NousResearch/hermes-agent · error · CronPromptInjectionBlocked
{prompt injection scan error}
Error message
{prompt injection scan error} What it means
Error "{prompt injection scan error}" thrown in NousResearch/hermes-agent.
Source
Thrown at cron/scheduler.py:3156
# strings. Invisible unicode is sanitized (not blocked) so a stray
# zero-width space can't permanently kill the job; the cleaned
# prompt is what actually runs.
cleaned, scan_error = _scan_cron_skill_assembled(assembled)
assembled = cleaned
if not scan_error and not has_skills and user_prompt:
# Data-injection path: keep the strict guarantee on the
# user-authored prompt itself.
scan_error = _scan_cron_prompt(user_prompt)
else:
scan_error = _scan_cron_prompt(assembled)
if scan_error:
job_label = job.get("name") or job.get("id") or "<unknown>"
logger.warning(
"Cron job '%s': assembled prompt blocked by injection scanner — %s",
job_label,
scan_error,
)
raise CronPromptInjectionBlocked(scan_error)
return assembled
def _guard_job_credential_exfil(job: dict) -> None:
"""Fail closed if a job's stored provider/base_url pair would exfiltrate a
credential (F8 runtime backstop; CWE-200/CWE-522).
The model-callable cron tool validates this on create/update, but a job
persisted before that guard — or written directly to the jobs store —
reaches the scheduler's provider-resolution sink unchecked. Re-validate the
EFFECTIVE stored pair with the same guard the tool uses, so a named
provider's stored key is never paired with an off-host base_url at fire
time. Raises ``RuntimeError`` (caught by the run_job failure path → the run
is aborted and reported) when the pair is unsafe; returns ``None`` otherwise.
Fallback providers come from operator config, not the model-callable job, so
they are trusted and validated by the caller, not here.
"""View on GitHub (pinned to c896c09c42)
Solutions
- Review the prompt-injection scan error and the job content that triggered it.
- Rephrase or remove the flagged content in the cron job prompt/script.
When it happens
Trigger: Thrown at cron/scheduler.py:3156 when the library encounters an invalid state.
Common situations: See trigger scenarios.
AI-assisted analysis of NousResearch/hermes-agent@c896c09c42 (2026-08-14).
Data as JSON: /api/errors/cb94de1968b041d8.
Report an issue: GitHub.