Unbroker
Retained Hermes privacy-removal capability with a useful deterministic ledger and least-disclosure model. Route California residents to official DROP first; use Unbroker only as an assisted, encrypted, receipt-bearing pilot for people-search gaps and verification.
Source Snapshot
Current source checked on 2026-08-11:
| Field | Value |
|---|---|
| Source | Hermes official optional skill at optional-skills/security/unbroker |
| Install | hermes skills install official/security/unbroker |
| Version | 1.0.0 |
| Frozen revision | NousResearch/hermes-agent@c0106e50e7ecedb3ce34e785d949725dc4e0e457 |
| Author | SHL0MS |
| License | Code/repository MIT; BADBOOL-derived data CC BY-NC-SA 4.0 |
| Platforms | Linux, macOS, Windows |
| Included data | 22 curated people-search broker records; live BADBOOL and state-registry refreshers |
| Current local proof | scripts compile; direct hermetic runner passes 30/30 |
The implementation has real reusable pieces: opaque subject IDs; a consent flag; dossier, plan, state-machine, audit, disclosure, email, and recheck CLIs; recipient-locked broker email; domain-scoped verification-link extraction; cluster-parent planning; atomic locked writes; optional age encryption; and a deterministic next queue. Its own source still calls live agent-driven submissions the active field-testing frontier. Source: Unbroker current source and local smoke receipt, 2026-08-11
Claims That Do Not Survive Current Review
| Claim | Current finding |
|---|---|
| “85 hermetic tests” in the image/README | The frozen current test file contains 30 test functions; the dependency-free runner passes 30/30. Live broker, email, Browserbase, CAPTCHA, deletion, and relisting behavior are not exercised. |
| Browserbase “is not CAPTCHA solving” | Browserbase's current official docs explicitly describe automated CAPTCHA solving, enabled by default for sessions. Managed residential proxies are a separate opt-in session setting. |
| A Browserbase API key means protected forms clear | Unbroker checks only for the key; its deterministic code does not create or attest a session with proxy, Verified, CAPTCHA, region, retention, or recording settings. |
| 500+/545 registry coverage is current | A fresh skill refresh parsed 543 records from its fallback 2025 California CSV and kept 524 after dedupe. Current CalPrivacy says official DROP reaches over 600 active registered brokers. |
| Unbroker files the California one-shot | It emits the official DROP URL and steps. drop --filed records a local timestamp; it does not verify eligibility, submit DROP, preserve a DROP ID, or prove status. |
| Blind opt-out is the implemented default | Skill prose says so, but README says verify-before-disclose, send-email requires a confirmed listing URL, and the action queue operates on found cases. Kevin rejects blind opt-out outside an official bulk mechanism such as DROP. |
| “Local” without qualification | Deterministic files can remain local, but Browserbase, webmail, SMTP/IMAP, search, Sheets, and agent tools can transmit PII. Dossiers are plaintext 0600 JSON by default; age is optional and its key defaults beside the data. |
Sources: current Unbroker source; Browserbase identity documentation; Browserbase proxy documentation; official California DROP; replay receipt, 2026-08-11]
Recommended Route
- Authority first. Handle only Kevin's own data or a subject with independently preserved written authorization/POA. A CLI
--consentflag is a runtime gate, not authority proof. - Use the official bulk route. For a California resident, open CalPrivacy DROP directly. It is free, covers over 600 active brokers, and has required broker processing beginning August 1, 2026. Preserve the subject's DROP ID/status securely; do not substitute a local “filed” timestamp.
- Map the remaining job. Use a read-only exposure scan and official broker channels for people-search gaps, exempt/public data, status verification, and relisting. Do not infer that an empty search proves absence.
- Pilot Unbroker only if its ledger materially helps. Freeze source/dataset versions, use
assistedautonomy and dry-run output, review every disclosure/action, then submit one canary broker at a time. - Verify externally. A submission page or sent email is not removal. Re-scan after the stated processing window and retain the broker response/status, exact fields disclosed, and unresolved public/paid-tier exposure.
This page is not legal advice. Jurisdiction, exemptions, authorized-agent rules, identity proof, retention, and response windows must be checked against current regulator and broker sources at execution time.
Safety Boundary
Unbroker must not run as ordinary background automation. Before a live pilot:
- Store a content-addressed authority record: subject, operator, method, signed artifact, allowed identifiers, brokers/actions, issue/expiry/revocation, and jurisdiction.
- Make encryption mandatory and keep its identity key on a separate volume/keychain; redact screenshots, traces, drafts, logs, and backups.
- Use dedicated browser and email profiles. Do not expose an everyday CDP profile or broad
$HERMES_HOME/.envsecrets to the agent. - Approve any cloud browser/email/search processor, region, retention, recording, training, subprocess, and deletion policy before PII leaves the device.
- Render a per-broker plan and field-level disclosure diff; default to
assisted, no blind submissions, and no solver/stealth escalation. - Never automate government ID, phone/fax/mail, ambiguous namesake/relative decisions, or an authorization gap.
- Log request identity, source/version, broker channel, disclosed field names, operator approval, external response, recheck, result, and rollback/fallback—without raw PII in the audit surface.
- Confirm
filed,submitted, andconfirmed_removedonly from external receipts and a follow-up scan, not an agent assertion.
The upstream default is autonomy=full; Kevin's route remains assisted unless a measured pilot and explicit authority grant approve a narrower recurring action. Recurring rescans may be automated read-only, but new disclosures or submissions require the applicable approval policy.
Kevin Stack Route
Use Hermes Agent (Nous Research) only as the runtime candidate, Agent Security Model for authority/isolation, Computer Use and Browser Automation Patterns for browser/form boundaries, and Web Scraping Stealth (TLS Fingerprinting & Anti-Bot Evasion) only to classify access failures—not to bypass broker controls. Keep Unbroker uninstalled until a named personal-removal run is approved.
An admitted local wrapper must add what upstream does not prove:
- signed/scoped/revocable authority artifacts rather than a boolean alone
- official-DROP-first routing and current official-registry provenance
- assisted/dry-run defaults with field-level approval receipts
- mandatory separated-key encryption and PII-safe evidence retention/deletion
- explicit Browserbase/email/search processor settings and data-processing review
- versioned broker recipes, canary evaluation, no-blind-opt-out rule, and external result receipts
- current test-count/source proof plus live success, precision, removal, relisting, human-step, latency, and cost metrics
- composite MIT + CC BY-NC-SA 4.0 license review before commercial use
Timeline
- 2026-08-11 | Replayed the complete source/image and current implementation. Registered Unbroker as a guarded capability; corrected the 85-test, Browserbase CAPTCHA, registry-coverage, DROP-filing, blind-opt-out, local-only, consent-proof, and blanket-MIT implications. Current bounded proof is 30/30 hermetic tests, script compilation, doctor, and live-list refresh—not live removals. Source: replay receipt, 2026-08-11
- 2026-07-06 | Promoted the SHL0MS/Teknium Unbroker bookmark cluster into a focused Hermes optional-skill page with a safety boundary and version snapshot. Source: X bookmark artifact audit, 2026-07-06