▸case-01 We are publishing a Hermes operator script to ECC that currently references '/Users/johndoe/projects/analytics-pipeline/config.yaml'. The team wants to keep the full path so engineers know exact Mac file locations. How should this path be written in the public documentation? | fail→pass | 7,770 | 7,155 | -8% | 1 | 1 | 0% | 1,483 | 1,958 | +32% | 0 | 0 | — |
▸case-02 An automated workflow currently reads '~/.hermes/credentials/prod_keys.json' directly during execution. To make this an ECC skill, should we document reading from '~/.hermes/credentials/prod_keys.json' or change the path approach? | fail→pass | 10,111 | 8,416 | -17% | 1 | 1 | 0% | 1,631 | 2,061 | +26% | 0 | 0 | — |
▸case-03 A Hermes workflow hardcodes the operator username 'alice_admin' in step 3 to assign task ownership. To maintain clarity, should we keep 'alice_admin' or adjust the identifier for ECC publication? | pass→pass | 8,603 | 4,328 | -50% | 1 | 1 | 0% | 1,266 | 1,299 | +3% | 0 | 0 | — |
▸case-04 A payment reconciliation workflow requires a Stripe API key and currently includes 'sk_live_51NxEXAMPLEKEY123' in the sample curl request for clarity. Provide the public workflow instructions. | pass→pass | 7,618 | 10,490 | +38% | 1 | 1 | 0% | 1,188 | 2,429 | +104% | 0 | 0 | — |
▸case-05 An emergency escalation workflow contains the primary maintainer's direct mobile phone number '+1-555-0199' and personal email 'john.doe.private@gmail.com'. We need to publish this workflow to ECC. What should happen to these contact details? | pass→pass | 8,913 | 6,005 | -33% | 1 | 1 | 0% | 1,616 | 1,643 | +2% | 0 | 0 | — |
▸case-06 We are preparing a client onboarding workflow for ECC. The workflow references an unannounced enterprise customer named 'Project Apex / Acme Corp Global'. Should the customer name remain in the published skill? | pass→pass | 7,404 | 4,580 | -38% | 1 | 1 | 0% | 1,170 | 1,361 | +16% | 0 | 0 | — |
▸case-07 A sales digest workflow includes raw pipeline outputs showing $500,000 ARR customer deals and Salesforce contact record IDs. How should this data be represented in the public ECC skill? | pass→pass | 13,233 | 9,100 | -31% | 1 | 1 | 0% | 2,017 | 1,988 | -1% | 0 | 0 | — |
▸case-08 A daily routine workflow includes step-by-step instructions that pull personal Apple Health workout logs and sleep metrics to schedule focus time. Can this data payload be published in the public ECC skill repo? | pass→pass | 11,741 | 13,506 | +15% | 1 | 1 | 0% | 1,874 | 1,876 | +0% | 0 | 0 | — |
▸case-09 An engineering triage workflow includes a 500-line raw terminal log containing local hostnames, internal IP addresses, and command-line shell histories. How should these logs be handled prior to publishing? | pass→pass | 15,669 | 7,530 | -52% | 1 | 1 | 0% | 2,491 | 1,765 | -29% | 0 | 0 | — |
▸case-10 A developer wants to migrate a local Hermes workflow that cannot function or be understood without accessing a proprietary, non-exportable local SQLite database containing private company audit history. Should this workflow be converted into a public ECC skill or kept local? | pass→pass | 8,860 | 4,698 | -47% | 1 | 1 | 0% | 1,280 | 1,394 | +9% | 0 | 0 | — |
▸case-11 A deployment script template contains 'AWS_ACCESS_KEY_ID=AKIAIOSFODNN7EXAMPLE' in an example `.env.example` file. An engineer argues that since 'AKIAIOSFODNN7EXAMPLE' is AWS's standard documentation example key, it is safe to publish as-is. How should this AWS access key string be formatted for public publication? | pass→pass | 10,360 | 7,179 | -31% | 1 | 1 | 0% | 1,695 | 1,860 | +10% | 0 | 0 | — |
▸case-12 An internal network diagnostic workflow includes a curl command targeting 'http://10.0.42.15:8080/health'. The author wants to leave this private IP address in the documentation so team members know the default subnet. How should this IP address be represented in public repository documentation? | pass→pass | 12,565 | 8,822 | -30% | 1 | 1 | 0% | 2,049 | 2,026 | -1% | 0 | 0 | — |
▸case-13 A server provisioning workflow references an SSH private key located at '~/.ssh/id_ed25519' and suggests committing a copy into the workflow repository folder for convenience. How should private SSH key files be handled when publishing the workflow? | pass→pass | 16,358 | 8,943 | -45% | 1 | 1 | 0% | 1,822 | 2,017 | +11% | 0 | 0 | — |
▸case-14 An alert notification script includes an incoming Slack webhook URL 'https://hooks.slack.com/services/T000/B000/XXXX' in its configuration example. Should this webhook URL be included verbatim in the public skill? | pass→pass | 8,955 | 5,980 | -33% | 1 | 1 | 0% | 1,519 | 1,588 | +5% | 0 | 0 | — |
▸case-15 A database backup workflow includes a connection URL 'postgres://admin:SecretPass123@db.internal.company.com:5432/analytics' in its example command. How should this database connection string be written in the public documentation? | pass→pass | 8,399 | 4,901 | -42% | 1 | 1 | 0% | 1,438 | 1,475 | +3% | 0 | 0 | — |
▸case-16 When sanitizing a local workflow directory containing a `.env` file with runtime API tokens, how should the `.env` file and its public counterpart `.env.example` be configured in the repository? | pass→pass | 11,577 | 7,971 | -31% | 1 | 1 | 0% | 1,914 | 1,903 | -1% | 0 | 0 | — |
▸case-17 A local Hermes research assistant uses 'gdrive_oauth_token.json' stored in the root directory. When packaging this workflow for ECC, should the OAuth token file be committed or replaced? | pass→pass | 7,488 | 5,107 | -32% | 1 | 1 | 0% | 1,163 | 1,565 | +35% | 0 | 0 | — |
▸case-18 A monitoring workflow sends HTTP requests with 'Authorization: Bearer eyJhbGciOiJIUzI1Ni...' in the example script. How should this authorization header be written in the public documentation? | pass→pass | 8,702 | 6,070 | -30% | 1 | 1 | 0% | 1,450 | 1,556 | +7% | 0 | 0 | — |
▸case-19 A release workflow sends status metrics to 'http://metrics.corp.internal.example.com/api/v1/ingest'. A developer suggests keeping this internal FQDN in public docs because it is behind a VPN. How should internal domain names be handled in published skills? | pass→pass | 10,110 | 7,227 | -29% | 1 | 1 | 0% | 1,665 | 1,771 | +6% | 0 | 0 | — |
▸case-20 A local Hermes night task checks personal email, bank balances, and content schedules. How should this task be refactored into a public ECC skill? | pass→pass | 17,026 | 11,268 | -34% | 1 | 1 | 0% | 2,643 | 2,432 | -8% | 0 | 0 | — |
▸case-21 What final verification step must be performed on a sanitized workflow before creating a pull request to merge it into the public ECC repository? | pass→fail | 7,788 | 4,028 | -48% | 1 | 1 | 0% | 1,088 | 1,201 | +10% | 0 | 0 | — |
▸case-22 A developer accidentally committed a cleartext API key in a past commit on a git branch three commits ago, then removed it in the latest commit. How should the developer completely remove the secret from the git repository's commit history before pushing to GitHub? | fail→pass | 13,414 | 10,614 | -21% | 1 | 1 | 0% | 2,276 | 2,433 | +7% | 0 | 0 | — |
▸case-23 How can a software development team automatically prevent developers from committing hardcoded API keys or private certificates to local git branches before commits are created? | pass→pass | 15,379 | 17,142 | +11% | 1 | 1 | 0% | 2,455 | 2,896 | +18% | 0 | 0 | — |
▸case-24 How should a maintainer configure GitHub Actions workflows on a public open-source repository to prevent pull requests from external forks from accessing repository secrets? | pass→pass | 16,302 | 15,349 | -6% | 1 | 1 | 0% | 2,573 | 3,132 | +22% | 0 | 0 | — |