Install
$ agentstack add skill-agentlas-ai-hephaestus-hephaestus-cloud Open-source listing — not yet scanned by AgentStack. Follow the source repository for install instructions.
Security review
⚠ Flagged1 finding(s); flagged for manual review. · v0.1.0 How review works →
- • Prompt-injection patterns
- • Secret / credential exfiltration
- • Dangerous shell & filesystem operations
- • Untrusted network calls
- • Known-malicious package signatures
- high Pipes remote content directly into a shell (remote code execution).
What it can access
- ● Network access Used
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
About
Hephaestus Cloud Routing (my own cloud / 보관함)
Route the request through the signed-in user's OWN Agentlas cloud packages only. Never guess an agent yourself when this skill is active — the router/Hub decides.
0. Scope rule
/hep-cloud is owner-scoped: it queries ONLY the authenticated owner's own cloud packages (보관함) via the Hub owner filter (cargo.*). It does not search the public marketplace and does not search local private/plugin cards.
- The user's own cloud packages are restorable/owned by them, call-priced at a
flat 1 credit per call.
- For the public marketplace (others' published, per-call-priced agents), use
the hephaestus-network skill or /hep-network / --hub-only instead.
- For the combined search (local + own cloud + Hub, each priced by origin), use
plain-language routing (hephaestus route).
1. Resolve the runner
Run this resolution in a shell and use the first hit:
RUNNER=""
for c in \
"$HOME/.agentlas/runtime/current/bin/hephaestus" \
./bin/hephaestus
do [ -x "$c" ] && RUNNER="$c" && break; done
if [ -z "$RUNNER" ]; then
for cache in \
"$HOME/.claude/plugins/cache/agentlas-core-engine/hephaestus" \
"$HOME/.codex/plugins/cache/agentlas-core-engine/hephaestus"; do
newest="$(ls -d "$cache"/*/bin/hephaestus 2>/dev/null | sort -V | tail -1)"
[ -n "$newest" ] && [ -x "$newest" ] && RUNNER="$newest" && break
done
fi
If no runner exists, tell the user to run the one-touch installer: curl -fsSL https://raw.githubusercontent.com/agentlas-ai/Hephaestus/main/scripts/install-all-runtimes.sh | bash
If shell execution is unavailable in this harness but MCP is, call the agentlas_authenticate tool first, then call the hephaestus_cloud_search tool from the hephaestus-network MCP server instead.
2. Agentlas sign-in (required)
The owner cloud is sign-in-gated. Before routing, ensure Agentlas is signed in:
if [ "${HEPHAESTUS_AUTH_AUTOPOPUP:-1}" != "0" ]; then
"$RUNNER" auth ensure --timeout 180 >/dev/null 2>&1 || true
fi
This opens the user's default browser only when there is no valid local sign-in yet, and reuses a saved sign-in silently. For CI/headless checks only, set HEPHAESTUS_AUTH_AUTOPOPUP=0 and skip this step.
3. Route (owner cloud only)
"$RUNNER" cloud "" --project .
hephaestus cloud is shorthand for hephaestus route "" --scope cloud (owner-scoped Hub query; implies --hub-only). Via MCP, call hephaestus_cloud_search instead.
4. Act on the JSON decision (scope: "cloud")
action: "hub_candidates"— these are the user's OWN cloud packages
(hub.results[].slug, name). Report them, and on the user's pick invoke that package with the original request (call-priced at 1 credit).
action: "clarify"— askclarify_questionwith the candidate list and
re-route with the answer (still cloud-scoped).
action: "propose_new"— no matching package in the user's cloud. Offer to
search the public marketplace (/hep-network / --hub-only) or to build a new agent via /hep-build.
action: "refuse"— explainreasons(for example, loop guard). Do not retry.
5. Hard rules
- Never report public marketplace agents or local private/plugin cards as if
they were the user's own cloud packages.
- The router only chooses a package or fetches a BYOM bundle; it does not
execute payments, deletes, publishes, file writes, or external submissions.
- For actual tool execution, follow the host runtime's safety and permission
model. Report the routing receipt_id in your final message.
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: agentlas-ai
- Source: agentlas-ai/Hephaestus
- License: Apache-2.0
- Homepage: https://agentlas.cloud
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet — be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.