--- name: hermes-agent description: "Configure, extend, or contribute to Hermes Agent." version: 2.0.0 author: Hermes Agent + Teknium license: MIT metadata: hermes: tags: [hermes, setup, configuration, multi-agent, spawning, cli, gateway, development] homepage: https://github.com/NousResearch/hermes-agent related_skills: [claude-code, codex, opencode] --- # Hermes Agent Hermes Agent is an open-source AI agent framework by Nous Research that runs in your terminal, messaging platforms, and IDEs. It belongs to the same category as Claude Code (Anthropic), Codex (OpenAI), and OpenClaw — autonomous coding and task-execution agents that use tool calling to interact with your system. Hermes works with any LLM provider (OpenRouter, Anthropic, OpenAI, DeepSeek, local models, and 15+ others) and runs on Linux, macOS, and WSL. What makes Hermes different: - **Self-improving through skills** — Hermes learns from experience by saving reusable procedures as skills. When it solves a complex problem, discovers a workflow, or gets corrected, it can persist that knowledge as a skill document that loads into future sessions. Skills accumulate over time, making the agent better at your specific tasks and environment. - **Persistent memory across sessions** — remembers who you are, your preferences, environment details, and lessons learned. Pluggable memory backends (built-in, Honcho, Mem0, and more) let you choose how memory works. - **Multi-platform gateway** — the same agent runs on Telegram, Discord, Slack, WhatsApp, Signal, Matrix, Email, and 10+ other platforms with full tool access, not just chat. - **Provider-agnostic** — swap models and providers mid-workflow without changing anything else. Credential pools rotate across multiple API keys automatically. - **Profiles** — run multiple independent Hermes instances with isolated configs, sessions, skills, and memory. - **Extensible** — plugins, MCP servers, custom tools, webhook triggers, cron scheduling, and the full Python ecosystem. People use Hermes for software development, research, system administration, data analysis, content creation, home automation, and anything else that benefits from an AI agent with persistent context and full system access. **This skill helps you work with Hermes Agent effectively** — setting it up, configuring features, spawning additional agent instances, troubleshooting issues, finding the right commands and settings, and understanding how the system works when you need to extend or contribute to it. **Docs:** https://hermes-agent.nousresearch.com/docs/ ## Quick Start ```bash # Install curl -fsSL https://raw.githubusercontent.com/NousResearch/hermes-agent/main/scripts/install.sh | bash # Interactive chat (default) hermes # Single query hermes chat -q "What is the capital of France?" # Setup wizard hermes setup # Change model/provider hermes model # Check health hermes doctor ``` --- ## CLI Reference ### Global Flags ``` hermes [flags] [command] --version, -V Show version --resume, -r SESSION Resume session by ID or title --continue, -c [NAME] Resume by name, or most recent session --worktree, -w Isolated git worktree mode (parallel agents) --skills, -s SKILL Preload skills (comma-separate or repeat) --profile, -p NAME Use a named profile --yolo Skip dangerous command approval --pass-session-id Include session ID in system prompt ``` No subcommand defaults to `chat`. ### Chat ``` hermes chat [flags] -q, --query TEXT Single query, non-interactive -m, --model MODEL Model (e.g. anthropic/claude-sonnet-4) -t, --toolsets LIST Comma-separated toolsets --provider PROVIDER Force provider (openrouter, anthropic, nous, etc.) -v, --verbose Verbose output -Q, --quiet Suppress banner, spinner, tool previews --checkpoints Enable filesystem checkpoints (/rollback) --source TAG Session source tag (default: cli) ``` ### Configuration ``` hermes setup [section] Interactive wizard (model|terminal|gateway|tools|agent) hermes model Interactive model/provider picker hermes config View current config hermes config edit Open config.yaml in $EDITOR hermes config set KEY VAL Set a config value hermes config path Print config.yaml path hermes config env-path Print .env path hermes config check Check for missing/outdated config hermes config migrate Update config with new options hermes login [--provider P] OAuth login (nous, openai-codex) hermes logout Clear stored auth hermes doctor [--fix] Check dependencies and config hermes status [--all] Show component status ``` ### Tools & Skills ``` hermes tools Interactive tool enable/disable (curses UI) hermes tools list Show all tools and status hermes tools enable NAME Enable a toolset hermes tools disable NAME Disable a toolset hermes skills list List installed skills hermes skills search QUERY Search the skills hub hermes skills install ID Install a skill (ID can be a hub identifier OR a direct https://…/SKILL.md URL; pass --name to override when frontmatter has no name) hermes skills inspect ID Preview without installing hermes skills config Enable/disable skills per platform hermes skills check Check for updates hermes skills update Update outdated skills hermes skills uninstall N Remove a hub skill hermes skills publish PATH Publish to registry hermes skills browse Browse all available skills hermes skills tap add REPO Add a GitHub repo as skill source ``` ### MCP Servers ``` hermes mcp serve Run Hermes as an MCP server hermes mcp add NAME Add an MCP server (--url or --command) hermes mcp remove NAME Remove an MCP server hermes mcp list List configured servers hermes mcp test NAME Test connection hermes mcp configure NAME Toggle tool selection ``` ### Gateway (Messaging Platforms) ``` hermes gateway run Start gateway foreground hermes gateway install Install as background service hermes gateway start/stop Control the service hermes gateway restart Restart the service hermes gateway status Check status hermes gateway setup Configure platforms ``` Supported platforms: Telegram, Discord, Slack, WhatsApp, Signal, Email, SMS, Matrix, Mattermost, Home Assistant, DingTalk, Feishu, WeCom, BlueBubbles (iMessage), Weixin (WeChat), API Server, Webhooks. Open WebUI connects via the API Server adapter. Platform docs: https://hermes-agent.nousresearch.com/docs/user-guide/messaging/ ### Sessions ``` hermes sessions list List recent sessions hermes sessions browse Interactive picker hermes sessions export OUT Export to JSONL hermes sessions rename ID T Rename a session hermes sessions delete ID Delete a session hermes sessions prune Clean up old sessions (--older-than N days) hermes sessions stats Session store statistics ``` ### Cron Jobs ``` hermes cron list List jobs (--all for disabled) hermes cron create SCHED Create: '30m', 'every 2h', '0 9 * * *' hermes cron edit ID Edit schedule, prompt, delivery hermes cron pause/resume ID Control job state hermes cron run ID Trigger on next tick hermes cron remove ID Delete a job hermes cron status Scheduler status ``` #### Daily work log pattern When the user asks for recurring work logs, create a durable logs directory and a scheduled Hermes cron job rather than relying on memory or ad-hoc summaries. Recommended setup used here: - Directory: `/home/hermesai/work-logs` (do not put daily work logs inside a project repo's `docs/` directory unless the user explicitly asks for project-local docs) - File naming: `YYYY-MM-DD.md`, matching existing examples such as `2026-05-17.md` - Schedule: `50 23 * * *` (daily 23:50 local time) - Job name: `daily-work-log` - Prompt requirements: - Summarize the current local day from Hermes sessions and actual work performed. - Use `session_search` or read `~/.hermes/sessions`; do not write from memory alone. - Overwrite the day's file with the most complete final version. - Markdown sections: 总览, 主要工作内容, 产出物, 技能/记忆更新, 风险与未完成事项, 次日建议. - Verify the file exists and is non-empty. For backfilling a prior day, search `~/.hermes/sessions/session_YYYYMMDD*.json` and/or use `session_search`, then write `/home/hermesai/work-logs/YYYY-MM-DD.md` directly. If a work log was mistakenly committed to a project repo, move/copy the content to `/home/hermesai/work-logs/YYYY-MM-DD.md`, remove the misplaced repo file, and commit the cleanup if the repo was changed. #### Recurring task status sync pattern When the user asks for periodic status updates, do not merely remember the preference or rely on ad-hoc manual reports. Create a separate scheduled cron job whose purpose is status reporting. Recommended setup used here: - Job name: `task-status-sync` - Schedule: `0 8-22/2 * * *` (every 2 hours during 08:00-22:00 local time; **do not send status syncs from 23:00 through 07:59** for this user) - Delivery: `origin` so the update reaches the current user/channel, not only local logs - Toolsets: `cronjob`, `terminal`, `file`, and `session_search` when available - Skills: `hermes-agent` plus `kanban-orchestrator` when task orchestration is involved - Prompt requirements: - Get current time. - If the current local hour is >=23 or <08, exit silently with no user-visible status update. - Inspect `cronjob list` for scheduled/running/paused/failed jobs, including `last_status`, `next_run_at`, `last_run_at`, and delivery errors. - Inspect background processes if available. - Check `/home/hermesai/work-logs` for today/yesterday log presence. - Use session search when available to identify recent work themes. - Report in Chinese with fixed sections: 时间, 运行中/待运行任务, 最近完成/失败/异常, 工作日志状态, 风险/阻塞, 需要用户决策. - If old jobs show stale `scheduled` state or `last_run_at=null`, label them as needing manual scheduler review instead of claiming success. - After creating/updating it, verify it appears in `cronjob list` with the expected next run. If you removed stale/overdue cron jobs while the gateway was already running, restart the gateway before scheduling replacement jobs so the scheduler does not keep an in-memory snapshot of deleted jobs. #### Cleaning stale cron jobs safely When old one-shot cron jobs are overdue (`next_run_at` in the past) or stuck with `last_run_at=null`, clean them before re-dispatching work: 1. Snapshot `cronjob list` / `hermes cron list` and identify true recurring jobs to keep (backup, watchdog, daily work log, task-status-sync). 2. Remove stale one-shot jobs with `cronjob(action="remove")` or `hermes cron remove `. 3. **Restart the gateway after removals** (`hermes gateway restart`) if it was running. Otherwise the gateway scheduler can retain a stale in-memory due-job list and log warnings like `mark_job_run: job_id ... not found` instead of firing newly-created replacements promptly. 4. Recreate replacement jobs only after the restart, or use independent `hermes chat --source ...` background processes for urgent recovery work that must survive the current conversation. 5. Verify with `hermes gateway status`, `hermes cron status`, `hermes cron list`, and (if needed) `journalctl --user -u hermes-gateway --since '10 minutes ago'`. ### Webhooks ``` hermes webhook subscribe N Create route at /webhooks/ hermes webhook list List subscriptions hermes webhook remove NAME Remove a subscription hermes webhook test NAME Send a test POST ``` ### Profiles ``` hermes profile list List all profiles hermes profile create NAME Create (--clone, --clone-all, --clone-from) hermes profile use NAME Set sticky default hermes profile delete NAME Delete a profile hermes profile show NAME Show details hermes profile alias NAME Manage wrapper scripts hermes profile rename A B Rename a profile hermes profile export NAME Export to tar.gz hermes profile import FILE Import from archive ``` ### Credential Pools ``` hermes auth add Interactive credential wizard hermes auth list [PROVIDER] List pooled credentials hermes auth remove P INDEX Remove by provider + index hermes auth reset PROVIDER Clear exhaustion status ``` ### Other ``` hermes insights [--days N] Usage analytics hermes update Update to latest version hermes pairing list/approve/revoke DM authorization hermes plugins list/install/remove Plugin management hermes honcho setup/status Honcho memory integration (requires honcho plugin) hermes memory setup/status/off Memory provider config hermes completion bash|zsh Shell completions hermes acp ACP server (IDE integration) hermes claw migrate Migrate from OpenClaw hermes uninstall Uninstall Hermes ``` --- ## Slash Commands (In-Session) Type these during an interactive chat session. ### Session Control ``` /new (/reset) Fresh session /clear Clear screen + new session (CLI) /retry Resend last message /undo Remove last exchange /title [name] Name the session /compress Manually compress context /stop Kill background processes /rollback [N] Restore filesystem checkpoint /background Run prompt in background /queue Queue for next turn /resume [name] Resume a named session ``` ### Configuration ``` /config Show config (CLI) /model [name] Show or change model /personality [name] Set personality /reasoning [level] Set reasoning (none|minimal|low|medium|high|xhigh|show|hide) /verbose Cycle: off → new → all → verbose /voice [on|off|tts] Voice mode /yolo Toggle approval bypass /skin [name] Change theme (CLI) /statusbar Toggle status bar (CLI) ``` ### Tools & Skills ``` /tools Manage tools (CLI) /toolsets List toolsets (CLI) /skills Search/install skills (CLI) /skill Load a skill into session /cron Manage cron jobs (CLI) /reload-mcp Reload MCP servers /plugins List plugins (CLI) ``` ### Gateway ``` /approve Approve a pending command (gateway) /deny Deny a pending command (gateway) /restart Restart gateway (gateway) /sethome Set current chat as home channel (gateway) /update Update Hermes to latest (gateway) /platforms (/gateway) Show platform connection status (gateway) ``` ### Utility ``` /branch (/fork) Branch the current session /fast Toggle priority/fast processing /browser Open CDP browser connection /history Show conversation history (CLI) /save Save conversation to file (CLI) /paste Attach clipboard image (CLI) /image Attach local image file (CLI) ``` ### Info ``` /help Show commands /commands [page] Browse all commands (gateway) /usage Token usage /insights [days] Usage analytics /status Session info (gateway) /profile Active profile info ``` ### Exit ``` /quit (/exit, /q) Exit CLI ``` --- ## Key Paths & Config ``` ~/.hermes/config.yaml Main configuration ~/.hermes/.env API keys and secrets $HERMES_HOME/skills/ Installed skills ~/.hermes/sessions/ Session transcripts ~/.hermes/logs/ Gateway and error logs ~/.hermes/auth.json OAuth tokens and credential pools ~/.hermes/hermes-agent/ Source code (if git-installed) ``` Profiles use `~/.hermes/profiles//` with the same layout. ### Config Sections Edit with `hermes config edit` or `hermes config set section.key value`. | Section | Key options | |---------|-------------| | `model` | `default`, `provider`, `base_url`, `api_key`, `context_length` | | `agent` | `max_turns` (90), `tool_use_enforcement` | | `terminal` | `backend` (local/docker/ssh/modal), `cwd`, `timeout` (180) | | `compression` | `enabled`, `threshold` (0.50), `target_ratio` (0.20) | | `display` | `skin`, `tool_progress`, `show_reasoning`, `show_cost` | | `stt` | `enabled`, `provider` (local/groq/openai/mistral) | | `tts` | `provider` (edge/elevenlabs/openai/minimax/mistral/neutts) | | `memory` | `memory_enabled`, `user_profile_enabled`, `provider` | | `security` | `tirith_enabled`, `website_blocklist` | | `delegation` | `model`, `provider`, `base_url`, `api_key`, `max_iterations` (50), `reasoning_effort` | | `checkpoints` | `enabled`, `max_snapshots` (50) | Full config reference: https://hermes-agent.nousresearch.com/docs/user-guide/configuration ### Providers 20+ providers supported. Set via `hermes model` or `hermes setup`. | Provider | Auth | Key env var | |----------|------|-------------| | OpenRouter | API key | `OPENROUTER_API_KEY` | | Anthropic | API key | `ANTHROPIC_API_KEY` | | Nous Portal | OAuth | `hermes auth` | | OpenAI Codex | OAuth | `hermes auth` | | GitHub Copilot | Token | `COPILOT_GITHUB_TOKEN` | | Google Gemini | API key | `GOOGLE_API_KEY` or `GEMINI_API_KEY` | | DeepSeek | API key | `DEEPSEEK_API_KEY` | | xAI / Grok | API key | `XAI_API_KEY` | | Hugging Face | Token | `HF_TOKEN` | | Z.AI / GLM | API key | `GLM_API_KEY` | | MiniMax | API key | `MINIMAX_API_KEY` | | MiniMax CN | API key | `MINIMAX_CN_API_KEY` | | Kimi / Moonshot | API key | `KIMI_API_KEY` | | Alibaba / DashScope | API key | `DASHSCOPE_API_KEY` | | Xiaomi MiMo | API key | `XIAOMI_API_KEY` | | Kilo Code | API key | `KILOCODE_API_KEY` | | AI Gateway (Vercel) | API key | `AI_GATEWAY_API_KEY` | | OpenCode Zen | API key | `OPENCODE_ZEN_API_KEY` | | OpenCode Go | API key | `OPENCODE_GO_API_KEY` | | Qwen OAuth | OAuth | `hermes login --provider qwen-oauth` | | Custom endpoint | Config | `model.base_url` + `model.api_key` in config.yaml | | GitHub Copilot ACP | External | `COPILOT_CLI_PATH` or Copilot CLI | Full provider docs: https://hermes-agent.nousresearch.com/docs/integrations/providers ### Toolsets Enable/disable via `hermes tools` (interactive) or `hermes tools enable/disable NAME`. | Toolset | What it provides | |---------|-----------------| | `web` | Web search and content extraction | | `browser` | Browser automation (Browserbase, Camofox, or local Chromium) | | `terminal` | Shell commands and process management | | `file` | File read/write/search/patch | | `code_execution` | Sandboxed Python execution | | `vision` | Image analysis | | `image_gen` | AI image generation | | `tts` | Text-to-speech | | `skills` | Skill browsing and management | | `memory` | Persistent cross-session memory | | `session_search` | Search past conversations | | `delegation` | Subagent task delegation | | `cronjob` | Scheduled task management | | `clarify` | Ask user clarifying questions | | `messaging` | Cross-platform message sending | | `search` | Web search only (subset of `web`) | | `todo` | In-session task planning and tracking | | `rl` | Reinforcement learning tools (off by default) | | `moa` | Mixture of Agents (off by default) | | `homeassistant` | Smart home control (off by default) | Tool changes take effect on `/reset` (new session). They do NOT apply mid-conversation to preserve prompt caching. --- ## Security & Privacy Toggles Common "why is Hermes doing X to my output / tool calls / commands?" toggles — and the exact commands to change them. Most of these need a fresh session (`/reset` in chat, or start a new `hermes` invocation) because they're read once at startup. ### Secret redaction in tool output Secret redaction is **off by default** — tool output (terminal stdout, `read_file`, web content, subagent summaries, etc.) passes through unmodified. If the user wants Hermes to auto-mask strings that look like API keys, tokens, and secrets before they enter the conversation context and logs: ```bash hermes config set security.redact_secrets true # enable globally ``` **Restart required.** `security.redact_secrets` is snapshotted at import time — toggling it mid-session (e.g. via `export HERMES_REDACT_SECRETS=true` from a tool call) will NOT take effect for the running process. Tell the user to run `hermes config set security.redact_secrets true` in a terminal, then start a new session. This is deliberate — it prevents an LLM from flipping the toggle on itself mid-task. Disable again with: ```bash hermes config set security.redact_secrets false ``` ### PII redaction in gateway messages Separate from secret redaction. When enabled, the gateway hashes user IDs and strips phone numbers from the session context before it reaches the model: ```bash hermes config set privacy.redact_pii true # enable hermes config set privacy.redact_pii false # disable (default) ``` ### Command approval prompts By default (`approvals.mode: manual`), Hermes prompts the user before running shell commands flagged as destructive (`rm -rf`, `git reset --hard`, etc.). The modes are: - `manual` — always prompt (default) - `smart` — use an auxiliary LLM to auto-approve low-risk commands, prompt on high-risk - `off` — skip all approval prompts (equivalent to `--yolo`) ```bash hermes config set approvals.mode smart # recommended middle ground hermes config set approvals.mode off # bypass everything (not recommended) ``` Per-invocation bypass without changing config: - `hermes --yolo …` - `export HERMES_YOLO_MODE=1` Note: YOLO / `approvals.mode: off` does NOT turn off secret redaction. They are independent. ### Shell hooks allowlist Some shell-hook integrations require explicit allowlisting before they fire. Managed via `~/.hermes/shell-hooks-allowlist.json` — prompted interactively the first time a hook wants to run. ### Disabling the web/browser/image-gen tools To keep the model away from network or media tools entirely, open `hermes tools` and toggle per-platform. Takes effect on next session (`/reset`). See the Tools & Skills section above. --- ## Voice & Transcription ### STT (Voice → Text) Voice messages from messaging platforms are auto-transcribed. Provider priority (auto-detected): 1. **Local faster-whisper** — free, no API key: `pip install faster-whisper` 2. **Groq Whisper** — free tier: set `GROQ_API_KEY` 3. **OpenAI Whisper** — paid: set `VOICE_TOOLS_OPENAI_KEY` 4. **Mistral Voxtral** — set `MISTRAL_API_KEY` Config: ```yaml stt: enabled: true provider: local # local, groq, openai, mistral local: model: base # tiny, base, small, medium, large-v3 ``` ### TTS (Text → Voice) | Provider | Env var | Free? | |----------|---------|-------| | Edge TTS | None | Yes (default) | | ElevenLabs | `ELEVENLABS_API_KEY` | Free tier | | OpenAI | `VOICE_TOOLS_OPENAI_KEY` | Paid | | MiniMax | `MINIMAX_API_KEY` | Paid | | Mistral (Voxtral) | `MISTRAL_API_KEY` | Paid | | NeuTTS (local) | None (`pip install neutts[all]` + `espeak-ng`) | Free | Voice commands: `/voice on` (voice-to-voice), `/voice tts` (always voice), `/voice off`. --- ## Spawning Additional Hermes Instances Run additional Hermes processes as fully independent subprocesses — separate sessions, tools, and environments. ### When to Use This vs delegate_task | | `delegate_task` | Spawning `hermes` process | |-|-----------------|--------------------------| | Isolation | Separate conversation, shared process | Fully independent process | | Duration | Minutes (bounded by parent loop) | Hours/days | | Tool access | Subset of parent's tools | Full tool access | | Interactive | No | Yes (PTY mode) | | Use case | Quick parallel subtasks | Long autonomous missions | ### One-Shot Mode ``` terminal(command="hermes chat -q 'Research GRPO papers and write summary to ~/research/grpo.md'", timeout=300) # Background for long tasks: terminal(command="hermes chat -q 'Set up CI/CD for ~/myapp'", background=true) ``` ### Interactive PTY Mode (via tmux) Hermes uses prompt_toolkit, which requires a real terminal. Use tmux for interactive spawning: ``` # Start terminal(command="tmux new-session -d -s agent1 -x 120 -y 40 'hermes'", timeout=10) # Wait for startup, then send a message terminal(command="sleep 8 && tmux send-keys -t agent1 'Build a FastAPI auth service' Enter", timeout=15) # Read output terminal(command="sleep 20 && tmux capture-pane -t agent1 -p", timeout=5) # Send follow-up terminal(command="tmux send-keys -t agent1 'Add rate limiting middleware' Enter", timeout=5) # Exit terminal(command="tmux send-keys -t agent1 '/exit' Enter && sleep 2 && tmux kill-session -t agent1", timeout=10) ``` ### Multi-Agent Coordination ``` # Agent A: backend terminal(command="tmux new-session -d -s backend -x 120 -y 40 'hermes -w'", timeout=10) terminal(command="sleep 8 && tmux send-keys -t backend 'Build REST API for user management' Enter", timeout=15) # Agent B: frontend terminal(command="tmux new-session -d -s frontend -x 120 -y 40 'hermes -w'", timeout=10) terminal(command="sleep 8 && tmux send-keys -t frontend 'Build React dashboard for user management' Enter", timeout=15) # Check progress, relay context between them terminal(command="tmux capture-pane -t backend -p | tail -30", timeout=5) terminal(command="tmux send-keys -t frontend 'Here is the API schema from the backend agent: ...' Enter", timeout=5) ``` ### Session Resume ``` # Resume most recent session terminal(command="tmux new-session -d -s resumed 'hermes --continue'", timeout=10) # Resume specific session terminal(command="tmux new-session -d -s resumed 'hermes --resume 20260225_143052_a1b2c3'", timeout=10) ``` ### Tips - **Prefer `delegate_task` for quick subtasks** — less overhead than spawning a full process - **Use `-w` (worktree mode)** when spawning agents that edit code — prevents git conflicts - **Set timeouts** for one-shot mode — complex tasks can take 5-10 minutes - **Use `hermes chat -q` for fire-and-forget** — no PTY needed - **Use tmux for interactive sessions** — raw PTY mode has `\r` vs `\n` issues with prompt_toolkit - **For scheduled tasks**, use the `cronjob` tool instead of spawning — handles delivery and retry --- ## Troubleshooting ### Voice not working 1. Check `stt.enabled: true` in config.yaml 2. Verify provider: `pip install faster-whisper` or set API key 3. In gateway: `/restart`. In CLI: exit and relaunch. ### Tool not available 1. `hermes tools` — check if toolset is enabled for your platform 2. Some tools need env vars (check `.env`) 3. `/reset` after enabling tools ### Model/provider issues 1. `hermes doctor` — check config and dependencies 2. `hermes login` — re-authenticate OAuth providers 3. Check `.env` has the right API key 4. **Copilot 403**: `gh auth login` tokens do NOT work for Copilot API. You must use the Copilot-specific OAuth device code flow via `hermes model` → GitHub Copilot. ### hermes update behind SOCKS5 proxy (China/firewall) When direct access to git remotes is blocked but a SOCKS5 proxy is available (e.g. SSH reverse tunnel at `127.0.0.1:1086`): ```bash # Set global git proxy temporarily git config --global http.proxy socks5://127.0.0.1:1086 git config --global https.proxy socks5://127.0.0.1:1086 # Verify proxy works curl -x socks5://127.0.0.1:1086 -I https://github.com # should return 200 # Then update (may timeout if hermes update doesn't use proxy properly) hermes update # If hermes update times out, do manual git pull: cd /d/hermesai/hermes/hermes-agent # or wherever hermes-agent is installed git pull origin main # Clean up proxy config when done git config --global --unset http.proxy git config --global --unset https.proxy ``` **Pitfall:** `hermes update` command itself may not respect git proxy settings and timeout after 120s. In that case, use `git pull origin main` directly in the hermes-agent directory. Verify with `hermes --version` afterward. **Note:** `socks5://` requires the proxy to handle DNS resolution locally. If DNS fails, use `socks5h://` instead (proxy handles DNS). ### Changes not taking effect - **Tools/skills:** `/reset` starts a new session with updated toolset - **Config changes:** In gateway: `/restart`. In CLI: exit and relaunch. - **Code changes:** Restart the CLI or gateway process ### Skills not showing 1. `hermes skills list` — verify installed 2. `hermes skills config` — check platform enablement 3. Load explicitly: `/skill name` or `hermes -s name` ### Gateway issues Check logs first: ```bash grep -i "failed to send\|error" ~/.hermes/logs/gateway.log | tail -20 ``` Common gateway problems: - **Gateway dies on SSH logout**: Enable linger: `sudo loginctl enable-linger $USER` - **Gateway dies on WSL2 close**: WSL2 requires `systemd=true` in `/etc/wsl.conf` for systemd services to work. Without it, gateway falls back to `nohup` (dies when session closes). - **Gateway crash loop**: Reset the failed state: `systemctl --user reset-failed hermes-gateway` ### Platform-specific issues - **Discord bot silent**: Must enable **Message Content Intent** in Bot → Privileged Gateway Intents. - **Slack bot only works in DMs**: Must subscribe to `message.channels` event. Without it, the bot ignores public channels. - **Windows HTTP 400 "No models provided"**: Config file encoding issue (BOM). Ensure `config.yaml` is saved as UTF-8 without BOM. ### Browser tools not working (browser_navigate timeout) See `references/browser-troubleshooting.md` for detailed setup guides and failure diagnostics. The `browser` toolset (`browser_navigate`, `browser_snapshot`, `browser_click`, etc.) depends on the **`agent-browser` CLI**, not directly on the Playwright Python module. Having `playwright` installed via pip does NOT make browser tools work. **Diagnosis:** ```bash # Check if the CLI exists agent-browser --version # or: ~/.hermes/node/bin/agent-browser --version # Check if browser binaries are installed ls ~/.cache/ms-playwright/chromium-*/chrome-linux64/chrome 2>/dev/null ``` **Setup (normal):** ```bash # 1. Install the agent-browser CLI npm install -g agent-browser # 2. Install browser binaries (downloads Chromium ~300MB) agent-browser install ``` **CDP mode (recommended for Linux servers, China, or when agent-browser install fails):** When `agent-browser install` cannot download Chrome (CDN blocked, GLIBC mismatch, snap permission issues), run Chrome manually with CDP debugging port and point Hermes at it: ```bash # 1. Use Playwright's already-downloaded Chromium CHROME=~/.cache/ms-playwright/chromium-*/chrome-linux64/chrome # 2. Launch with CDP port and --no-sandbox (required on most Linux servers) $CHROME --headless=new --no-sandbox --disable-setuid-sandbox \ --remote-debugging-port=9222 --user-data-dir=/tmp/chrome-hermes-data about:blank & # 3. Configure Hermes to connect via CDP (in config.yaml) hermes config set browser.cdp_url 'http://localhost:9222' # or edit config.yaml: browser.cdp_url: 'http://localhost:9222' ``` The CDP URL can be an HTTP discovery endpoint (`http://host:port`) — Hermes will automatically resolve the WebSocket URL via `/json/version`. This means the UUID changes on each Chrome restart are handled transparently. A startup script is included in the skill (`scripts/start-chrome-cdp.sh`) that handles launch, readiness check, and stale process cleanup. Use it directly or adapt for cron/systemd. **Common issues:** - **`agent-browser: command not found`**: Binary lives in `~/.hermes/node/bin/` (Hermes's npm prefix). Ensure this directory is in PATH. - **`agent-browser install` times out**: CDN blocked (common in China). Use CDP mode with Playwright's pre-cached Chromium instead. - **`snap-confine is packaged without necessary permissions`**: System snap Chrome is unusable. Use Playwright's Chromium binary with `--no-sandbox`. - **`GLIBC_2.38 not found`**: Snap Chrome requires newer glibc. Use Playwright's Chromium. - **`browser_navigate` returns timeout**: Usually means agent-browser CLI is missing or Chrome can't launch. Use CDP mode as a reliable alternative. - **Chrome auto-launch fails in Docker/containers**: Always add `--no-sandbox,--disable-setuid-sandbox` via `AGENT_BROWSER_ARGS` env var or config file. ### CLI input freezing / unresponsive typing **Symptom:** CLI becomes unresponsive after typing a certain amount of text — keystrokes don't register, Enter doesn't send the message, but the process is still alive. Intermittent, correlates with input length. **Root cause:** Expensive functions called on every render cycle (every keystroke, spinner tick, thread invalidation) can saturate the event loop, blocking input processing. Common culprits in cli.py: 1. **`_input_height()` function** — calculates visual line count for dynamic TextArea height. If it imports modules inside the function body and recalculates from scratch every time, the import lock contention + computation overhead can block input. 2. **Text stripping functions** — `_strip_leaked_bracketed_paste_wrappers()` and `_strip_leaked_terminal_responses_with_meta()` run on every keystroke via `_on_text_changed`. Without fast paths, they perform 4+ regex substitutions even when no patterns match. 3. **Paste detection threshold** — `chars_added > 1` can trigger false positives during fast typing when prompt_toolkit batches 2-3 keystrokes into a single event. **Fix pattern (cli.py around line 12116):** - Move `from prompt_toolkit.application import get_app` and `from prompt_toolkit.utils import get_cwidth` **outside** the `_input_height()` function body (to module-level or enclosing scope) - Add caching with lightweight hash: store `(text_hash, cols) → result`, only recalculate when text content or terminal width changes - Add fast path to `_strip_leaked_bracketed_paste_wrappers()`: check `if "~" not in text: return text` before running replacements (all bracketed-paste markers contain `~`) - Raise paste detection threshold from `chars_added > 1` to `chars_added > 10` **Diagnostic approach:** - Check if `_input_height()` or similar layout functions are called on every render (they're assigned to `window.height` properties) - Profile by adding `import time; t0=time.monotonic()` at function start and `print(time.monotonic()-t0)` at end — if >5ms per call, it's a bottleneck - Look for imports inside function bodies in hot paths - Check if text processing functions have fast paths for common cases (empty text, no target patterns) **Prevention:** Any function assigned to a prompt_toolkit layout property (height, width, content) should be O(1) with caching, not O(n) with full recalculation. ### Auxiliary models not working If `auxiliary` tasks (vision, compression, session_search) fail silently, the `auto` provider can't find a backend. Either set `OPENROUTER_API_KEY` or `GOOGLE_API_KEY`, or explicitly configure each auxiliary task's provider: ```bash hermes config set auxiliary.vision.provider hermes config set auxiliary.vision.model ``` ### session_search "file is not a database" The SQLite session store can become corrupted by concurrent writes or disk full conditions. When `session_search` returns `DatabaseError: file is not a database`: ```bash # Check disk space first df -h ~/.hermes/sessions/ # Try repair hermes session repair # if available # If repair fails, the database is unrecoverable # Sessions are still in ~/.hermes/sessions/session_*.json files # but full-text search index is broken ``` This does NOT affect running sessions or cronjobs — only historical search. The session files (JSON) remain intact. ### hermes chat -q exit code 1 (subagent spawning failure) When `hermes chat -q` fails with exit code 1 in a background process or cronjob: - **Gateway unavailable**: The gateway must be running for `hermes chat -q` to work. Check `hermes gateway status`. - **Prompt too long**: If the prompt exceeds the model's context limit, it fails silently. Verify prompt < context window. - **Model/provider error**: Check gateway logs for model-specific errors: `tail -20 ~/.hermes/logs/gateway.log` For reliable subagent dispatch, prefer `delegate_task` (in-session) or `cronjob` (scheduled) over raw `hermes chat -q` terminal commands — they have better error reporting and retry logic. --- ## Where to Find Things | Looking for... | Location | |----------------|----------| | Daily work log automation | `references/daily-work-log.md` | | Config options | `hermes config edit` or [Configuration docs](https://hermes-agent.nousresearch.com/docs/user-guide/configuration) | | Available tools | `hermes tools list` or [Tools reference](https://hermes-agent.nousresearch.com/docs/reference/tools-reference) | | Slash commands | `/help` in session or [Slash commands reference](https://hermes-agent.nousresearch.com/docs/reference/slash-commands) | | Skills catalog | `hermes skills browse` or [Skills catalog](https://hermes-agent.nousresearch.com/docs/reference/skills-catalog) | | Provider setup | `hermes model` or [Providers guide](https://hermes-agent.nousresearch.com/docs/integrations/providers) | | Platform setup | `hermes gateway setup` or [Messaging docs](https://hermes-agent.nousresearch.com/docs/user-guide/messaging/) | | MCP servers | `hermes mcp list` or [MCP guide](https://hermes-agent.nousresearch.com/docs/user-guide/features/mcp) | | Profiles | `hermes profile list` or [Profiles docs](https://hermes-agent.nousresearch.com/docs/user-guide/profiles) | | Cron jobs | `hermes cron list` or [Cron docs](https://hermes-agent.nousresearch.com/docs/user-guide/features/cron) | | Memory | `hermes memory status` or [Memory docs](https://hermes-agent.nousresearch.com/docs/user-guide/features/memory) | | Env variables | `hermes config env-path` or [Env vars reference](https://hermes-agent.nousresearch.com/docs/reference/environment-variables) | | CLI commands | `hermes --help` or [CLI reference](https://hermes-agent.nousresearch.com/docs/reference/cli-commands) | | Gateway logs | `~/.hermes/logs/gateway.log` | | Session files | `~/.hermes/sessions/` or `hermes sessions browse` | | Source code | `~/.hermes/hermes-agent/` | --- ## Contributor Quick Reference For occasional contributors and PR authors. Full developer docs: https://hermes-agent.nousresearch.com/docs/developer-guide/ ### Project Layout ``` hermes-agent/ ├── run_agent.py # AIAgent — core conversation loop ├── model_tools.py # Tool discovery and dispatch ├── toolsets.py # Toolset definitions ├── cli.py # Interactive CLI (HermesCLI) ├── hermes_state.py # SQLite session store ├── agent/ # Prompt builder, context compression, memory, model routing, credential pooling, skill dispatch ├── hermes_cli/ # CLI subcommands, config, setup, commands │ ├── commands.py # Slash command registry (CommandDef) │ ├── config.py # DEFAULT_CONFIG, env var definitions │ └── main.py # CLI entry point and argparse ├── tools/ # One file per tool │ └── registry.py # Central tool registry ├── gateway/ # Messaging gateway │ └── platforms/ # Platform adapters (telegram, discord, etc.) ├── cron/ # Job scheduler ├── tests/ # ~3000 pytest tests └── website/ # Docusaurus docs site ``` Config: `~/.hermes/config.yaml` (settings), `~/.hermes/.env` (API keys). ### Adding a Tool (3 files) **1. Create `tools/your_tool.py`:** ```python import json, os from tools.registry import registry def check_requirements() -> bool: return bool(os.getenv("EXAMPLE_API_KEY")) def example_tool(param: str, task_id: str = None) -> str: return json.dumps({"success": True, "data": "..."}) registry.register( name="example_tool", toolset="example", schema={"name": "example_tool", "description": "...", "parameters": {...}}, handler=lambda args, **kw: example_tool( param=args.get("param", ""), task_id=kw.get("task_id")), check_fn=check_requirements, requires_env=["EXAMPLE_API_KEY"], ) ``` **2. Add to `toolsets.py`** → `_HERMES_CORE_TOOLS` list. Auto-discovery: any `tools/*.py` file with a top-level `registry.register()` call is imported automatically — no manual list needed. All handlers must return JSON strings. Use `get_hermes_home()` for paths, never hardcode `~/.hermes`. ### Adding a Slash Command 1. Add `CommandDef` to `COMMAND_REGISTRY` in `hermes_cli/commands.py` 2. Add handler in `cli.py` → `process_command()` 3. (Optional) Add gateway handler in `gateway/run.py` All consumers (help text, autocomplete, Telegram menu, Slack mapping) derive from the central registry automatically. ### Agent Loop (High Level) ``` run_conversation(): 1. Build system prompt 2. Loop while iterations < max: a. Call LLM (OpenAI-format messages + tool schemas) b. If tool_calls → dispatch each via handle_function_call() → append results → continue c. If text response → return 3. Context compression triggers automatically near token limit ``` ### Testing ```bash python -m pytest tests/ -o 'addopts=' -q # Full suite python -m pytest tests/tools/ -q # Specific area ``` - Tests auto-redirect `HERMES_HOME` to temp dirs — never touch real `~/.hermes/` - Run full suite before pushing any change - Use `-o 'addopts='` to clear any baked-in pytest flags ### Commit Conventions ``` type: concise subject line Optional body. ``` Types: `fix:`, `feat:`, `refactor:`, `docs:`, `chore:` ### Key Rules - **Never break prompt caching** — don't change context, tools, or system prompt mid-conversation - **Message role alternation** — never two assistant or two user messages in a row - Use `get_hermes_home()` from `hermes_constants` for all paths (profile-safe) - Config values go in `config.yaml`, secrets go in `.env` - New tools need a `check_fn` so they only appear when requirements are met --- ## Migration & Backup ### Relocating to a Larger Volume (Disk Full) When ~/.hermes grows to 20+ GB (checkpoints, backup-repo, sessions) and the root filesystem is >95% full, relocate it to a larger mounted volume via rsync + symlink. Two-phase: copy while running, then switch from outside the session (the agent can't kill its own home). - Procedure and pitfalls: `references/relocate-hermes-home.md` - Migration script: `scripts/migrate-hermes-home.sh` - Quick check: `du -sh ~/.hermes/*/ | sort -rh | head -5 && df -h /` ### Profile Export/Import (Lightweight) Hermes has built-in profile export/import for migrating a single profile's config and memory: ```bash hermes profile export myprofile # exports to tar.gz hermes profile import archive.tar.gz ``` **What profile export includes:** `config.yaml`, `.env`, `SOUL.md`, `memories/`, `state.db`, `sessions/` **What it does NOT include:** skills, `hermes-agent` source, `~/repos/` business modules, custom hooks/cron ### Full Instance Migration (Comprehensive) When moving a Hermes instance to a new machine or clean install — especially when it has accumulated custom skills and modules — use a comprehensive backup: #### What to include | Path | Content | Typical size | |------|---------|-------------| | `~/.hermes/config.yaml` | Main config | 12K | | `~/.hermes/.env` | Environment variables | 20K | | `~/.hermes/SOUL.md` | Agent personality | 4K | | `~/.hermes/state.db` | State database | 60M | | `~/.hermes/memories/` | MEMORY.md + USER.md | 12K | | `~/.hermes/skills/` | All installed skills | 15M | | `~/.hermes/hermes-agent/` | Source code (git repo) | 350M | | `~/repos/` | Business modules | 280M | #### What to exclude - `auth.json` — OAuth tokens (re-authenticate on new instance) - `sessions/` — conversation history (regeneratable, large) - `checkpoints/` — build cache (regeneratable) - `logs/` — runtime logs - `image_cache/`, `audio_cache/`, `node/` — caches - `pastes/` — temporary files - `.skills_prompt_snapshot.json`, `.update_check`, `processes.json` — regenerated at runtime #### Packaging steps ```bash # Create staging dir WORKDIR=$(mktemp -d) # Config files — REDACT sensitive keys for transport sed 's/api_key: .*/api_key: "***REDACTED***/' ~/.hermes/config.yaml > "$WORKDIR/config.yaml" cp ~/.hermes/.env "$WORKDIR/.env" # Redact API keys, passwords manually if needed # Core files cp ~/.hermes/SOUL.md "$WORKDIR/" cp ~/.hermes/state.db "$WORKDIR/" cp -r ~/.hermes/memories "$WORKDIR/" # ALL skills (especially custom module-development skills) cp -r ~/.hermes/skills "$WORKDIR/" # Source and modules cp -r ~/.hermes/hermes-agent "$WORKDIR/" cp -r ~/repos "$WORKDIR/" # Package tar czf ~/hermes-backup-$(date +%Y%m%d).tgz -C "$WORKDIR" . rm -rf "$WORKDIR" ``` #### Restore steps ```bash # 1. Install fresh Hermes on target machine curl -fsSL https://raw.githubusercontent.com/NousResearch/hermes-agent/main/scripts/install.sh | bash hermes setup # Basic initial setup # 2. Extract backup tar xzf hermes-backup-*.tgz -C /tmp/hermes-restore cd /tmp/hermes-restore # 3. Copy .hermes files (merge with new install) cp config.yaml ~/.hermes/config.yaml cp .env ~/.hermes/.env cp SOUL.md ~/.hermes/SOUL.md cp state.db ~/.hermes/state.db cp -r memories/* ~/.hermes/memories/ cp -r skills/* ~/.hermes/skills/ # Overwrites default skills with custom ones cp -r hermes-agent ~/.hermes/ # Source code cp -r repos/* ~/repos/ # Business modules # 4. Re-enter API keys in config.yaml and .env (find ***REDACTED***) hermes config edit # 5. Verify hermes skills list # Should show all custom skills hermes doctor # Check health hermes model # Verify model config ``` #### Important notes - **API keys must be re-entered** — the backup redacts them for safe transport - **auth.json is NOT included** — new instance needs re-authentication (`hermes login`) - **Skill curator state** — after restoring skills, run `hermes skills list` to rebuild the internal index - **Database compatibility** — `state.db` is SQLite and portable across machines - **Module dependencies** — after copying `~/repos/`, run `pip install -e` for each module if the new machine doesn't have them installed - **Permissions** — ensure file ownership matches the target user: `chown -R $USER:$USER ~/.hermes ~/repos`