Skip to content

feat(sync): HSP/1 personal skill sync client (M1 client) - #66730

Merged
teknium1 merged 16 commits into
mainfrom
feat/hsp-sync-client
Jul 29, 2026
Merged

feat(sync): HSP/1 personal skill sync client (M1 client)#66730
teknium1 merged 16 commits into
mainfrom
feat/hsp-sync-client

Conversation

@benbarclay

@benbarclay benbarclay commented Jul 18, 2026

Copy link
Copy Markdown
Collaborator

[!IMPORTANT] Scope expanded 2026-07-24 (single-review consolidation, per Ben): this PR now contains the ENTIRE hermes-agent client for Collective Wisdom — M1 personal sync plus the two M2 commits that previously sat in stacked PRs #70024 (org pull / hermes skills propose / 202 handling) and #70459 (org-skill namespace: token-gated discovery, fail-loud collisions, load-time provenance, read-only mirror). Those PRs' descriptions document the M2 design detail; their commits (bdef497a5, 78598d091) are fast-forwarded here unchanged (authorship preserved — no rebase/squash of the history). One review covers everything; no stacked-merge sequencing or squash-loss retargeting needed anymore.

Summary

Adds the HSP/1 sync client to hermes-agent — pushes and pulls a user's personal skills to the gateway-gateway sync plane (Milestone 1 of Collective Wisdom). Client half of a three-repo change (server: gateway-gateway feat/hsp-sync-plane; UI: nous-account-service feat/sync-ui), built to the frozen hsp-1-contract.md.

What's in it

  • tools/skills_sync_client.py — the HSP/1 client: content-addressed snapshot of a skill directory into blob/tree/commit objects (full-64-hex sha256, canonical JSON), push via multipart/form-data raw-bytes, pull via ref diff + object fetch, and a three-way merge on conflict.
  • Merge reuses existing machinery_is_tracked_user_modification + the origin/user/incoming decision block from tools/skills_sync.py; on a 409 it fetches the actual head, three-way merges, and either retries CAS (non-overlap) or writes a refs/user/<owner>/conflict/<n> head for out-of-band resolution (true overlap).
  • Push hook — debounced, in the skill_manage success path (after the write-gate, so staged-unapproved writes don't push).
  • Pull hook — a maybe_pull_skills cloning the curator's gate-and-swallow shape, at the existing tick sites.
  • Auth — reuses resolve_nous_runtime_credentials() (no re-implemented refresh); the returned key is the Authorization: Bearer.
  • CLIhermes sync status|pull|push|now.

Scope (M1)

Agent-created + user-authored skills under ~/.hermes/skills/ only. Bundled and hub-installed skills are excluded. Opt-in (provisional): nothing syncs unless a skill is marked for sync. Memory is M1.5, out of scope here.

NAS-admin-only dev gate

Per the initial-development constraint, client sync is inert (no push, no pull, no-op) unless the resolved identity's Nous token carries tool_gateway_admin === true. The gate is checked first; without it, sync silently does nothing. Commented as a dev-phase gate.

Cross-repo interop verified

A cross-language conformance harness runs this client's canonicalization and the server's hash.ts over identical fixtures (blob, tree, commit, key-shuffled commit): byte-identical canonical JSON and identical sha256 addresses on both sides. The client's multipart/form-data raw-bytes upload matches the server's parser.

Verification

  • scripts/run_tests.sh (the three touched modules) → 252 passed, 0 failed (29 new sync-client tests + 223 regression), tested against a mocked HSP server.
  • ruff clean on new files.

Depends on

The server PR (gateway-gateway feat/hsp-sync-plane) must merge first — the client's E2E path integration-tests against a live sync plane. This PR is safe to review in parallel; the client is inert without the admin gate + a configured sync endpoint.

Infographic

hsp-sync-client

…and)

Implements the hermes-agent HSP/1 sync CLIENT against the frozen wire
contract (~/src/specs/collective-wisdom/hsp-1-contract.md §8), tested
against an in-process mock HSP server.

tools/skills_sync_client.py (new, low-level; does NOT import the CLI):
  * Full 64-hex sha256 content addressing + canonical JSON (§2.1/§2.5,
    OI-5) — kept distinct from the truncated local content_hash namespace.
  * HSPClient: capabilities/refs/objects GET, batch object upload
    (multipart, raw bytes per §1/§4.2), CAS ref (§4.4) with 409->HSPConflict.
  * Object building: skill dir -> blob/tree/commit; exec-bit preserved,
    symlinks skipped, oversize (413) surfaced; profile-root category trees.
  * push/pull + three-way merge (M1-C): reuses the origin/user/incoming
    decision semantics of skills_sync.py; non-overlap -> merge commit +
    retry CAS; true overlap -> refs/user/<owner>/conflict/<n> + surface.
  * DEV-PHASE gate: sync is INERT unless the resolved Nous token carries
    tool_gateway_admin===true (decoded from the bearer; server re-verifies).
  * Auth reuses resolve_nous_runtime_credentials() (no refresh reimpl).
  * maybe_push_skills / maybe_pull_skills gate-and-swallow entrypoints.

Opt-in (M1-D): tools/skill_usage.set_sync / is_sync_enabled — a `sync`
flag on the .usage.json sidecar; nothing syncs unless opted in. Only
agent-created/user-authored skills are eligible (bundled/hub excluded).

Hooks:
  * Debounced push in skill_manage success block (after the write gate).
  * Periodic pull at the two curator tick sites (gateway housekeeping loop
    + CLI startup).

CLI: hermes sync status|pull|push|now|enable|disable
  (hermes_cli/subcommands/sync.py + cmd_sync in main.py).

Tests: tests/tools/test_skills_sync_client.py — 29 tests (addressing,
canonicalization, dev gate, opt-in, object building, merge decisions, and
e2e push/pull/idempotency/conflict against a stdlib mock HSP server).
@alt-glitch alt-glitch added type/feature New feature or request comp/cli CLI entry point, hermes_cli/, setup wizard comp/gateway Gateway runner, session dispatch, delivery tool/skills Skills system (list, view, manage) P3 Low — cosmetic, nice to have needs-decision Awaiting maintainer decision before any implementation labels Jul 18, 2026
@alt-glitch

Copy link
Copy Markdown
Collaborator

This was generated by AI during triage.

Related to #39343 and #62753: this introduces a distinct cloud HSP protocol rather than git-based profile backup. The opt-in admin-gated rollout and multi-repo contract need a maintainer decision.

@tonydwb tonydwb left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review Summary

Verdict: Comment

+1976 additions / 8 files. New HSP/1 personal skill sync client (M1 client) — adds hermes sync <status|pull|push|now|enable|disable> CLI command, periodic background pull on gateway/CLI startup, and a tools/skills_sync_client.py module. The sync is gated behind a DEV-PHASE flag and tool_gateway_admin.

Large new feature addition without visible tests in the diff. Given the scope and that this is a new sync mechanism, flagging for human review before merge. The security surface (credentials, skill fetching from remote URL, write-back to local filesystem) warrants careful review.


Reviewed by Hermes Agent

…evice

Replace the device-local opt-in model (`.usage.json` `sync` flag as the sole
source of truth) with the §2.8 content model: a root-level `sync-manifest` blob
in the tree at `refs/user/<owner>/HEAD` recording per-skill {name, enabled},
matching gateway-gateway src/sync/manifest.ts byte-for-byte.

- build/parse_sync_manifest: canonical {type,version:1,skills:[{name,enabled}]},
  strict parse (malformed != empty).
- snapshot_profile embeds the manifest as a root-level blob alongside skill
  subtrees; the skill walk skips it (blob, not a SKILL.md-bearing tree).
- pull reconciles local opt-in intent FROM the plane manifest, so a skill opted
  in on one device becomes opted in on the others (opt-in is now cross-device,
  not per-device). Never silently disables a locally-enabled skill on pull.
- .usage.json `sync` flag kept as the editable local intent; plane manifest is
  authoritative.

Cross-repo byte-compat verified: the Python client's manifest bytes parse
cleanly through gateway-gateway's real parseSyncManifest (tsx harness).

Tests: 34 pass incl. 5 new (roundtrip, wire shape, strict-reject, root-blob
embed, pull adopts opt-in from manifest).
@github-actions

github-actions Bot commented Jul 22, 2026

Copy link
Copy Markdown
Contributor

૮ >ﻌ< ა ci review

ran on f5b68ad

ℹ️ Info

Desktop E2E visual evidence · View test artifacts · View job

1 visual diff.

inline evidence upload failed.

Failed to upload diff-665a0833239e-onboarding-overlay-diff.png with gh image (exit code 1): Error uploading /home/runner/work/_temp/e2e-evidence/diff-665a0833239e-onboarding-overlay-diff.png: step 0 (get upload token): uploadToken not found on repo page — do you have write access to NousResearch/hermes-agent? (or, if NousResearch enforces SAML SSO, authorize at https://github.com/orgs/NousResearch/sso)

Two changes:

1) Rename the client-local head-bookkeeping file .sync_manifest -> .sync_state
   (read_sync_state/write_sync_state) to remove the name collision with the
   §2.8 plane 'sync-manifest' OBJECT. read_sync_state migrates an existing
   .sync_manifest on first read so no device loses its head record.

2) Make the knobs a Hermes Cloud instance needs env-configurable, so an
   instance can be set up to use sync BY DEFAULT with no config.yaml edit or
   per-skill CLI call. Precedence: HERMES_SYNC_* env -> config.yaml sync.* ->
   built-in default (mirrors the existing HERMES_SYNC_BASE_URL bridge).
     - HERMES_SYNC_ENABLED        -> sync.enabled        (master on/off; def off)
       gated in maybe_push/maybe_pull alongside the dev-gate + base_url.
     - HERMES_SYNC_DEFAULT_OPT_IN -> sync.default_opt_in  (M1-D policy; def off)
       opt-out mode: every eligible skill syncs unless usage rec says sync:false;
       'your skills follow you with no setup' — the Cloud default. opt-in mode
       (default) unchanged: only sync:true skills sync.
   sync_status() + 'hermes sync status' surface feature_enabled/default_opt_in.

Cross-repo byte-compat re-verified: client manifest bytes still parse cleanly
through gateway-gateway parseSyncManifest.

Tests: 41 pass (+7: env precedence, opt-out/opt-in policy, rename migration).
… env seed)

Commit author.device was an opaque uuid4 hex, so the sync console showed a hash
per device. Make it human-friendly:

- Default: seed new devices from the short hostname + a short random suffix
  (e.g. bens-macbook-a1b2c3) instead of a bare uuid. Existing .sync_device_id
  files are honored verbatim (a machine keeps its id) — backward-compatible.
- hermes sync device [--name N]: show or set an explicit label
  (set_device_name(), written to ~/.hermes/skills/.sync_device_id). New commits
  use it; past commits keep their old label (author.device is immutable).
- Hermes Cloud: HERMES_SYNC_DEVICE_NAME env seeds the first-use label so a
  hosted instance shows a recognizable name with no CLI call. Precedence:
  explicit .sync_device_id file > HERMES_SYNC_DEVICE_NAME env > hostname default.
  Env seeds first-use only, then persists, so a later --name still wins locally.

Tests: 46 pass (+5: hostname default, file-wins precedence, env first-use seed +
persistence, set/trim, empty-name reject). CLI verb smoke-verified end-to-end.
test_startup_plugin_gating::test_builtin_set_covers_every_registered_subcommand
failed: 'sync' was a live subcommand but missing from _BUILTIN_SUBCOMMANDS. This
pre-existed on the branch (the original sync command was never registered here);
CI's registry-completeness guard caught it. Beyond the test, the omission meant
'hermes sync ...' triggered a ~500-650ms plugin-discovery pass it should skip.

Add 'sync' to the frozenset. Guard test + sync suites green (84 passed).
… 202 handling

Client leg of M2 org-shared skills (hsp-1-contract.md §11), pairing with
gateway-gateway #162 and NAS #768 (both merged).

- resolve_org_identity(): org_id + org_role from the token claims. NO
  org_role claim (personal org — NAS only stamps it for multi-member orgs)
  => SyncInertError => every org surface is inert; personal M1 sync
  untouched (contract §11.1 REFINED). org_sync_available() for callers.
- pull_org_skills(): materialize the org canonical set (refs/org/<org_id>/
  HEAD) into ~/.hermes/skills/_org/<org_id>/ — fast-forward only, no client
  merge on the org path (design.md §2.6); read-only mirror by convention
  (§7.1: a local edit is a personal fork until proposed). maybe_pull_org_
  skills() best-effort hook (never raises; inert without the claim).
- propose_skill(): snapshot the LOCAL skill dir, splice it into the org
  HEAD's skill-tree map (per-skill delta, never wholesale replace), upload
  ?scope=org, CAS the org HEAD. ADMIN => direct merge; MEMBER => server
  converts to a proposal — cas_ref now surfaces 202 as
  {proposal_pending: True, proposal_id, ref} (success-shaped, NEVER
  presented as live). Non-interactive by design for the future automated
  submitter (Ben's trajectory note).
- put_objects(org_scope=True) adds ?scope=org (contract §11.5).
- is_sync_eligible(): skills under _org/ are excluded from PERSONAL sync —
  enterprise content never rides a personal push (§11.11).
- CLI: hermes skills propose <name> [-m msg] — prints 'pending admin
  review' for 202, 'merged' for admin, and a plain 'org sync unavailable'
  for personal orgs instead of a raw 403.

Tests: 56 in the sync client suite (+10 org: identity gate both ways, _org/
personal-sync exclusion, admin direct merge, member 202 w/ HEAD untouched +
proposal ref parked + never-merged, splice-not-replace root, pull mirror
materialization, no-head noop, org-feature gate, maybe_pull inert). Mock
server extended (org feature flag, member-CAS→202). 103 across skills
suites. Live CLI smoke: propose --help + personal-org inert path verified.
…collisions, provenance (M2)

Implements the agreed design (2026-07-23): org skills are FIRST-CLASS (bare
names) with three hard companions.

1. TOKEN-GATED RESOLUTION: _org/<org_id>/ mirrors resolve ONLY while marked
   active. pull_org_skills (which runs only after the token's org_id+org_role
   verified) writes _org/.active_org; discovery (iter_skill_index_files,
   _find_skill_dir, snapshot manifest) prunes every other mirror. Leave the
   org (verified personal token in maybe_pull_org_skills) => marker cleared
   => org skills stop resolving; offline => marker untouched (grace).
   Snapshot manifest includes the marker so org switches invalidate the
   prompt snapshot; _SKILLS_SNAPSHOT_VERSION bumped to 2.

2. FAIL-LOUD COLLISIONS: listing pass unified across snapshot/scan paths;
   a personal/org name clash flags BOTH entries '[name collision — load via
   category path]' — neither side silently wins (personal-wins = silent
   divergence from the org set; org-wins = shadowed personal work).
   skill_view's existing multi-candidate refusal already rejects the
   ambiguous bare name.

3. PROVENANCE: org entries list under an org:<org_id> category with
   '[org-shared: by <author>]' tags; skill_view prepends a load-time header
   (org, author, as-of + read-only/fork-and-propose guidance) INTO the
   content the model consumes, plus an org_provenance result field. Author
   comes from the pull-time .org-provenance.json sidecar (HEAD commit author
   — token-verified at push by the plane's author_mismatch guard, gg #166).

4. READ-ONLY MIRROR: skill_manage patch/edit/delete/write_file refuse org-
   mirror targets with fork-and-propose guidance; org skills are curation-
   exempt (is_curation_eligible False — the org HEAD owns them).

Tests: 11 new (tests/agent/test_org_skill_namespace.py) covering gating,
stale-mirror pruning, org-switch flip, snapshot provenance, listing labels,
both-sides collision flags, read-only guard, curation exemption; 448 green
across skills/prompt/sync suites. Live E2E (real modules, temp HERMES_HOME,
mock plane): merge -> pull -> marker+sidecar -> labeled listing -> exactly-2
collision flags -> load-time header -> edit refused -> marker cleared =>
org skills vanish, personal survive.
Two defects found by manual testing on the branch.

1. ORG SYNC NEVER RAN. The org pull/mirror/gating machinery was fully
   implemented and unit-tested but had ZERO runtime callers —
   maybe_pull_org_skills() was referenced only inside a comment, and
   `hermes sync` had no org path at all. Every code path fell through to
   personal sync (refs/user/<sub>/), so org skills never loaded and the
   feature looked like 'everything syncs to my personal org' even with a
   valid org token. The unit tests could not catch this: they invoked the
   functions directly, which is exactly the gap they left open.

   - cli.py session startup now calls maybe_pull_org_skills() alongside the
     personal maybe_pull_skills(), fail-quiet.
   - Auto-pull is gated on real org membership: resolve_org_identity()
     requires an org role on the token, only issued for multi-member orgs,
     so a solo account never reaches the network.
   - `hermes sync pull` refreshes the org mirror too (one pull, both
     surfaces) and reports what it refreshed.
   - `hermes sync status` exposes org_available/org_id/org_role/org_skills
     plus a plain-language summary, so a user can tell whether the org
     workflow applies instead of it being invisible.

2. INTERNAL JARGON LEAKED TO USERS. Help text and errors exposed internal
   milestone/spec coordinates: 'Propose a skill ... (M2)', 'Personal skill
   sync (HSP/1)', 'DEV-PHASE gate closed: your token lacks
   tool_gateway_admin', 'contract §4.3', and an inert message describing our
   internal personal-vs-multi-member design split. All rewritten in user
   language. Feature-local comments/docstrings lost their internal
   coordinates (§N, M1/M2, design.md, PR numbers) while keeping the
   explanatory prose. Pre-existing issue references elsewhere in the tree
   were deliberately left untouched.

Tests: 4 new guards, including two that assert the CALL SITES exist so the
org pull cannot silently become dead code again (verified failing when the
wiring is removed) and one that fails if user-facing help leaks jargon.
344 passed across the sync/skills/prompt suites.

Verified against live staging with a real org token: sync status reports
org_available=true, org_role=OWNER; sync pull performs the org refresh; the
.active_org marker is written with the org id from the token.
pull_org_skills/propose_skill resolved and demanded HERMES_SYNC_BASE_URL
before using the caller-provided `client`, which already carries its own
base URL. Only resolve/require it on the path that actually constructs a
client.

Caught by scripts/run_tests.sh, which blanks env vars to match CI. Plain
`pytest` masked it: my shell had HERMES_SYNC_BASE_URL exported from live
testing, so the redundant check silently passed. Reproduced deliberately
with `env -u HERMES_SYNC_BASE_URL pytest` before fixing.

371 passed / 0 failed across the sync, skills, prompt, and skill-utils
suites via the canonical runner.
`hermes sync` gave no hint that org sharing exists, so there was no path
from 'I want to share this with my team' to `hermes skills propose` — sync
looked like the only sharing surface while being personal-only (it always
CAS-es refs/user/<owner>/HEAD).

- Bare `hermes sync` usage and the `--help` epilog now state that these
  commands are personal-only and name `hermes skills propose <skill>` as
  the org path, noting the approval step and that org skills arrive
  automatically and are read-only locally.
- Scrubbed the remaining internal jargon from the sync module docstring
  (M1-D, DEV-PHASE, HSP/1) missed by the earlier pass, which only covered
  help= strings.

Tests: 2 new guards asserting both surfaces reference the org command.
373 passed / 0 failed via scripts/run_tests.sh. Both outputs verified by
running the actual commands.
…rg updates

The read-only org mirror broke the learning loop precisely where it matters
most. The system prompt tells every agent to patch a skill the moment it
finds a gap, and shared skills are the ones the most people use — but every
write to _org/ was refused, and the curator was excluded from them outright.
So org skills froze while personal skills kept improving, and the offered
alternative ("fork it into a personal skill, then propose the fork") is not
something an agent does mid-task. The refusal WAS the feature; improvements
were simply lost, and manual forks would have fragmented the shared set.

Edit in place:
- skill_manage patch/edit/write_file now work on org skills. Only delete is
  still refused (the mirror is a view of org HEAD — a local delete returns on
  the next pull; removing a shared skill is an admin action).
- Org skills are curation-eligible again, so the curator can improve the
  highest-leverage skills in the system instead of skipping them.
- The load-time provenance header now says edits are allowed and kept,
  instead of instructing the agent not to edit.

Local edits are never overwritten:
- pull_org_skills previously rmtree'd each skill dir and re-materialized it,
  silently destroying local work on the next session start. It now records a
  content fingerprint per skill (.org-baseline.json) when it writes one, and
  SKIPS any skill whose local content diverges from that baseline.
- When upstream ALSO changed such a skill, it is reported in the pull
  result's "conflicted" list and left untouched for the user to resolve
  deliberately (propose the local version, or delete it and re-pull to take
  theirs). A missing baseline is treated as unmodified so pre-existing
  mirrors do not raise phantom conflicts.
- Fingerprints are content-based (path + bytes, sorted), so a touch/mtime
  change is not mistaken for an edit.

Sharing back:
- Default: the edit stays local and the tool result tells the user to run
  "hermes skills propose <skill>".
- Opt-in sync.org_auto_propose / HERMES_SYNC_ORG_AUTO_PROPOSE submits each
  edit immediately. Defaults OFF — pushing every agent edit to a whole
  organisation is not a safe default. A failed submission never fails the
  edit; the change is saved and can be proposed later.
- "hermes sync status" lists org skills with unshared local edits;
  "hermes sync pull" reports conflicts it declined to overwrite.

Tests: 25 in the namespace suite (was 15). The two that asserted the old
read-only behaviour now assert the opposite. New coverage for edit-applied,
share-back guidance, delete-still-refused, curation-allowed, edit detection,
missing-baseline tolerance, mtime-insensitivity, and the auto-propose
default. 428 passed / 0 failed via scripts/run_tests.sh.

Verified through the REAL pull path against a mock plane: pull v1 -> edit in
place -> upstream ships v2 -> pull leaves the local edit intact, reports the
conflict, and surfaces it in status.
@benbarclay
benbarclay force-pushed the feat/hsp-sync-client branch from b76b684 to 981feb6 Compare July 27, 2026 23:08
…SP naming

Encapsulates the feature behind one command for launch, and adopts the
official product name.

One command:
- `propose` moves from `hermes skills propose` to `hermes sync propose`, so
  the whole feature is one command to learn and one to document. Its handler
  moves from cmd_skills to cmd_sync accordingly.
- The `hermes sync` parser now documents both halves plainly: personal sync
  across your devices, and sharing with your organisation. Added an examples
  epilog; rewrote the verb help in user language ("Include a skill in your
  sync" rather than "Opt a skill into sync").
- Every user-facing string that pointed at `hermes skills propose` now points
  at `hermes sync propose` (8 sites, including the agent-visible guidance
  returned by skill_manage and the org provenance header).

This also clears the way for #39343, which adds its own top-level `sync` for
git-repo profile backup — that feature nests under `skills`, this one owns
`sync`.

Naming:
- HSP / "Hermes Sync Protocol" is gone from prose, docstrings, and comments.
  The feature is "Skill Sync".
- Public identifiers renamed: HSPClient -> SyncClient, HSPError -> SyncError,
  HSPConflict -> SyncConflict, hsp_address -> wire_address, HSP_VERSION ->
  WIRE_VERSION.
- The WIRE names are deliberately NOT renamed: the `hsp_version` capability
  field and the `x-hsp-object-type` response header are set by the deployed
  gateway-gateway sync plane (verified in src/sync/syncRouter.ts), so
  renaming them client-side would break sync against a live server. A comment
  at the version constant records why they differ from the product name.
- The version-mismatch error is now actionable ("this server speaks sync
  version X, but this Hermes speaks Y — update Hermes to sync with it")
  instead of leaking the protocol acronym.

Also fixes a wiring gap found on the way: the gateway housekeeping tick
pulled personal skills but never org skills — the same defect already fixed
for the CLI. Org pull now runs there too, gated on real org membership.

Tests: the jargon guard now also fails on a bare "HSP". The two tests that
asserted the old cross-command structure are replaced by three asserting the
new one (propose IS under sync, propose is NOT under skills, sync usage
lists it). 2294 passed / 0 failed across all 51 suites that import the
changed modules, via scripts/run_tests.sh.

Verified by running the real CLI: `hermes sync --help` lists all eight verbs,
`hermes skills --help` no longer mentions propose, `hermes sync propose
--help` parses, and `hermes sync status` still reports live org state.
The client called its gate "the DEV-PHASE gate (tool_gateway_admin)", which
reads as though Skill Sync is gated on an unrelated service's admin right.
It isn't. NAS populates that claim from Permissions.ADMIN_ACCESS — the global
portal admin permission that guards /admin/* — so the gate is "is this user a
Nous admin?". The claim is simply named for its first consumer, the tool
gateway.

Renamed on this side to say what it means, while keeping the wire string
(other services read it):

- DEV_GATE_CLAIM -> NOUS_ADMIN_CLAIM (value unchanged: "tool_gateway_admin",
  with a comment recording why the wire name differs).
- identity/status key dev_gate_ok -> nous_admin, across the client, the CLI
  consumers, and the tests.
- The module docstring now states where the claim comes from, that the wire
  name is misleading, and that this gate is pre-launch containment rather
  than the shipping entitlement — admin status conflates "may administer
  Nous" with "has Skill Sync enabled" and has no middle setting for a beta
  cohort. Choosing the real entitlement is left as a separate decision.

Naming only — no behaviour change, and no change to which accounts can sync.
The user-facing messages stay deliberately vague ("not enabled for your
account yet") rather than telling users they need portal admin.

Verified: 2346 passed / 0 failed across 56 suites via scripts/run_tests.sh;
`hermes sync status` against a live token reports "nous_admin": true. Zero
stale dev_gate_ok / DEV_GATE_CLAIM references remain.
Skill Sync had no default base URL, so a user with no `sync.base_url` in
config.yaml and no HERMES_SYNC_BASE_URL got:

    sync inert: no sync base URL configured (config.yaml sync.base_url
    or HERMES_SYNC_BASE_URL).

Every sync command was unusable out of the box. The URL was left unset
because the plane did not exist yet when the client was written; it does now.

- Adds DEFAULT_SYNC_BASE_URL = "https://gateway-gateway.nousresearch.com" and
  returns it as the last step of resolve_sync_base_url().
- Resolution order is unchanged otherwise: HERMES_SYNC_BASE_URL ->
  config.yaml sync.base_url -> production default. The env var and config key
  now exist to point a dev/staging build at another plane rather than to make
  the feature work at all.
- Follows the existing precedent for production endpoints in this codebase
  (DEFAULT_NOUS_PORTAL_URL in hermes_cli/auth.py, HERMES_DIAGNOSTICS_BASE_URL
  in diagnostics_upload.py): a module constant with env/config override.

The "no sync base URL configured" guards are kept — they are now unreachable
in practice but remain correct if the default is ever blanked.

Tests: 3 new — the default is returned when nothing is configured, config
still overrides it, and the constant is a bare https origin (no trailing
slash, no path) since the client appends /v1/sync/. 2349 passed / 0 failed
across 56 suites via scripts/run_tests.sh.

Verified against a temp HERMES_HOME with no config: resolves to the
production plane; HERMES_SYNC_BASE_URL and sync.base_url both still win, and
trailing slashes are stripped.
Resolves the PR's conflict with main (2252 commits). Two conflicts, both
"each side added an independent block in the same place" — kept both:

- gateway/run.py — the housekeeping loop. This branch adds the Skill Sync
  pulls inside the CURATOR_EVERY branch (12-space indent); main adds a
  stale-session auto-archive as a sibling `if` at loop level (8-space).
  Different scopes, so the naive union would have mis-nested the archive
  block into the curator branch; kept each at its own indent level.
- tools/skill_manager_tool.py — the _edit_skill result dict. This branch
  appends the org auto-propose note; main appends
  _add_description_prompt_preview(). Independent, order-insensitive.

No behaviour dropped from either side.

Verified: 3552 passed / 0 failed across 63 suites (scope regenerated to
include main's new maybe_auto_archive / _add_description_prompt_preview
consumers) via scripts/run_tests.sh. `hermes sync` and `hermes sync status`
still work against a live token, resolving the production plane default.

The Pyright Optional-parameter warnings in skill_manager_tool.py are
pre-existing on main (`content: str = None` etc.), not introduced here.
@teknium1
teknium1 merged commit 1a08898 into main Jul 29, 2026
38 checks passed
@teknium1
teknium1 deleted the feat/hsp-sync-client branch July 29, 2026 22:20
gabrielcosi pushed a commit to gabrielcosi/home-ops that referenced this pull request Aug 5, 2026
….7.30 ➔ v2026.8.3) (#253)

This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| [ghcr.io/gabrielcosi/hermes-agent](https://github.com/NousResearch/hermes-agent) | minor | `v2026.7.30` → `v2026.8.3` |

---

### Release Notes

<details>
<summary>NousResearch/hermes-agent (ghcr.io/gabrielcosi/hermes-agent)</summary>

### [`v2026.8.3`](https://github.com/NousResearch/hermes-agent/releases/tag/v2026.8.3): Hermes Agent v0.20.0 (2026.8.3)

[Compare Source](https://github.com/NousResearch/hermes-agent/compare/v2026.7.30...v2026.8.3)

##### Hermes Agent v0.20.0 (v2026.8.3)

**Release Date:** August 3, 2026
**Since v0.19.0:** \~3,650 commits · \~1,400 merged PRs · \~5,200 files changed · \~559,000 insertions · \~405,000 deletions · **\~1,200 issues closed** · 650+ contributors

> **The Herald Release.** Hermes is the herald of the gods, and this release makes him one in earnest: he **speaks** (real-time conversational voice with streaming TTS, barge-in, on-device wake words, and hands-free control across the CLI, desktop, and every audio-capable gateway platform), he **carries word to other agents** (A2A v1.0), he **announces events to your systems** (signed outbound webhooks), and he **cites his sources** (grounded research with verifiable citations and fact-checking). Around that spine: the desktop app became a platform (artifacts with live preview, a plugin SDK, quick-entry from anywhere, multiple windows), the CLI got a wave of power commands (`!` shell mode, `/init`, `/diff`, `/context`, `/focus`), compression got smarter and gentler, and the tools themselves now recover from their own failures instead of making the model guess. This release rolls up everything from the v0.19.1 infrastructure patch tag — that window is fully documented here.

***

##### ✨ Highlights

- **Talk to Hermes — streaming, conversational voice with barge-in** — Voice mode used to mean: speak, wait for the whole reply to generate, then listen to one long audio file. Now Hermes speaks clause-by-clause as the response streams, you can interrupt it mid-sentence by just talking (it stops, listens, and the model is told you cut in), and busy-aware silence detection means it doesn't talk over you. This works in CLI voice mode, on the desktop, and through gateway adapters. Talking to Hermes finally feels like a conversation, not a voicemail exchange. ([#&#8203;69511](https://github.com/NousResearch/hermes-agent/pull/69511), [#&#8203;73862](https://github.com/NousResearch/hermes-agent/pull/73862), [#&#8203;74223](https://github.com/NousResearch/hermes-agent/pull/74223), [#&#8203;74000](https://github.com/NousResearch/hermes-agent/pull/74000), [#&#8203;69602](https://github.com/NousResearch/hermes-agent/pull/69602) — [@&#8203;teknium1](https://github.com/teknium1), [@&#8203;OutThisLife](https://github.com/OutThisLife))

- **Wake words and hands-free control** — Say your own open-vocabulary wake phrase ("hey Hermes", or anything you pick) and Hermes starts listening — detection runs on-device, so no audio leaves your machine while it waits. Multi-profile voice routing means different wake words can reach different profiles, and saying "stop" ends the voice chat on every surface without touching the keyboard. Your terminal is now something you can talk to from across the room. ([#&#8203;70509](https://github.com/NousResearch/hermes-agent/pull/70509), [#&#8203;73106](https://github.com/NousResearch/hermes-agent/pull/73106), [#&#8203;73933](https://github.com/NousResearch/hermes-agent/pull/73933) — [@&#8203;teknium1](https://github.com/teknium1))

- **Voice on every platform** — Send a voice note to Hermes on WhatsApp, Feishu, DingTalk, LINE, QQ, Photon, or Weixin and it's transcribed and answered; auto-TTS replies are delivered platform-aware (opus where platforms want opus, captions attached correctly). STT is now fully configurable — its own `hermes tools` category, GUI toggles, dashboard dropdowns, unified language resolution so transcripts stop coming back in the wrong language, and OpenAI's gpt-transcribe support. One unified spoken-text preprocessor cleans markdown, code, and URLs out of speech across all TTS providers. ([#&#8203;73515](https://github.com/NousResearch/hermes-agent/pull/73515), [#&#8203;73508](https://github.com/NousResearch/hermes-agent/pull/73508), [#&#8203;73910](https://github.com/NousResearch/hermes-agent/pull/73910), [#&#8203;73513](https://github.com/NousResearch/hermes-agent/pull/73513), [#&#8203;73067](https://github.com/NousResearch/hermes-agent/pull/73067) — [@&#8203;teknium1](https://github.com/teknium1))

- **Research you can trust — grounded citations with fact-checking** — The new `grounded-citations` skill makes Hermes produce research where every claim is backed by a verifiable source: quotes are matched against the actual page text (not hallucinated), citations link to the exact evidence, and a fact-checking mode turns the same machinery on any document or claim you hand it — it tells you what checks out, what doesn't, and what couldn't be verified. If you use Hermes for research, this is the difference between "sounds right" and "provably sourced." ([#&#8203;71698](https://github.com/NousResearch/hermes-agent/pull/71698), [#&#8203;77104](https://github.com/NousResearch/hermes-agent/pull/77104) — [@&#8203;teknium1](https://github.com/teknium1))

- **Outbound webhooks — Hermes pushes events to your systems** — Until now, integrating with Hermes meant polling or listening on a platform. Now Hermes pushes **signed lifecycle events** (session activity, turn completions, tool events) to any HTTP endpoint you register — with HMAC signatures so your receiver can verify authenticity. Wire Hermes into your CI, your home automation, your dashboards, or any service that speaks HTTP, with no polling loop. ([#&#8203;69406](https://github.com/NousResearch/hermes-agent/pull/69406) — [@&#8203;teknium1](https://github.com/teknium1))

- **The desktop app becomes a platform — artifacts, plugin SDK, quick entry** — Hermes desktop now renders **artifacts**: versioned cards with sandboxed live preview in a right-rail viewer, so generated HTML/apps run safely next to the chat. A real **plugin SDK** landed with Kanban as its founding plugin, `ctx.download` for handing users files, floating pane placement, and multiple GUI windows. A global-hotkey **quick-entry window** captures a thought into any session from anywhere in your OS. The desktop stopped being a chat client and started being a workbench. ([#&#8203;72345](https://github.com/NousResearch/hermes-agent/pull/72345), [#&#8203;61173](https://github.com/NousResearch/hermes-agent/pull/61173), [#&#8203;74413](https://github.com/NousResearch/hermes-agent/pull/74413), [#&#8203;72315](https://github.com/NousResearch/hermes-agent/pull/72315), [#&#8203;68259](https://github.com/NousResearch/hermes-agent/pull/68259), [#&#8203;73143](https://github.com/NousResearch/hermes-agent/pull/73143) — [@&#8203;OutThisLife](https://github.com/OutThisLife), [@&#8203;teknium1](https://github.com/teknium1))

- **Hermes speaks Agent-to-Agent — A2A v1.0** — A new bundled plugin implements the Agent-to-Agent protocol, so Hermes can discover, talk to, and be driven by other A2A-compatible agents. This closes issue [#&#8203;514](https://github.com/NousResearch/hermes-agent/issues/514) — one of the oldest open feature requests in the repo. If you're building multi-agent systems with heterogeneous stacks, Hermes now has a standard wire protocol for joining them. ([#&#8203;77109](https://github.com/NousResearch/hermes-agent/pull/77109) — [@&#8203;teknium1](https://github.com/teknium1))

- **CLI power-user wave** — `!command` runs a shell command instantly without spending a model turn. `/init` scans your project and generates (or updates) an `AGENTS.md`. `/diff` shows staged/all/session changes from any surface, `/context` breaks down exactly what's filling your context window, `/focus` gives you a reduced-output view with hidden-line recovery, and Ctrl+S stashes a half-written prompt into a browsable panel. Plus `hermes import-agent` migrates your Claude Code or Codex CLI setup into Hermes in one command. ([#&#8203;72257](https://github.com/NousResearch/hermes-agent/pull/72257), [#&#8203;72178](https://github.com/NousResearch/hermes-agent/pull/72178), [#&#8203;72240](https://github.com/NousResearch/hermes-agent/pull/72240), [#&#8203;72242](https://github.com/NousResearch/hermes-agent/pull/72242), [#&#8203;72302](https://github.com/NousResearch/hermes-agent/pull/72302), [#&#8203;72262](https://github.com/NousResearch/hermes-agent/pull/72262), [#&#8203;72190](https://github.com/NousResearch/hermes-agent/pull/72190) — [@&#8203;teknium1](https://github.com/teknium1), several salvaging long-standing community PRs)

- **Correct the agent mid-turn — redirects** — If Hermes is heading the wrong way, you no longer have to `/stop` and re-explain. Type a correction while it works and the active turn is redirected: work in flight is preserved, the original prompt is kept, and the agent course-corrects with your new guidance. Paired with double-ESC draft discard and a composer undo stack, steering feels like editing, not restarting. ([#&#8203;63104](https://github.com/NousResearch/hermes-agent/pull/63104), [#&#8203;72339](https://github.com/NousResearch/hermes-agent/pull/72339), [#&#8203;74736](https://github.com/NousResearch/hermes-agent/pull/74736) — [@&#8203;OutThisLife](https://github.com/OutThisLife))

- **Tools that fix themselves** — A sweep of self-recovery upgrades means the agent wastes far fewer turns on tool friction: truncated terminal output spills to a file the agent can read back, `patch` detects already-applied edits and diagnoses whitespace mismatches, `write_file` verifies content on disk, searches that match nothing probe for near-misses and recover, and common failure classes come back with actionable hints. The default tool-calling iteration limit also jumped 90 → 500 — long autonomous runs stopped hitting an artificial wall. ([#&#8203;77041](https://github.com/NousResearch/hermes-agent/pull/77041), [#&#8203;76998](https://github.com/NousResearch/hermes-agent/pull/76998), [#&#8203;77024](https://github.com/NousResearch/hermes-agent/pull/77024), [#&#8203;77055](https://github.com/NousResearch/hermes-agent/pull/77055), [#&#8203;77011](https://github.com/NousResearch/hermes-agent/pull/77011), [#&#8203;76992](https://github.com/NousResearch/hermes-agent/pull/76992), [#&#8203;72176](https://github.com/NousResearch/hermes-agent/pull/72176) — [@&#8203;teknium1](https://github.com/teknium1))

- **Compression that respects your conversation** — Context compression got a deep overhaul: proactive tool-result pruning for large-window models, per-turn micro-compaction that amortizes the cost instead of one giant pause, a guaranteed N-user-message tail so recent conversation always survives, progress-aware timeouts that stop punishing slow summary models, and ghost-skill defense so a pruned skill can never silently haunt a session. Thresholds are now configurable per-model and in absolute tokens. Long sessions stay coherent and stop stalling. ([#&#8203;70254](https://github.com/NousResearch/hermes-agent/pull/70254), [#&#8203;75345](https://github.com/NousResearch/hermes-agent/pull/75345), [#&#8203;70250](https://github.com/NousResearch/hermes-agent/pull/70250), [#&#8203;71508](https://github.com/NousResearch/hermes-agent/pull/71508), [#&#8203;70275](https://github.com/NousResearch/hermes-agent/pull/70275) — [@&#8203;teknium1](https://github.com/teknium1), [@&#8203;kshitijk4poor](https://github.com/kshitijk4poor), salvaging multiple community PRs)

- **Smart approvals grow up** — `hermes approvals suggest` mines your approval history into allowlist proposals, operators can customize the smart-approval policy, a consecutive-denial circuit breaker stops a misbehaving loop cold, and desktop pairing approvals are profile-correct with a proper surface to answer them from. Plus a new approval gate for docker/podman daemon-redirect commands. Less clicking "approve", without giving an inch of control. ([#&#8203;72259](https://github.com/NousResearch/hermes-agent/pull/72259), [#&#8203;72186](https://github.com/NousResearch/hermes-agent/pull/72186), [#&#8203;72203](https://github.com/NousResearch/hermes-agent/pull/72203), [#&#8203;74446](https://github.com/NousResearch/hermes-agent/pull/74446), [#&#8203;71092](https://github.com/NousResearch/hermes-agent/pull/71092) — [@&#8203;teknium1](https://github.com/teknium1), [@&#8203;OutThisLife](https://github.com/OutThisLife))

- **Faster everywhere, again** — Prompt caching now covers tool schemas on native Anthropic without history loss. `hermes -w` cold start dropped \~14s → \~1.8s, `hermes update` no-ops got 2–6s faster, heavy SDKs lazy-load off the import path, config reads stopped deep-copying (54× faster on the telemetry gate), and the desktop shipped a second 60fps wave — streaming cost independent of transcript length, drag at 60fps with five streaming tabs, idle CPU near zero in the background. ([#&#8203;76032](https://github.com/NousResearch/hermes-agent/pull/76032), [#&#8203;71637](https://github.com/NousResearch/hermes-agent/pull/71637), [#&#8203;74218](https://github.com/NousResearch/hermes-agent/pull/74218), [#&#8203;74204](https://github.com/NousResearch/hermes-agent/pull/74204), [#&#8203;71835](https://github.com/NousResearch/hermes-agent/pull/71835), [#&#8203;72346](https://github.com/NousResearch/hermes-agent/pull/72346), [#&#8203;75218](https://github.com/NousResearch/hermes-agent/pull/75218) — [@&#8203;kshitijk4poor](https://github.com/kshitijk4poor), [@&#8203;teknium1](https://github.com/teknium1), [@&#8203;OutThisLife](https://github.com/OutThisLife))

- **New places to run and be reached** — Buzz lands as a bundled gateway platform (Block's Nostr-based messenger, with native WebSocket transport and NIP-42 auth), the Vercel AI Gateway provider and Vercel Sandbox terminal backend return modernized, desktop gains an SSH remote-backend connection mode, and the Relay shipped four phases of parity — media, interactive prompts, thread lifecycle, typing indicators — plus HSP personal + org skill sync. ([#&#8203;73610](https://github.com/NousResearch/hermes-agent/pull/73610), [#&#8203;73761](https://github.com/NousResearch/hermes-agent/pull/73761), [#&#8203;74518](https://github.com/NousResearch/hermes-agent/pull/74518), [#&#8203;68130](https://github.com/NousResearch/hermes-agent/pull/68130), [#&#8203;71300](https://github.com/NousResearch/hermes-agent/pull/71300)–[#&#8203;71624](https://github.com/NousResearch/hermes-agent/pull/71624), [#&#8203;66730](https://github.com/NousResearch/hermes-agent/pull/66730) — [@&#8203;teknium1](https://github.com/teknium1), [@&#8203;yoniebans](https://github.com/yoniebans), [@&#8203;benbarclay](https://github.com/benbarclay))

***

##### 🎙️ Voice & Speech

##### Conversational voice

- Streaming, conversational TTS with barge-in across all surfaces; clause-by-clause synthesis for CLI voice mode + gateway adapters ([#&#8203;69511](https://github.com/NousResearch/hermes-agent/pull/69511), [#&#8203;73862](https://github.com/NousResearch/hermes-agent/pull/73862) — [@&#8203;OutThisLife](https://github.com/OutThisLife), [@&#8203;teknium1](https://github.com/teknium1))
- Voice chat UX polish — busy-aware silence, stop hint, thinking sounds, barge-in fix; full-duplex turn listener (interrupt by voice during generation AND playback) ([#&#8203;74000](https://github.com/NousResearch/hermes-agent/pull/74000), [#&#8203;74223](https://github.com/NousResearch/hermes-agent/pull/74223) — [@&#8203;teknium1](https://github.com/teknium1))
- On-device wake words with open-vocabulary phrases + multi-profile voice routing; say "stop" to end voice chat hands-free on every surface ([#&#8203;70509](https://github.com/NousResearch/hermes-agent/pull/70509), [#&#8203;73106](https://github.com/NousResearch/hermes-agent/pull/73106), [#&#8203;73933](https://github.com/NousResearch/hermes-agent/pull/73933) — [@&#8203;teknium1](https://github.com/teknium1))
- The model is told when the user interrupts its spoken reply; desktop speaks the whole turn and idle-flushes held narration ([#&#8203;69602](https://github.com/NousResearch/hermes-agent/pull/69602), [#&#8203;69936](https://github.com/NousResearch/hermes-agent/pull/69936) — [@&#8203;OutThisLife](https://github.com/OutThisLife), [@&#8203;teknium1](https://github.com/teknium1))
- 15-item CLI/TUI voice-mode UX and environment fix wave ([#&#8203;73520](https://github.com/NousResearch/hermes-agent/pull/73520) — [@&#8203;teknium1](https://github.com/teknium1))

##### TTS / STT infrastructure

- Unified spoken-text preprocessing + speed/instructions/provider tool params; unified STT language resolution (fixes the wrong-language transcription class); global `stt.language` defaults to `en` ([#&#8203;73513](https://github.com/NousResearch/hermes-agent/pull/73513), [#&#8203;73067](https://github.com/NousResearch/hermes-agent/pull/73067), [#&#8203;73100](https://github.com/NousResearch/hermes-agent/pull/73100) — [@&#8203;teknium1](https://github.com/teknium1))
- Fully configurable STT — `hermes tools` category, GUI toggle/matrix, dashboard dropdowns, setup status; OpenAI gpt-transcribe support ([#&#8203;73910](https://github.com/NousResearch/hermes-agent/pull/73910), [#&#8203;73853](https://github.com/NousResearch/hermes-agent/pull/73853) — [@&#8203;teknium1](https://github.com/teknium1))
- Platform-aware auto-TTS voice delivery (opus platforms, streamed/global gap, captions); inbound voice classification/routing for Feishu, DingTalk, LINE, QQ, Photon, WhatsApp, Weixin ([#&#8203;73508](https://github.com/NousResearch/hermes-agent/pull/73508), [#&#8203;73515](https://github.com/NousResearch/hermes-agent/pull/73515) — [@&#8203;teknium1](https://github.com/teknium1))
- Command TTS/STT provider hardening — idle timeouts, env scrubbing, no-shell, path guards ([#&#8203;73514](https://github.com/NousResearch/hermes-agent/pull/73514) — [@&#8203;teknium1](https://github.com/teknium1))
- Sync per-sentence TTS synthesis pipelined with playback — the next sentence renders while the current one speaks ([#&#8203;77355](https://github.com/NousResearch/hermes-agent/pull/77355) — [@&#8203;kshitijk4poor](https://github.com/kshitijk4poor))
- Discord voice PCM streams to ffmpeg stdin instead of a temp file ([#&#8203;76970](https://github.com/NousResearch/hermes-agent/pull/76970) — [@&#8203;kshitijk4poor](https://github.com/kshitijk4poor))

##### 🏗️ Core Agent & Architecture

##### Compression & context

- Proactive tool-result pruning for large-window models; per-turn micro-compaction; N-user tail guarantee (`compression.min_tail_user_messages`); bounded summarizer input with head+tail retention ([#&#8203;70254](https://github.com/NousResearch/hermes-agent/pull/70254), [#&#8203;75345](https://github.com/NousResearch/hermes-agent/pull/75345), [#&#8203;70250](https://github.com/NousResearch/hermes-agent/pull/70250), [#&#8203;70249](https://github.com/NousResearch/hermes-agent/pull/70249) — [@&#8203;teknium1](https://github.com/teknium1), [@&#8203;kshitijk4poor](https://github.com/kshitijk4poor))
- Ghost-skill defense — `[SKILL_PRUNED]` markers, protected prune, deterministic survival; progress-aware timeouts; lock-contended compression soft-defers instead of exhausting ([#&#8203;70275](https://github.com/NousResearch/hermes-agent/pull/70275), [#&#8203;71508](https://github.com/NousResearch/hermes-agent/pull/71508), [#&#8203;70285](https://github.com/NousResearch/hermes-agent/pull/70285) — [@&#8203;teknium1](https://github.com/teknium1))
- Per-model threshold overrides; absolute token threshold (`compression.threshold_tokens`); opt-in idle-triggered compaction; opt-in progress notices; structured local logging for compression attempts ([#&#8203;69339](https://github.com/NousResearch/hermes-agent/pull/69339), [#&#8203;69335](https://github.com/NousResearch/hermes-agent/pull/69335), [#&#8203;69360](https://github.com/NousResearch/hermes-agent/pull/69360), [#&#8203;70457](https://github.com/NousResearch/hermes-agent/pull/70457), [#&#8203;69338](https://github.com/NousResearch/hermes-agent/pull/69338) — [@&#8203;teknium1](https://github.com/teknium1))
- Context-engine ABC grows `select_context()` + `on_turn_complete()` verbs (salvage of [@&#8203;chaos-xxl](https://github.com/chaos-xxl)'s RFC work); engines can suppress or customize compaction status ([#&#8203;70458](https://github.com/NousResearch/hermes-agent/pull/70458), [#&#8203;69859](https://github.com/NousResearch/hermes-agent/pull/69859) — [@&#8203;teknium1](https://github.com/teknium1))
- Strict redaction applied at every compaction text boundary ([#&#8203;69294](https://github.com/NousResearch/hermes-agent/pull/69294) — [@&#8203;teknium1](https://github.com/teknium1))

##### Prompt caching & hot-path performance

- Tool schemas cached on native Anthropic without history loss + consolidated cache-plan internals ([#&#8203;76032](https://github.com/NousResearch/hermes-agent/pull/76032), [#&#8203;76067](https://github.com/NousResearch/hermes-agent/pull/76067) — [@&#8203;kshitijk4poor](https://github.com/kshitijk4poor))
- DeepSeek prompt caching on OpenCode gateways; per-API-call token accounting off the turn thread; OpenAI wire client reused across sequential LLM calls; send-path tool-call canonicalization memoized ([#&#8203;75886](https://github.com/NousResearch/hermes-agent/pull/75886), [#&#8203;73359](https://github.com/NousResearch/hermes-agent/pull/73359), [#&#8203;73375](https://github.com/NousResearch/hermes-agent/pull/73375), [#&#8203;76880](https://github.com/NousResearch/hermes-agent/pull/76880) — [@&#8203;teknium1](https://github.com/teknium1), [@&#8203;kshitijk4poor](https://github.com/kshitijk4poor))
- Readonly config loader at 29 call sites (28× cheaper reads); per-turn config deepcopies killed (telemetry gate 54×); one raw config.yaml parse per process; inter-tool delay removed ([#&#8203;74322](https://github.com/NousResearch/hermes-agent/pull/74322), [#&#8203;74211](https://github.com/NousResearch/hermes-agent/pull/74211), [#&#8203;74228](https://github.com/NousResearch/hermes-agent/pull/74228), [#&#8203;64172](https://github.com/NousResearch/hermes-agent/pull/64172) — [@&#8203;teknium1](https://github.com/teknium1), [@&#8203;Soju06](https://github.com/Soju06))
- Lazy heavy-SDK imports (−8-10% import cost on top of the mcp/tool-discovery diet); streaming hot loop drops per-chunk repr() (\~3× cheaper accounting); cursor/memo optimizations for per-iteration history walks ([#&#8203;74204](https://github.com/NousResearch/hermes-agent/pull/74204), [#&#8203;74194](https://github.com/NousResearch/hermes-agent/pull/74194), [#&#8203;74221](https://github.com/NousResearch/hermes-agent/pull/74221), [#&#8203;74231](https://github.com/NousResearch/hermes-agent/pull/74231) — [@&#8203;teknium1](https://github.com/teknium1))
- Cold-start \~14s GIL stall during backend init mitigated; turn flush batched into one SQLite transaction; provider-capability-gated prompt cache keys (implied for api.openai.com) ([#&#8203;77814](https://github.com/NousResearch/hermes-agent/pull/77814), [#&#8203;77619](https://github.com/NousResearch/hermes-agent/pull/77619), [#&#8203;77609](https://github.com/NousResearch/hermes-agent/pull/77609) — [@&#8203;kshitijk4poor](https://github.com/kshitijk4poor))
- AIAgent hot-path salvage — prompt-cache copy, reasoning-timeout precompute, lazy compressor init ([#&#8203;57229](https://github.com/NousResearch/hermes-agent/pull/57229) — [@&#8203;kshitijk4poor](https://github.com/kshitijk4poor))

##### Approvals & the agent loop

- `hermes approvals suggest` mines approval history into allowlist proposals; operator-customizable `approvals.smart_policy`; consecutive-denial circuit breaker; cross-surface approvals mode command ([#&#8203;72259](https://github.com/NousResearch/hermes-agent/pull/72259), [#&#8203;72186](https://github.com/NousResearch/hermes-agent/pull/72186), [#&#8203;72203](https://github.com/NousResearch/hermes-agent/pull/72203), [#&#8203;63517](https://github.com/NousResearch/hermes-agent/pull/63517) — [@&#8203;teknium1](https://github.com/teknium1))
- Docker/podman daemon-redirect commands require approval; session-wide runaway-loop caps for web\_search + delegate\_task (Claude Code-inspired) ([#&#8203;71092](https://github.com/NousResearch/hermes-agent/pull/71092), [#&#8203;66600](https://github.com/NousResearch/hermes-agent/pull/66600) — [@&#8203;teknium1](https://github.com/teknium1))
- Mid-turn redirects — user corrections steer the active turn, preserving in-flight work and the original prompt ([#&#8203;63104](https://github.com/NousResearch/hermes-agent/pull/63104), [#&#8203;72339](https://github.com/NousResearch/hermes-agent/pull/72339) — [@&#8203;OutThisLife](https://github.com/OutThisLife))
- Delegation: structured timeout/stall metadata + live per-child status in `/agents`; subagents can use `execute_code`; redacted child tool history exposed in `subagent_stop`; public subagent lifecycle API for plugins ([#&#8203;72300](https://github.com/NousResearch/hermes-agent/pull/72300), [#&#8203;69325](https://github.com/NousResearch/hermes-agent/pull/69325), [#&#8203;72403](https://github.com/NousResearch/hermes-agent/pull/72403), [#&#8203;72501](https://github.com/NousResearch/hermes-agent/pull/72501) — [@&#8203;teknium1](https://github.com/teknium1))
- Single-owner refactors for backend identity + failure-scoped skips, empty-content wire repair, call\_id/reasoning sanitization, model-switch parsing ([#&#8203;72505](https://github.com/NousResearch/hermes-agent/pull/72505), [#&#8203;73071](https://github.com/NousResearch/hermes-agent/pull/73071), [#&#8203;74319](https://github.com/NousResearch/hermes-agent/pull/74319), [#&#8203;74229](https://github.com/NousResearch/hermes-agent/pull/74229) — [@&#8203;teknium1](https://github.com/teknium1))
- Labeled reasoning excerpt surfaced at the empty-response terminal; tool\_search probe-validates blind tool\_call args ([#&#8203;65144](https://github.com/NousResearch/hermes-agent/pull/65144), [#&#8203;59267](https://github.com/NousResearch/hermes-agent/pull/59267) — [@&#8203;teknium1](https://github.com/teknium1))

##### Tool self-recovery wave

- Terminal: recoverable truncation (full output spilled + pre-truncation size), cwd echoed when a command changes directory, output-pattern failure hints ([#&#8203;77041](https://github.com/NousResearch/hermes-agent/pull/77041), [#&#8203;77004](https://github.com/NousResearch/hermes-agent/pull/77004), [#&#8203;76992](https://github.com/NousResearch/hermes-agent/pull/76992) — [@&#8203;teknium1](https://github.com/teknium1))
- Patch: already-applied edits return success no-op, whitespace-visualized no-match diagnosis, ambiguous-match locations listed ([#&#8203;76998](https://github.com/NousResearch/hermes-agent/pull/76998), [#&#8203;77024](https://github.com/NousResearch/hermes-agent/pull/77024), [#&#8203;77001](https://github.com/NousResearch/hermes-agent/pull/77001) — [@&#8203;teknium1](https://github.com/teknium1))
- Search: zero-match probes + multi-path recovery, auto-multiline for newline patterns; read\_file default limit 500 → 2000 lines; negative-result cache for read/search misses; write\_file verifies on-disk content ([#&#8203;77011](https://github.com/NousResearch/hermes-agent/pull/77011), [#&#8203;77102](https://github.com/NousResearch/hermes-agent/pull/77102), [#&#8203;76996](https://github.com/NousResearch/hermes-agent/pull/76996), [#&#8203;76945](https://github.com/NousResearch/hermes-agent/pull/76945), [#&#8203;77055](https://github.com/NousResearch/hermes-agent/pull/77055) — [@&#8203;teknium1](https://github.com/teknium1), [@&#8203;kshitijk4poor](https://github.com/kshitijk4poor))
- execute\_code recovery hints; skill\_view dedup stub for unchanged re-reads; terminal/execute\_code schema prose trimmed \~40%; tiered tool disclosure scales with catalog size; default iteration limit 90 → 500 ([#&#8203;77106](https://github.com/NousResearch/hermes-agent/pull/77106), [#&#8203;77095](https://github.com/NousResearch/hermes-agent/pull/77095), [#&#8203;77023](https://github.com/NousResearch/hermes-agent/pull/77023), [#&#8203;67034](https://github.com/NousResearch/hermes-agent/pull/67034), [#&#8203;72176](https://github.com/NousResearch/hermes-agent/pull/72176) — [@&#8203;teknium1](https://github.com/teknium1))

##### Providers & models

- Vercel AI Gateway provider + Vercel Sandbox terminal backend return, modernized (SDK 0.7.2, telemetry off) ([#&#8203;74518](https://github.com/NousResearch/hermes-agent/pull/74518) — [@&#8203;teknium1](https://github.com/teknium1))
- Gemini 3.1 Pro + 3.6 Flash in catalogs; Gemini salvage cluster (3.6-flash aux default, Vertex catalog, direct cost tracking); claude-opus-5 in OpenRouter + Nous Portal; deepseek-v4-flash-0731 ([#&#8203;73479](https://github.com/NousResearch/hermes-agent/pull/73479), [#&#8203;73516](https://github.com/NousResearch/hermes-agent/pull/73516), [#&#8203;70946](https://github.com/NousResearch/hermes-agent/pull/70946), [#&#8203;75501](https://github.com/NousResearch/hermes-agent/pull/75501) — [@&#8203;teknium1](https://github.com/teknium1))
- Bedrock Converse API prompt caching (cachePoint) ([#&#8203;70231](https://github.com/NousResearch/hermes-agent/pull/70231) — [@&#8203;JoaoMarcos44](https://github.com/JoaoMarcos44))
- OpenAI data-residency endpoints get declared transport + correct catalog; provider-aware API-server request routing; backend-acknowledged session model lock; Nous sticky routing via top-level session\_id ([#&#8203;74958](https://github.com/NousResearch/hermes-agent/pull/74958), [#&#8203;70853](https://github.com/NousResearch/hermes-agent/pull/70853), [#&#8203;70950](https://github.com/NousResearch/hermes-agent/pull/70950), [#&#8203;69253](https://github.com/NousResearch/hermes-agent/pull/69253) — [@&#8203;victor-kyriazakos](https://github.com/victor-kyriazakos), [@&#8203;teknium1](https://github.com/teknium1))
- Model picker: curated defaults + collapsible providers + select-all; stale caches served instantly with background refresh; custom-endpoint probe capped at 1.5s; honcho OAuth device-code login ([#&#8203;73172](https://github.com/NousResearch/hermes-agent/pull/73172), [#&#8203;76430](https://github.com/NousResearch/hermes-agent/pull/76430), [#&#8203;76922](https://github.com/NousResearch/hermes-agent/pull/76922), [#&#8203;61608](https://github.com/NousResearch/hermes-agent/pull/61608) — [@&#8203;OutThisLife](https://github.com/OutThisLife), [@&#8203;teknium1](https://github.com/teknium1), [@&#8203;kshitijk4poor](https://github.com/kshitijk4poor), [@&#8203;akattelu](https://github.com/akattelu))
- ACP: named custom providers in the model selector; authenticated cross-provider model choices; non-blocking startup via background MCP discovery ([#&#8203;70082](https://github.com/NousResearch/hermes-agent/pull/70082), [#&#8203;70404](https://github.com/NousResearch/hermes-agent/pull/70404), [#&#8203;75985](https://github.com/NousResearch/hermes-agent/pull/75985) — [@&#8203;israellot](https://github.com/israellot), [@&#8203;amanning3390](https://github.com/amanning3390), [@&#8203;kshitijk4poor](https://github.com/kshitijk4poor))

##### Secrets & config

- Command-helper secret source (composes with all vaults); one-command token rotation + actionable startup errors; opt-in encrypted break-glass cache for Bitwarden; vault-injected keys scoped per profile home; orchestrator preserve\_existing + profile aliasing ([#&#8203;69266](https://github.com/NousResearch/hermes-agent/pull/69266), [#&#8203;68605](https://github.com/NousResearch/hermes-agent/pull/68605), [#&#8203;69251](https://github.com/NousResearch/hermes-agent/pull/69251), [#&#8203;69250](https://github.com/NousResearch/hermes-agent/pull/69250), [#&#8203;69058](https://github.com/NousResearch/hermes-agent/pull/69058) — [@&#8203;teknium1](https://github.com/teknium1))
- `${env:VAR}` SecretRef parity between config.yaml and MCP config; secret-source env vars reach stdio MCP servers ([#&#8203;69267](https://github.com/NousResearch/hermes-agent/pull/69267), [#&#8203;69053](https://github.com/NousResearch/hermes-agent/pull/69053) — [@&#8203;teknium1](https://github.com/teknium1))
- Canonical config loaders for behavioral reads; table-driven config migration registry; DEFAULT\_CONFIG extracted to config\_defaults.py; auto-migration support floor at v12 ([#&#8203;74237](https://github.com/NousResearch/hermes-agent/pull/74237), [#&#8203;74200](https://github.com/NousResearch/hermes-agent/pull/74200), [#&#8203;74182](https://github.com/NousResearch/hermes-agent/pull/74182), [#&#8203;74433](https://github.com/NousResearch/hermes-agent/pull/74433) — [@&#8203;teknium1](https://github.com/teknium1))

##### 🌐 Gateway, Relay & Fleet

- Session activity heartbeats, stall watchdog, and bounded compression waits — re-landed hardened after an in-window revert cycle (originally [#&#8203;72424](https://github.com/NousResearch/hermes-agent/issues/72424) by [@&#8203;fangliquanflq](https://github.com/fangliquanflq)) ([#&#8203;76354](https://github.com/NousResearch/hermes-agent/pull/76354) — [@&#8203;teknium1](https://github.com/teknium1))
- SessionState consolidation (19 session-keyed dicts → one turn/conversation/persistent-scoped object); TurnContext/TurnRunner seam extraction; declarative busy\_policy on CommandDef ([#&#8203;74289](https://github.com/NousResearch/hermes-agent/pull/74289), [#&#8203;74353](https://github.com/NousResearch/hermes-agent/pull/74353), [#&#8203;74197](https://github.com/NousResearch/hermes-agent/pull/74197) — [@&#8203;teknium1](https://github.com/teknium1))
- Relay parity waves: Phase 1 (supported\_ops discovery, identity fields, /handoff aliasing), Phase 2 media, Phase 3 interactive prompts, Phase 4 thread lifecycle; egress typing indicators ([#&#8203;71300](https://github.com/NousResearch/hermes-agent/pull/71300), [#&#8203;71363](https://github.com/NousResearch/hermes-agent/pull/71363), [#&#8203;71404](https://github.com/NousResearch/hermes-agent/pull/71404), [#&#8203;71624](https://github.com/NousResearch/hermes-agent/pull/71624), [#&#8203;69721](https://github.com/NousResearch/hermes-agent/pull/69721) — [@&#8203;benbarclay](https://github.com/benbarclay))
- HSP skill sync: personal client (M1) + org-skills client (M2) + org-skill namespace with token-gated discovery ([#&#8203;66730](https://github.com/NousResearch/hermes-agent/pull/66730), [#&#8203;70024](https://github.com/NousResearch/hermes-agent/pull/70024), [#&#8203;70459](https://github.com/NousResearch/hermes-agent/pull/70459) — [@&#8203;benbarclay](https://github.com/benbarclay))
- Buzz (Block/Nostr) platform adapter with native WebSocket inbound transport + NIP-42 auth ([#&#8203;73610](https://github.com/NousResearch/hermes-agent/pull/73610), [#&#8203;73761](https://github.com/NousResearch/hermes-agent/pull/73761) — [@&#8203;teknium1](https://github.com/teknium1))
- Photon: native polls, effects, clarify-as-poll, rich links (4-PR salvage) ([#&#8203;73614](https://github.com/NousResearch/hermes-agent/pull/73614) — [@&#8203;teknium1](https://github.com/teknium1))
- Slack: native Block Kit clarify buttons; opt-in reaction triggers; outbound payload sanitization; thread-context lifecycle fixes ([#&#8203;69318](https://github.com/NousResearch/hermes-agent/pull/69318), [#&#8203;70195](https://github.com/NousResearch/hermes-agent/pull/70195), [#&#8203;69317](https://github.com/NousResearch/hermes-agent/pull/69317), [#&#8203;69320](https://github.com/NousResearch/hermes-agent/pull/69320) — [@&#8203;teknium1](https://github.com/teknium1))
- Discord auto-thread sessions keyed on prospective\_thread\_id; reply references built from ids (no fetch\_message); WhatsApp configurable inbound read receipts ([#&#8203;76513](https://github.com/NousResearch/hermes-agent/pull/76513), [#&#8203;76875](https://github.com/NousResearch/hermes-agent/pull/76875), [#&#8203;73322](https://github.com/NousResearch/hermes-agent/pull/73322) — [@&#8203;benbarclay](https://github.com/benbarclay), [@&#8203;kshitijk4poor](https://github.com/kshitijk4poor))
- Kanban wakes resume the creator's DM/thread session; kanban/delegate wake-ups reach api\_server sessions; per-task model + thinking-depth from the board ([#&#8203;72191](https://github.com/NousResearch/hermes-agent/pull/72191), [#&#8203;70171](https://github.com/NousResearch/hermes-agent/pull/70171), [#&#8203;69876](https://github.com/NousResearch/hermes-agent/pull/69876), [#&#8203;76417](https://github.com/NousResearch/hermes-agent/pull/76417) — [@&#8203;teknium1](https://github.com/teknium1), [@&#8203;OutThisLife](https://github.com/OutThisLife))
- Relay: Discord tool-progress routed into the auto-thread instead of the parent channel ([#&#8203;77830](https://github.com/NousResearch/hermes-agent/pull/77830) — [@&#8203;benbarclay](https://github.com/benbarclay))
- Outbound webhooks — push signed lifecycle events to external endpoints; simplex channel enumeration in `hermes send --list` ([#&#8203;69406](https://github.com/NousResearch/hermes-agent/pull/69406), [#&#8203;77110](https://github.com/NousResearch/hermes-agent/pull/77110) — [@&#8203;teknium1](https://github.com/teknium1))

##### 🖥️ Hermes Desktop App

##### The platform wave

- **Artifacts** — versioned cards, sandboxed live preview, right-rail viewer ([#&#8203;72345](https://github.com/NousResearch/hermes-agent/pull/72345) — [@&#8203;teknium1](https://github.com/teknium1))
- **Plugin SDK** — Kanban as the founding desktop plugin; `ctx.download` hands the user a file; widget-app SDK (apps as state+reducer+render) with three reference apps; widget-grid layout engine + background-aware theme engine ([#&#8203;61173](https://github.com/NousResearch/hermes-agent/pull/61173), [#&#8203;74413](https://github.com/NousResearch/hermes-agent/pull/74413), [#&#8203;68306](https://github.com/NousResearch/hermes-agent/pull/68306), [#&#8203;20379](https://github.com/NousResearch/hermes-agent/pull/20379) — [@&#8203;OutThisLife](https://github.com/OutThisLife))
- Quick-entry window (global hotkey → any session); multiple GUI windows; floating pane placement; pane toggles anywhere + hidden header; ⌘O open-folder-as-project ([#&#8203;72315](https://github.com/NousResearch/hermes-agent/pull/72315), [#&#8203;68259](https://github.com/NousResearch/hermes-agent/pull/68259), [#&#8203;73143](https://github.com/NousResearch/hermes-agent/pull/73143), [#&#8203;75848](https://github.com/NousResearch/hermes-agent/pull/75848), [#&#8203;74623](https://github.com/NousResearch/hermes-agent/pull/74623) — [@&#8203;teknium1](https://github.com/teknium1), [@&#8203;OutThisLife](https://github.com/OutThisLife))
- SSH remote-backend connection mode; event-driven live sync replaces always-on polls; remote profile routing/sessions/pool lifecycle repaired ([#&#8203;68130](https://github.com/NousResearch/hermes-agent/pull/68130), [#&#8203;73673](https://github.com/NousResearch/hermes-agent/pull/73673), [#&#8203;72835](https://github.com/NousResearch/hermes-agent/pull/72835) — [@&#8203;yoniebans](https://github.com/yoniebans), [@&#8203;OutThisLife](https://github.com/OutThisLife))
- Let the agent drive the shell (preview pane + pane focus) AND inspect the desktop app it's developing; find-in-page (Ctrl+F); GUI terminal copy/paste + font picker ([#&#8203;69519](https://github.com/NousResearch/hermes-agent/pull/69519), [#&#8203;73121](https://github.com/NousResearch/hermes-agent/pull/73121), [#&#8203;72235](https://github.com/NousResearch/hermes-agent/pull/72235), [#&#8203;73705](https://github.com/NousResearch/hermes-agent/pull/73705), [#&#8203;76395](https://github.com/NousResearch/hermes-agent/pull/76395) — [@&#8203;OutThisLife](https://github.com/OutThisLife), [@&#8203;teknium1](https://github.com/teknium1))

##### Composer & UX

- Attach files/folders/links via picker; composer chips for @&#8203; paths and pasted links; composer undo stack; double-ESC discards draft; double-Enter sends the queued turn; type-to-focus ([#&#8203;74668](https://github.com/NousResearch/hermes-agent/pull/74668), [#&#8203;73110](https://github.com/NousResearch/hermes-agent/pull/73110), [#&#8203;72201](https://github.com/NousResearch/hermes-agent/pull/72201), [#&#8203;72288](https://github.com/NousResearch/hermes-agent/pull/72288), [#&#8203;74736](https://github.com/NousResearch/hermes-agent/pull/74736), [#&#8203;73101](https://github.com/NousResearch/hermes-agent/pull/73101), [#&#8203;68918](https://github.com/NousResearch/hermes-agent/pull/68918) — [@&#8203;OutThisLife](https://github.com/OutThisLife))
- 2-keypress model switching (⌘⇧M); YOLO in ⌘K with live toggle state; keyboard-first pickers; keyboard navigation for clarify choices; server-owned pins that follow you between apps ([#&#8203;74545](https://github.com/NousResearch/hermes-agent/pull/74545), [#&#8203;74674](https://github.com/NousResearch/hermes-agent/pull/74674), [#&#8203;74602](https://github.com/NousResearch/hermes-agent/pull/74602), [#&#8203;69799](https://github.com/NousResearch/hermes-agent/pull/69799), [#&#8203;74234](https://github.com/NousResearch/hermes-agent/pull/74234) — [@&#8203;OutThisLife](https://github.com/OutThisLife))
- Grouped, live-ticking tool-activity line; improved tool call detail views; [@&#8203;session](https://github.com/session) links resolve to clickable titles; brand icons on known-domain links; iMessage-style emoji reactions (opt-in, two-way); double-click to heart ([#&#8203;72893](https://github.com/NousResearch/hermes-agent/pull/72893), [#&#8203;69868](https://github.com/NousResearch/hermes-agent/pull/69868), [#&#8203;71162](https://github.com/NousResearch/hermes-agent/pull/71162), [#&#8203;73047](https://github.com/NousResearch/hermes-agent/pull/73047), [#&#8203;74533](https://github.com/NousResearch/hermes-agent/pull/74533), [#&#8203;74644](https://github.com/NousResearch/hermes-agent/pull/74644) — [@&#8203;OutThisLife](https://github.com/OutThisLife), [@&#8203;teknium1](https://github.com/teknium1))
- Sidebar date dividers + pinned section + opt-in stale-session auto-archive; sessions stop lying about running state; credit-usage toasts; configurable attachment size limit; Cron Blueprints + Webhooks pages; searchable timezone picker ([#&#8203;70822](https://github.com/NousResearch/hermes-agent/pull/70822), [#&#8203;72303](https://github.com/NousResearch/hermes-agent/pull/72303), [#&#8203;69828](https://github.com/NousResearch/hermes-agent/pull/69828), [#&#8203;73221](https://github.com/NousResearch/hermes-agent/pull/73221), [#&#8203;70066](https://github.com/NousResearch/hermes-agent/pull/70066), [#&#8203;69687](https://github.com/NousResearch/hermes-agent/pull/69687), [#&#8203;73505](https://github.com/NousResearch/hermes-agent/pull/73505) — [@&#8203;OutThisLife](https://github.com/OutThisLife), [@&#8203;austinpickett](https://github.com/austinpickett), [@&#8203;Adolanium](https://github.com/Adolanium), [@&#8203;teknium1](https://github.com/teknium1))
- RFC 8252 native desktop sign-in (system browser + PKCE, no webview cookies); "Connect to existing Hermes" in first-run onboarding; profile-correct pairing approvals with a desktop surface ([#&#8203;67920](https://github.com/NousResearch/hermes-agent/pull/67920), [#&#8203;70907](https://github.com/NousResearch/hermes-agent/pull/70907), [#&#8203;74446](https://github.com/NousResearch/hermes-agent/pull/74446) — [@&#8203;benbarclay](https://github.com/benbarclay), [@&#8203;OutThisLife](https://github.com/OutThisLife))
- Keep-computer-awake toggle + notch wake indicator; /battery status-bar toggle; UI zoom 90% default preset; status bar hideable ([#&#8203;68140](https://github.com/NousResearch/hermes-agent/pull/68140), [#&#8203;76396](https://github.com/NousResearch/hermes-agent/pull/76396), [#&#8203;68860](https://github.com/NousResearch/hermes-agent/pull/68860), [#&#8203;73161](https://github.com/NousResearch/hermes-agent/pull/73161), [#&#8203;72960](https://github.com/NousResearch/hermes-agent/pull/72960) — [@&#8203;OutThisLife](https://github.com/OutThisLife), [@&#8203;teknium1](https://github.com/teknium1))

##### Desktop performance (60fps wave 2)

- Streaming cost independent of transcript length; 60fps on real sessions (reflow-gated pins, adaptive flush); drag at 60fps with five streaming tabs; multitab streaming made fast ([#&#8203;71835](https://github.com/NousResearch/hermes-agent/pull/71835), [#&#8203;72504](https://github.com/NousResearch/hermes-agent/pull/72504), [#&#8203;72346](https://github.com/NousResearch/hermes-agent/pull/72346), [#&#8203;71780](https://github.com/NousResearch/hermes-agent/pull/71780) — [@&#8203;OutThisLife](https://github.com/OutThisLife))
- Hidden-pane timers paused (agents view, cron sidebar, floating pet), scroll/status loops stopped in busy sessions ([#&#8203;77651](https://github.com/NousResearch/hermes-agent/pull/77651) — [@&#8203;kshitijk4poor](https://github.com/kshitijk4poor)); idle CPU near zero in the background; sidebar/overlay render churn killed; statusbar + transcript stop re-rendering per token/sash-drag/session-switch; ⌘K opens instantly; renderer cold start keeps shiki/mermaid off the boot path ([#&#8203;75218](https://github.com/NousResearch/hermes-agent/pull/75218), [#&#8203;73698](https://github.com/NousResearch/hermes-agent/pull/73698), [#&#8203;72163](https://github.com/NousResearch/hermes-agent/pull/72163), [#&#8203;72245](https://github.com/NousResearch/hermes-agent/pull/72245), [#&#8203;72524](https://github.com/NousResearch/hermes-agent/pull/72524), [#&#8203;74665](https://github.com/NousResearch/hermes-agent/pull/74665), [#&#8203;73024](https://github.com/NousResearch/hermes-agent/pull/73024) — [@&#8203;OutThisLife](https://github.com/OutThisLife))
- State diagnostics (render + store churn counters) + a lint rule banning atom-mirrored refs so the stale-read bug class cannot return; Playwright E2E suite with visual regression diffs ([#&#8203;71925](https://github.com/NousResearch/hermes-agent/pull/71925), [#&#8203;71560](https://github.com/NousResearch/hermes-agent/pull/71560), [#&#8203;65805](https://github.com/NousResearch/hermes-agent/pull/65805) — [@&#8203;OutThisLife](https://github.com/OutThisLife), [@&#8203;teknium1](https://github.com/teknium1), [@&#8203;ethernet8023](https://github.com/ethernet8023))

##### 🖥️ CLI, TUI & Dashboard

- `!` shell mode; `/init` AGENTS.md generation; `/diff` (staged/all/session, cross-surface); `/context` breakdown; `/focus` reduced-output view; Ctrl+S prompt stash; persistent `/goal` indicator; multi-select clarify (checkboxes) across CLI/gateway/TUI ([#&#8203;72257](https://github.com/NousResearch/hermes-agent/pull/72257), [#&#8203;72178](https://github.com/NousResearch/hermes-agent/pull/72178), [#&#8203;72240](https://github.com/NousResearch/hermes-agent/pull/72240), [#&#8203;72242](https://github.com/NousResearch/hermes-agent/pull/72242), [#&#8203;72302](https://github.com/NousResearch/hermes-agent/pull/72302), [#&#8203;72262](https://github.com/NousResearch/hermes-agent/pull/72262), [#&#8203;72244](https://github.com/NousResearch/hermes-agent/pull/72244), [#&#8203;72188](https://github.com/NousResearch/hermes-agent/pull/72188) — [@&#8203;teknium1](https://github.com/teknium1), salvaging [@&#8203;SHL0MS](https://github.com/SHL0MS), [@&#8203;iRonin](https://github.com/iRonin), [@&#8203;gigi206](https://github.com/gigi206) + more)
- `hermes import-agent` — one-command migration from Claude Code / Codex CLI setups ([#&#8203;72190](https://github.com/NousResearch/hermes-agent/pull/72190) — [@&#8203;teknium1](https://github.com/teknium1))
- Per-turn summary line + live token flow in the spinner; cross-surface theme SDK (one skin themes CLI, TUI, and desktop, live) ([#&#8203;72246](https://github.com/NousResearch/hermes-agent/pull/72246), [#&#8203;68857](https://github.com/NousResearch/hermes-agent/pull/68857) — [@&#8203;teknium1](https://github.com/teknium1), [@&#8203;OutThisLife](https://github.com/OutThisLife))
- TUI: reach the model picker without wrecking your draft + mid-turn switching; slash menu leads with your most-used skills; attachments live in the composer; Arabic (ar) locale with RTL across desktop/dashboard/agent ([#&#8203;74756](https://github.com/NousResearch/hermes-agent/pull/74756), [#&#8203;75931](https://github.com/NousResearch/hermes-agent/pull/75931), [#&#8203;75210](https://github.com/NousResearch/hermes-agent/pull/75210), [#&#8203;70870](https://github.com/NousResearch/hermes-agent/pull/70870) — [@&#8203;OutThisLife](https://github.com/OutThisLife))
- `hermes -w` startup \~14s → \~1.8s; global `--version` fast path; banner update-check 6× faster; dashboard lazy-loads routes + GROUP BY session stats; session filtering tabs (Chats/Automation/All) ([#&#8203;71637](https://github.com/NousResearch/hermes-agent/pull/71637), [#&#8203;62096](https://github.com/NousResearch/hermes-agent/pull/62096), [#&#8203;74188](https://github.com/NousResearch/hermes-agent/pull/74188), [#&#8203;72294](https://github.com/NousResearch/hermes-agent/pull/72294), [#&#8203;73362](https://github.com/NousResearch/hermes-agent/pull/73362), [#&#8203;73865](https://github.com/NousResearch/hermes-agent/pull/73865) — [@&#8203;teknium1](https://github.com/teknium1), [@&#8203;kshitijk4poor](https://github.com/kshitijk4poor))
- Runtime: Node 26 required across installers/heal/upgrade, managed Node/uv resolve before bare PATH, outdated managed trees heal to target major; brew + pip/PyPI wheel channels retired (shell installer / Docker / Nix are the supported channels) ([#&#8203;76459](https://github.com/NousResearch/hermes-agent/pull/76459), [#&#8203;68217](https://github.com/NousResearch/hermes-agent/pull/68217) — [@&#8203;ethernet8023](https://github.com/ethernet8023))

##### 🧩 Skills, Plugins & MCP

- **A2A v1.0** — Agent-to-Agent protocol plugin (closes [#&#8203;514](https://github.com/NousResearch/hermes-agent/issues/514)) ([#&#8203;77109](https://github.com/NousResearch/hermes-agent/pull/77109) — [@&#8203;teknium1](https://github.com/teknium1))
- Curator: surface unmanaged skills + `curator adopt`; skill-description truncation surfaced to authors; grounded-citations skill (+ fact-checking mode); simplify-code v1.1; tldraw-offline scripting skill ([#&#8203;71648](https://github.com/NousResearch/hermes-agent/pull/71648), [#&#8203;70519](https://github.com/NousResearch/hermes-agent/pull/70519), [#&#8203;71698](https://github.com/NousResearch/hermes-agent/pull/71698), [#&#8203;77104](https://github.com/NousResearch/hermes-agent/pull/77104), [#&#8203;70440](https://github.com/NousResearch/hermes-agent/pull/70440), [#&#8203;66896](https://github.com/NousResearch/hermes-agent/pull/66896) — [@&#8203;teknium1](https://github.com/teknium1))
- Office skills bundled: docx, xlsx, pdf + refreshed powerpoint; skills-tree debloat continues (yuanbao, segment-anything, jupyter, heartmula, audiocraft → optional-skills; claude-marketplace source removed; hub restructure absorbing themes/desktop-plugins/tui-widgets) ([#&#8203;68595](https://github.com/NousResearch/hermes-agent/pull/68595), [#&#8203;70452](https://github.com/NousResearch/hermes-agent/pull/70452)–[#&#8203;70456](https://github.com/NousResearch/hermes-agent/pull/70456), [#&#8203;73903](https://github.com/NousResearch/hermes-agent/pull/73903) — [@&#8203;teknium1](https://github.com/teknium1))
- MCP: Comfy Cloud catalog entry with curated 20-tool default; hidden-whitespace warnings in MCP config; pinecone-research optional skill ([#&#8203;66112](https://github.com/NousResearch/hermes-agent/pull/66112), [#&#8203;75736](https://github.com/NousResearch/hermes-agent/pull/75736), [#&#8203;70512](https://github.com/NousResearch/hermes-agent/pull/70512) — [@&#8203;teknium1](https://github.com/teknium1))
- MCP lazy server startup from a fingerprint-keyed on-disk tool-schema cache — configured servers no longer all boot at session start (design from [#&#8203;56832](https://github.com/NousResearch/hermes-agent/issues/56832)) ([#&#8203;77511](https://github.com/NousResearch/hermes-agent/pull/77511) — [@&#8203;kshitijk4poor](https://github.com/kshitijk4poor))
- NeMo Relay observability integration — re-landed after an in-window revert, on stable NeMo Relay 0.6 ([#&#8203;67607](https://github.com/NousResearch/hermes-agent/pull/67607) — [@&#8203;afourniernv](https://github.com/afourniernv))
- Gateway health & diagnostics OTLP export ([#&#8203;64536](https://github.com/NousResearch/hermes-agent/pull/64536) — [@&#8203;victor-kyriazakos](https://github.com/victor-kyriazakos))

##### 🔒 Security & Reliability

- Iron-proxy credential-injection egress firewall re-landed ([#&#8203;70848](https://github.com/NousResearch/hermes-agent/pull/70848) — [@&#8203;teknium1](https://github.com/teknium1))
- DNS-pinned SSRF-safe fetches + Slack CDN allowlist; strict redaction at compaction boundaries; ReDoS eliminated in config-key redaction patterns; prose words embedding a secret keyword no longer masked ([#&#8203;70193](https://github.com/NousResearch/hermes-agent/pull/70193), [#&#8203;69294](https://github.com/NousResearch/hermes-agent/pull/69294), [#&#8203;76083](https://github.com/NousResearch/hermes-agent/pull/76083), [#&#8203;67776](https://github.com/NousResearch/hermes-agent/pull/67776) — [@&#8203;teknium1](https://github.com/teknium1))
- Tier-3 credential reads scoped (FAL/XAI/VERCEL/DAYTONA/GITHUB presence checks etc.); CVE dependency pins refreshed (cryptography, starlette, python-multipart); hindsight env file 0600; /model moved off the gateway event loop ([#&#8203;75888](https://github.com/NousResearch/hermes-agent/pull/75888), [#&#8203;72362](https://github.com/NousResearch/hermes-agent/pull/72362) — [@&#8203;teknium1](https://github.com/teknium1))
- Windows hardening wave: text-mode subprocess decode bug class closed repo-wide, console flashes hidden across daemons/env probes/LSP/installer paths, residual encoding gaps (MCP stdio, gateway update I/O, STT/TTS, desktop spawn) ([#&#8203;70875](https://github.com/NousResearch/hermes-agent/pull/70875), [#&#8203;70205](https://github.com/NousResearch/hermes-agent/pull/70205), [#&#8203;70264](https://github.com/NousResearch/hermes-agent/pull/70264), [#&#8203;71014](https://github.com/NousResearch/hermes-agent/pull/71014) — [@&#8203;teknium1](https://github.com/teknium1), salvaging several community PRs)
- State/session integrity: four session-state fixes (safe close tracking, flush-cursor class fix, row-retry, usage-PK healer); compact v23 FTS layout + `hermes sessions optimize` + CJK-bigram FTS; read-path split with per-thread read-only connections ([#&#8203;75883](https://github.com/NousResearch/hermes-agent/pull/75883), [#&#8203;65798](https://github.com/NousResearch/hermes-agent/pull/65798), [#&#8203;69423](https://github.com/NousResearch/hermes-agent/pull/69423), [#&#8203;73344](https://github.com/NousResearch/hermes-agent/pull/73344) — [@&#8203;teknium1](https://github.com/teknium1), [@&#8203;kshitijk4poor](https://github.com/kshitijk4poor))
- OpenViking memory-provider hardening — fail closed on blocked endpoints, server verification before credentials are sent, config.yaml-first settings ([#&#8203;77747](https://github.com/NousResearch/hermes-agent/pull/77747) — [@&#8203;kshitijk4poor](https://github.com/kshitijk4poor))
- Credential pool: reset-aware primary restore (stay on fallback until the rate-limit window resets) + deferred-refresh locking fixes; FTS UPDATE triggers narrowed with fail-closed CJK migration ([#&#8203;77631](https://github.com/NousResearch/hermes-agent/pull/77631), [#&#8203;77628](https://github.com/NousResearch/hermes-agent/pull/77628) — [@&#8203;kshitijk4poor](https://github.com/kshitijk4poor))
- Config-driven memory allocator trim with telemetry; holographic memory vectors stored float32; loop-invariant HRR encodes hoisted ([#&#8203;76905](https://github.com/NousResearch/hermes-agent/pull/76905), [#&#8203;76917](https://github.com/NousResearch/hermes-agent/pull/76917), [#&#8203;76881](https://github.com/NousResearch/hermes-agent/pull/76881) — [@&#8203;kshitijk4poor](https://github.com/kshitijk4poor))

##### 🐛 Notable Bug Fixes

- Voice: full-duplex interruption during generation AND playback; whole-turn desktop speech; auto-TTS delivery gaps ([#&#8203;74223](https://github.com/NousResearch/hermes-agent/pull/74223), [#&#8203;69936](https://github.com/NousResearch/hermes-agent/pull/69936), [#&#8203;73508](https://github.com/NousResearch/hermes-agent/pull/73508) — [@&#8203;teknium1](https://github.com/teknium1))
- Desktop: Stop parks the queue instead of firing the next queued prompt; branch-in-new-chat restart loss; false remote-gateway reauthentication; cross-session composer leaks ([#&#8203;68725](https://github.com/NousResearch/hermes-agent/pull/68725), [#&#8203;71960](https://github.com/NousResearch/hermes-agent/pull/71960), [#&#8203;68250](https://github.com/NousResearch/hermes-agent/pull/68250), [#&#8203;70986](https://github.com/NousResearch/hermes-agent/pull/70986) — [@&#8203;SHL0MS](https://github.com/SHL0MS), [@&#8203;alelpoan](https://github.com/alelpoan), [@&#8203;helix4u](https://github.com/helix4u), [@&#8203;OutThisLife](https://github.com/OutThisLife))
- Gateway: session lists scoped before limiting; relay-backed home delivery after restart; timeline display events persisted ([#&#8203;65509](https://github.com/NousResearch/hermes-agent/pull/65509), [#&#8203;70102](https://github.com/NousResearch/hermes-agent/pull/70102), [#&#8203;69771](https://github.com/NousResearch/hermes-agent/pull/69771) — [@&#8203;GodsBoy](https://github.com/GodsBoy), [@&#8203;victor-kyriazakos](https://github.com/victor-kyriazakos), [@&#8203;ethernet8023](https://github.com/ethernet8023))
- Agent: context-length fallback logging + batch trajectory durability; Codex OAuth context windows revalidated against the live catalog ([#&#8203;76027](https://github.com/NousResearch/hermes-agent/pull/76027), [#&#8203;68554](https://github.com/NousResearch/hermes-agent/pull/68554) — [@&#8203;kshitijk4poor](https://github.com/kshitijk4poor), [@&#8203;teknium1](https://github.com/teknium1))
- ...plus roughly 770 more `fix:` PRs across every subsystem this window.

##### 👥 Contributors

**647 contributors** shipped this release (commit authors, co-authors, and salvaged-PR credits).

##### Core

[@&#8203;teknium1](https://github.com/teknium1), [@&#8203;OutThisLife](https://github.com/OutThisLife) (desktop, voice, perf), [@&#8203;kshitijk4poor](https://github.com/kshitijk4poor) (perf, caching, salvage), [@&#8203;ethernet8023](https://github.com/ethernet8023) (runtime, E2E, desktop), [@&#8203;benbarclay](https://github.com/benbarclay) (relay, HSP, auth)

##### All Contributors (alphabetical)

[@&#8203;02356abc](https://github.com/02356abc), [@&#8203;0301chris](https://github.com/0301chris), [@&#8203;0xAlcibiades](https://github.com/0xAlcibiades), [@&#8203;0xDevNinja](https://github.com/0xDevNinja), [@&#8203;0xLeathery](https://github.com/0xLeathery), [@&#8203;0xprincess](https://github.com/0xprincess), [@&#8203;0xr00tf3rr3t](https://github.com/0xr00tf3rr3t), [@&#8203;100yenadmin](https://github.com/100yenadmin),
[@&#8203;2001Y](https://github.com/2001Y), [@&#8203;3ssiri](https://github.com/3ssiri), [@&#8203;55nx954gn6-debug](https://github.com/55nx954gn6-debug), [@&#8203;686f6c61](https://github.com/686f6c61), [@&#8203;87degrees](https://github.com/87degrees), [@&#8203;aaronlab](https://github.com/aaronlab), [@&#8203;abundantbeing](https://github.com/abundantbeing), [@&#8203;Adolanium](https://github.com/Adolanium),
[@&#8203;adriansotomora](https://github.com/adriansotomora), [@&#8203;adurham](https://github.com/adurham), [@&#8203;afourniernv](https://github.com/afourniernv), [@&#8203;afurm](https://github.com/afurm), [@&#8203;AgenticSpark](https://github.com/AgenticSpark), [@&#8203;ahmadashfq](https://github.com/ahmadashfq), [@&#8203;AhmetArif0](https://github.com/AhmetArif0), [@&#8203;ai-ag2026](https://github.com/ai-ag2026),
[@&#8203;AIalliAI](https://github.com/AIalliAI), [@&#8203;aider4ryder](https://github.com/aider4ryder), [@&#8203;airclear](https://github.com/airclear), [@&#8203;ajzrva-sys](https://github.com/ajzrva-sys), [@&#8203;akattelu](https://github.com/akattelu), [@&#8203;AKAZIK-py](https://github.com/AKAZIK-py), [@&#8203;akb4q](https://github.com/akb4q), [@&#8203;akshan-main](https://github.com/akshan-main), [@&#8203;AlanBurningsuit](https://github.com/AlanBurningsuit),
[@&#8203;alelpoan](https://github.com/alelpoan), [@&#8203;AlexFucuson9](https://github.com/AlexFucuson9), [@&#8203;AlexxRussell](https://github.com/AlexxRussell), [@&#8203;AllardQuek](https://github.com/AllardQuek), [@&#8203;alt-glitch](https://github.com/alt-glitch), [@&#8203;aman-merchant](https://github.com/aman-merchant), [@&#8203;amanning3390](https://github.com/amanning3390), [@&#8203;amathxbt](https://github.com/amathxbt),
[@&#8203;aml1973](https://github.com/aml1973), [@&#8203;amoreno16003](https://github.com/amoreno16003), [@&#8203;AndrewMoryakov](https://github.com/AndrewMoryakov), [@&#8203;andrexibiza](https://github.com/andrexibiza), [@&#8203;andynguyendk](https://github.com/andynguyendk), [@&#8203;andyylin](https://github.com/andyylin), [@&#8203;aneym](https://github.com/aneym), [@&#8203;angelos](https://github.com/angelos),
[@&#8203;aniruddhaadak80](https://github.com/aniruddhaadak80), [@&#8203;AnnasMazhar](https://github.com/AnnasMazhar), [@&#8203;annguyenNous](https://github.com/annguyenNous), [@&#8203;anoopmehendale-cue](https://github.com/anoopmehendale-cue), [@&#8203;AnthonyFrancis](https://github.com/AnthonyFrancis), [@&#8203;arcabotai](https://github.com/arcabotai), [@&#8203;ArcherQAQ](https://github.com/ArcherQAQ),
[@&#8203;Ares4Tech](https://github.com/Ares4Tech), [@&#8203;arimu1](https://github.com/arimu1), [@&#8203;arnoldfrancisca](https://github.com/arnoldfrancisca), [@&#8203;asimons81](https://github.com/asimons81), [@&#8203;asorry75](https://github.com/asorry75), [@&#8203;AtakanGs](https://github.com/AtakanGs), [@&#8203;ATran28](https://github.com/ATran28), [@&#8203;austinpickett](https://github.com/austinpickett),
[@&#8203;Automata-intelligentsia](https://github.com/Automata-intelligentsia), [@&#8203;awain7](https://github.com/awain7), [@&#8203;aweiker](https://github.com/aweiker), [@&#8203;aydnOktay](https://github.com/aydnOktay), [@&#8203;ayushere](https://github.com/ayushere), [@&#8203;b](https://github.com/b), [@&#8203;baau](https://github.com/baau), [@&#8203;baauzi](https://github.com/baauzi), [@&#8203;baenregod](https://github.com/baenregod),
[@&#8203;bakhtiersizhaev](https://github.com/bakhtiersizhaev), [@&#8203;Baophan00](https://github.com/Baophan00), [@&#8203;baoyu0](https://github.com/baoyu0), [@&#8203;Bartok9](https://github.com/Bartok9), [@&#8203;basilalshukaili](https://github.com/basilalshukaili), [@&#8203;BB-light](https://github.com/BB-light), [@&#8203;bbopen](https://github.com/bbopen), [@&#8203;Beandon13](https://github.com/Beandon13),
[@&#8203;beardedeagle](https://github.com/beardedeagle), [@&#8203;bedirhancode](https://github.com/bedirhancode), [@&#8203;benbarclay](https://github.com/benbarclay), [@&#8203;benegessarit](https://github.com/benegessarit), [@&#8203;benjamin2026-dot](https://github.com/benjamin2026-dot), [@&#8203;bennybuoy](https://github.com/bennybuoy), [@&#8203;BenSheridanEdwards](https://github.com/BenSheridanEdwards),
[@&#8203;BKStock](https://github.com/BKStock), [@&#8203;BlackishGreen33](https://github.com/BlackishGreen33), [@&#8203;bnikanjam](https://github.com/bnikanjam), [@&#8203;bounce12340](https://github.com/bounce12340), [@&#8203;Bounty13](https://github.com/Bounty13), [@&#8203;bpross](https://github.com/bpross), [@&#8203;briandevans](https://github.com/briandevans), [@&#8203;bricelb](https://github.com/bricelb), [@&#8203;brunopirz](https://github.com/brunopirz),
[@&#8203;bryanneva](https://github.com/bryanneva), [@&#8203;byshubham](https://github.com/byshubham), [@&#8203;camaleonidas](https://github.com/camaleonidas), [@&#8203;canorionen](https://github.com/canorionen), [@&#8203;carbongotfound](https://github.com/carbongotfound), [@&#8203;carljborg](https://github.com/carljborg), [@&#8203;carlotestor](https://github.com/carlotestor), [@&#8203;carrion256](https://github.com/carrion256),
[@&#8203;caseyanthony](https://github.com/caseyanthony), [@&#8203;cat-thats-fat](https://github.com/cat-thats-fat), [@&#8203;Cdddo](https://github.com/Cdddo), [@&#8203;ceverson70](https://github.com/ceverson70), [@&#8203;chancelu](https://github.com/chancelu), [@&#8203;chaos-xxl](https://github.com/chaos-xxl), [@&#8203;CharlesMcquade](https://github.com/CharlesMcquade), [@&#8203;chazmaniandinkle](https://github.com/chazmaniandinkle),
[@&#8203;chefboyrdave21](https://github.com/chefboyrdave21), [@&#8203;chelsealong](https://github.com/chelsealong), [@&#8203;Christopher-Schulze](https://github.com/Chr…
randlee pushed a commit to randlee/hermes-agent that referenced this pull request Aug 11, 2026
…-client

feat(sync): HSP/1 personal skill sync client (M1 client)
33hodl pushed a commit to 33hodl/hermes-agent that referenced this pull request Aug 12, 2026
…-client

feat(sync): HSP/1 personal skill sync client (M1 client)
SHL0MS added a commit to SHL0MS/hermes-agent that referenced this pull request Aug 13, 2026
Adds 'hermes wisdom approve <skill>' — the owner's approve-share action.
Submits the skill to the org via the existing propose_skill path (HSP/1
org proposals, merged in NousResearch#66730). If the owner is an admin it merges
directly; otherwise it becomes a proposal for admin review.

The approved skill is removed from the candidate list so it doesn't
re-nominate. A non-candidate skill can still be approved (owner's call)
with an advisory note.

Verified end-to-end against the production sync plane: proposal NousResearch#3
created via 'hermes wisdom approve browser-game-development', visible
in the org proposals list, candidate removed from state. Test proposal
rejected (cleanup).

Tests: 98/98 passing (wisdom + sync client). Ruff clean.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

comp/cli CLI entry point, hermes_cli/, setup wizard comp/gateway Gateway runner, session dispatch, delivery needs-decision Awaiting maintainer decision before any implementation P3 Low — cosmetic, nice to have tool/skills Skills system (list, view, manage) type/feature New feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants