agent-ledger: a security and audit plugin for Hermes Agent, scored against the OWASP Agentic Top 10 A developer released agent-ledger, an MIT-licensed open-source plugin for Hermes Agent that records every tool call to a local SQLite ledger before execution and scores the agent's recorded behavior from 100 to 0 against the OWASP Top 10 for Agentic Applications 2026. The plugin hooks pre_tool_call, flags unconfirmed calls as "ghosts" and injects a warning into the agent's next context, and its posture.py scorer detects patterns such as curl-piped-to-bash and credential-shaped path access while explicitly listing the ASI categories it cannot cover without payload inspection. The scorer ships with its test suite, including a 36/36 per-ASI unit run and a 50k-row scale test completing in 0.281s. Every tool call your agent makes, recorded locally before it runs — with a 0–100 posture score and an honest list of what it can't see. If you run an AI agent on your own machine, you already trust it with a lot. It edits files, restarts services, pushes to GitHub. agent-ledger answers two questions about that arrangement: what did my agent actually do, and how risky is its behavior? It's a free, open-source MIT plugin for Hermes Agent, and it works in two layers. The plugin hooks pre tool call and writes an entry to a local SQLite database before the tool executes. When the call completes, the entry is confirmed. Anything issued but never confirmed becomes a ghost — a tool call the agent believed it made, with no evidence it happened. Ghosts typically appear when a session is torn down mid-flight, for example during context compaction. When a ghost is detected, the plugin injects a warning into the agent's next context, so the agent itself goes back and verifies reality instead of trusting its memory. That's the core loop: record first, act second, reconcile after. Everything stays on your machine. The ledger is a plain SQLite file, there is no telemetry, no account, nothing leaves the box. posture.py reads the ledger and scores your agent's recorded behavior from 100 to 0 against the OWASP Top 10 for Agentic Applications 2026 https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/ . What it detects from ledger metadata alone: curl ... | bash , wget | sh , obfuscated payloads like echo