Hrishi Kumawat

Principal Security Engineer · Cloud & Kubernetes Security · DevSecOps · GenAI Compliance

I break things on purpose (in labs), and secure them for a living.

Things I’m building and learning

A running notebook about building safer AI-agent systems, operating a self-hosted homelab, and turning experiments into practical tools.

I write down what I built, why I chose it, the tradeoffs, and what I learned.

Project notes

Running Hermes like an isolated personal VPS

An always-on personal agent running inside a hardened Ubuntu VM and Docker, with Telegram voice, scheduled automation, persistent memory, rollback checkpoints, and a dashboard designed to stay behind an SSH tunnel.

Read the Hermes note →

Jev as a decision gate for agent actions

A typed-probability gate that classifies command risk, estimates blast radius, and decides whether Hermes should run, ask, or block before a tool call. Work in progress.

Read the Jev note →

Turning agent-security ideas into a working queue

A Hermes-managed Kanban covering model routing, alert triage, SSVC and BOD 26-04 decisions, prompt quality, policy drift, dashboards, and personal projects.

Read the idea-board note →

Validated diagrams instead of hopeful diagrams

Why I adopted Archify for architecture and workflow diagrams: typed JSON, strict validation, deterministic output, and interactive HTML that refuses broken layouts.

Read the Archify note →

Paperclip and the case for a meta harness

Research notes on coordinating Hermes, Codex, Claude Code, and other agents through explicit tasks, decision gates, traceable artifacts, and per-agent access.

Read the Paperclip note →

Giving Hermes a practical operating rhythm

OpenCode delegation, a cost-conscious model policy, voice, scheduled digests, vault-integrity checks, and native dashboard deliverables.

Read the operations note →

Latest posts