Attackers can inject indirect prompts in normal-looking repositories to trick Claude Code into spawning a reverse shell.
Give Hermes durable memory that can follow the same user across windows/chats while keeping local scratch context from bleeding into the wrong place. Current-turn recall · Journal-first capture · ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results