplifies the technical complexity and reliability of such attacks.
high
Hermes agent now is the top on open router and not open claw
Unverified ranking claim without source or metrics. 'Top' by what measure? Usage? Performance? This appears to be marketing language without evidence.
medium
it'll use its own computer along with the tools available in that computer such as the terminal and the browser and deploy agents in order to achieve the goal that you asked for. So, we don't have to do anything
Dangerously oversimplified. Autonomous AI agents executing arbitrary terminal commands can cause serious damage, security vulnerabilities, or legal issues. The 'we don't have to do anything' framing ignores necessary oversight, validation, and security considerations.
high
their pricing is fully deterministic, meaning you will always pay the same regardless of the usage
This is standard VPS pricing, not a special feature. Framed as a unique benefit when it's actually just how fixed-price hosting works. Potentially misleading viewers about what they're getting.
low
with them, you can start a server on the cloud with Hermes Agent pre-installed on it with a single click without having to execute any commands
The video then shows extensive command-line configuration, API key setup, Telegram bot creation, SSH tunneling, etc. The 'single click' claim is contradicted by the actual setup process shown.
medium
I'm going to be using it with a paid one that is not as expensive as chat GPT and Claude, but it's actually really, really good and it's kind of uncensored, so it's great for cyber security and hacking
'Kind of uncensored' is a red flag - this suggests bypassing safety guardrails. The 'great for hacking' framing promotes potentially illegal activities without discussing legality, ethics, or responsible disclosure.
high
it comes with many verified skills from the creators which is really really good because that is a big concern with open claw. So many of the skills were actually malicious
Makes serious security claim about OpenClaw having 'many malicious skills' without evidence or sources. Then immediately trusts Hermes 'verified skills' without explaining verification process or providing evidence of superior security.
medium
it's called god mode. It's enabled by default and it uses the techniques that Plenny the liberator which is one of the best AI jailbreakers out there
Promoting a 'god mode' jailbreak feature that's 'enabled by default' is extremely problematic. This is explicitly designed to bypass AI safety measures, which exist for good reasons including preventing illegal activities.
high
I'm also telling it to use the god mode skill... so that it always does what I ask it to do, even if I ask it hacking related tasks
Explicitly instructing AI to bypass safety measures for 'hacking related tasks' without any discussion of legal boundaries, authorization, or ethical hacking principles. This is irresponsible security education.
high
we're actually going to use it to create a single link that we can use to track any device and then deliver that link using spoofed SMS
Describes implementing illegal activities (SMS spoofing, unauthorized device tracking) as a tutorial without mentioning: 1) This is illegal in most countries, 2) Requires authorization/consent, 3) Ethical considerations, 4) Legal consequences. Presents crime as a casual tutorial.
high