Dev News Daily ENDE

SANS releases two scripts to reconstruct what OpenCode and Hermes agents did

Incident responders increasingly have to answer a new question: what did the AI agent on this machine do? On 8 October SANS Internet Storm Center handler Jim Clausing published two Python scripts for exactly that, written for two open-source agents — OpenCode and Hermes — and released alongside an update of the SANS FOR577 course, whose day 5 now covers investigating eight coding assistants, including Claude Code, Codex, Gemini CLI, Cursor and Copilot.

opencode-chat-replay.py rebuilds conversations from OpenCode's SQLite database (by default ~/.local/share/opencode/opencode.db). It handles both the older separate message/part tables and the newer consolidated session_message storage. --list shows sessions with IDs, slugs, counts and UTC creation times; --latest, --session or --slug select one. Output is Markdown by default — metadata, then numbered turns, with reasoning and tool calls folded into <details> blocks — or JSON/JSONL for analysis with jq. Tool input and output are capped at 2,000 characters, and truncation is annotated, not silent. One stated goal: reproduce opencode export on an investigator's machine where OpenCode is not installed.

hermes_forensic_extract.py collects more: sessions, messages and model usage from ~/.hermes/state.db, full LLM request and response payloads from request_dump_*.json, and agent, error, gateway and GUI logs. It emits newline-delimited JSON, each record tagged with an _extraction_type (session, message, model_usage, request_dump, log_entry) plus source-file metadata.

SANS releases two scripts to reconstruct what OpenCode and Hermes agents did
SANS releases two scripts to reconstruct what OpenCode and Hermes agents did — Dev News Daily

Evidence handling is the part to copy. Both scripts need only Python 3.10+ and the standard library, take --start/--end time bounds, and work against a mounted image or collected tarball. Before querying, they copy the database and its -wal/-shm sidecars to a temporary directory and open that snapshot read-only, because opening a live SQLite file can still write staged data back. The OpenCode script never opens auth.json — but Clausing warns that transcripts can still contain secrets in recorded tool input and output.

Two caveats from the author himself: OpenCode and Hermes each wrote their own script, which explains their differences, and these are review tools, not replayers — they show what was recorded, not re-run it. The scripts are in Clausing's GitHub repository linked from the diary.

Source: SANS ISC diary, "Reconstructing AI Agent Activity: Two New Scripts for Forensic Review", 8 October 2026 — https://isc.sans.edu/diary/Reconstructing+AI+Agent+Activity+Two+New+Scripts+for+Forensic+Review/33410/

Primary source
SANS Internet Storm Center
https://isc.sans.edu/diary/rss/33410