Hermes Imports
Credit: This skill comes from ECC. Keep this credit in every copy and public release.
Use this skill to turn a repeated Hermes flow into a safe ECC skill.
Hermes is the local tool used by an operator. ECC holds flows that other people can reuse. Move only the steps that work in many places. Do not move private data or local state.
When to Use
Use this skill when:
- A Hermes flow has worked more than once.
- A local prompt should become a public ECC skill.
- A launch, writing, study, or code flow needs a clean handoff.
- A flow has local paths, secret keys, real names, or private account data.
- A flow needs clear inputs, steps, and outputs before it can be shared.
Do not use this skill when:
- The flow only works for one person or one task.
- The flow needs private data to make sense.
- You cannot test the clean version without private access.
- Removing private parts would change the main goal.
Keep those flows local.
Import Rules
- Change local paths to paths inside the repo.
- Use a clear placeholder when no repo path fits.
- Replace real user names with role names, such as
operator,workspace owner, ordefault profile. - Name the service needed for a secret, but never show the secret.
- Use fake names and fake data in all examples.
- Keep each example short and ready to use.
- State each needed input.
- State the exact files or text the skill must return.
- Keep steps that can work in a new workspace.
- Remove steps that depend on hidden local state.
- Keep the ECC credit in the final skill and release notes.
Never publish:
- Raw workspace exports
- API keys, tokens, cookies, or passwords
- OAuth files or login files
- Health records
- CRM records
- Money or income records
- Private contact lists
- Private client or family names
- Raw logs from private tools
Safe Replacements
Use these forms:
| Private value | Safe form |
|---|---|
/Users/alex/work/app |
./app or <repo-root>/app |
~/.hermes/profile.json |
<local-config-file> |
alex@example.com |
<operator-email> |
| A real account name | default profile |
| A real client name | <client-name> |
| An API key | <provider-api-key> |
| Raw private data | A small fake sample |
Do not replace a secret with part of the same secret. Remove the full value.
Clean-Up Steps
- Find the main task that repeats.
- List all inputs, steps, and outputs.
- Mark each item as public, private, or not known.
- Remove private inputs and outputs.
- Replace local paths with repo paths or clear placeholders.
- Replace real names and account names with role names.
- Turn one-time notes into a
When to Usesection and a short process. - Add exact output rules.
- Add one small example with fake data.
- Scan the final files for secrets, private data, and local paths.
- Test the flow with only the public inputs.
- Stop the import if the clean flow cannot work on its own.
If you are not sure whether data is private, treat it as private.
Clean-Up Check
Before you share the skill, check for:
- Full paths, such as
/Users/...,/home/..., orC:\Users\... - Home path forms, such as
~/...,$HOME, or%USERPROFILE% .hermespaths, unless they are clearly shown as local setup- API keys, tokens, cookies, passwords, and Bearer text
- OAuth files, login files, and session files
- Private phone numbers and email addresses
- Real people, clients, family names, and account names
- Health, money, income, sales, or CRM data
- Raw logs from private tools
- Git links to private repos
- Internal host names, IP addresses, and database names
- File details that may hold private data
- Secret values hidden in sample code, test files, links, or images
Check the full release package, not just SKILL.md.
If a match is needed for local setup, explain why it is safe. If you cannot prove it is safe, remove it.
Concrete Example
Local Hermes Prompt
Read /Users/alex/work/launch/private-notes.md.
Use alex@example.com and my AcmeCo account.
Write the launch posts.Safe ECC Skill Text
Read the public files in docs/releases/<version>/.
Use the workspace owner role and the default profile.
Return:
- One short X post
- One LinkedIn post
- One recording check list
- One list of missing files
Do not use private notes, real email addresses, or private account names.Expected Import Report
Candidate skill name: release-handoff
Clean flow:
Create public launch text from a release package.
Public inputs:
- docs/releases/<version>/notes.md
- docs/releases/<version>/assets/
Private inputs removed:
- Local home path
- Personal email
- Private account name
- Private notes file
Risks left:
- Release notes may still name a private client.
Files to create or update:
- skills/release-handoff/SKILL.md
- docs/releases/<version>/README.mdMore Rewrite Examples
Quiet-Hours Task
Private task:
At night, check my private inbox, money data, and content.Safe version:
Describe the schedule, quiet hours, alert rules, and check types.
Do not include private data sources, account names, or login details.Local Tool Log
Private task:
Use this raw log to show how the flow works.Safe version:
Make a short fake log that shows only the needed event types.
Remove user names, file paths, host names, IDs, and secret values.Output Contract
Return all of these items:
- Candidate ECC skill name: A short name in lowercase with hyphens.
- Clean flow summary: Two or three short sentences.
- Public inputs: Files, fields, or facts any user can provide.
- Private inputs removed: Types of data removed. Do not repeat their values.
- Risks left: Any part that still needs a human check.
- Files to create or update: Repo paths only.
- Test result: State whether the clean flow works with public inputs only.
- Credit note: State that the source is ECC.
Do not include private values in the report. If the clean flow still needs private state, return Keep local and explain why.