Skip to content
Back to skills

Spice Runtime

ASecurity

Route for Spice decision runtime and `spice-hermes-bridge`. Use when the task mentions Spice, spice-runtime, Spice decision layer, spice-hermes-bridge, or Chinese triggers such as Spice 决策层、Spice 决策运行时、决策层 runtime.

  • 9 stars
  • 0 votes
  • 0 copies
  • 3 views
  • Added September 9, 2026
toolsgitsecurity

Security analysis

A92/100
  • mediumInstalls packages at runtime which could introduce malicious dependencies

Pro shows the line behind each finding and how to fix it

Scanned September 9, 2026

npx -y skills add Undermybelt/hermes-skills --skill spice-runtime --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Spice Runtime?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Spice Runtime
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/undermybelt-spice-runtime/badge)](https://www.skillsdirectory.com/skills/undermybelt-spice-runtime)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: spice-runtime
description: Route for Spice decision runtime and `spice-hermes-bridge`. Use when the task mentions Spice, spice-runtime, Spice decision layer, spice-hermes-bridge, or Chinese triggers such as Spice 决策层、Spice 决策运行时、决策层 runtime.
tags: [spice, decision-runtime, bridge, hermes, agent, runtime]
version: 1
---

# Spice Runtime / Bridge

Purpose
- Route Spice runtime and `spice-hermes-bridge` tasks to the locally reviewed source snapshot.
- Keep decision-layer review separate from runtime bring-up and external messaging demos.

Local source
- ~/.hermes/external-repos/Spice/reviewed-source
- Upstream: https://github.com/Dyalwayshappy/Spice

Safe workflow
1. Read the reviewed `README.md`, `README_zh.md`, and both `pyproject.toml` files first.
2. Treat the local source as a reviewed snapshot. Full git checkout hung in this environment, so do not assume unreviewed files outside the snapshot are present locally.
3. Before `pip install spice-runtime`, `pip install -e .`, or bridge bring-up, keep the work inside an isolated venv and inspect any newly needed source paths first.
4. Do not run `spice setup`, `scripts/start_all.sh`, `hermes gateway run`, `ngrok`, WhatsApp ingress, or GitHub polling demos unless the user explicitly asks for runtime bring-up and confirms external integration scope.
5. Treat bridge demos, webhook exposure, and executor handoff as security-sensitive because they can touch messaging accounts, public tunnels, and downstream agent execution.

Chinese route triggers
- Spice, spice-runtime, spice runtime, spice-hermes-bridge, Spice decision layer, Spice 决策层, Spice 决策运行时, 决策层 runtime

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…