Skip to content

feat(desktop): plugins install in one click from hermes:// deeplinks, confirm-first (salvage #82735) - #89464

Merged
teknium1 merged 1 commit into
mainfrom
salvage/plugin-install-deeplink
Aug 18, 2026
Merged

teknium1 merged 1 commit into
mainfrom
salvage/plugin-install-deeplink

Conversation

@teknium1

Copy link
Copy Markdown
Collaborator

Summary

Plugins now install in one click from a hermes://plugin/install?repo=owner/repo deeplink (or Settings → Plugins → Install from Git), with a review step before anything touches disk — matching the confirm-first precedent set by the MCP install deeplink. Never auto-installs.

Salvage of #82735 by @serefyarar (branch carried merge commits, so the net diff was applied as a single authored commit preserving attribution). Per repo policy the preview-screenshot PNG committed on the original branch was dropped — images live in PR bodies, not the tree.

Changes

  • apps/desktop/electron/desktop-plugin-install.ts (new): git URL/owner-repo resolution, shallow clone + agent/desktop artifact probe, subdir-escape guard, 60s clone timeout, non-interactive git env (GIT_TERMINAL_PROMPT=0), insecure-scheme warnings, stable install-folder naming from repo identity
  • apps/desktop/src/app/settings/plugin-install-modal.tsx (new) + plugin-install-request.ts: review → probe → choose → install flow; hybrid repos (agent + desktop) get one dialog; legacy plugin-agent/plugin-desktop links route into the same modal
  • apps/desktop/src/lib/deeplink-routes.ts + plugin-source-urls.ts (new): deeplink parsing and GitHub browse/clone URL derivation, with tests
  • tui_gateway/methods_tools.py: plugins.manage gains an install action wrapping the existing dashboard_install_plugin (inherits the security-scan gate); runs inside the same profile-override bracket as list/toggle, so the profile param routes installs to the right HERMES_HOME
  • i18n: en + zh strings

Validation

Check Result
vitest (deeplink-routes, plugin-source-urls, desktop-plugin-install) 18/18 pass
pytest tests/tui_gateway/test_plugins_manage_install.py 3/3 pass
npm run check:lint (tsc ×3 + eslint) 0 errors
Profile routing verified: install runs under _mcp_resolve_profile HERMES_HOME override

Infographic

One-click plugin install

@alt-glitch alt-glitch added type/feature New feature or request P3 Low — cosmetic, nice to have comp/desktop Electron desktop app (apps/desktop/*) comp/plugins Plugin system and bundled plugins labels Aug 18, 2026
@github-actions

github-actions Bot commented Aug 18, 2026 •

Copy link
Copy Markdown

૮ >ﻌ< ა ci review

ran on 999cd3a — feat(desktop): one-click plugin install via hermes:// deepli

⚠️ Warnings

CI timings · View report · View job

Wall time 10m1s vs 3m41s (+171.9%). 18 job(s) slower, 18 faster, 2 unchanged.

  • JS & TS checks / apps/desktop / check:test:ui:shard-1of3: -44.0s
  • Python tests / Run tests slice 8/12: +36.0s
  • Python tests / Run tests slice 6/12: -29.0s
  • Python tests / Run tests slice 11/12: +28.0s
  • Python tests / Run tests slice 5/12: -23.0s

OSV vulnerability scan · View job

7 known vulnerabilities found in pinned dependencies.

How to fix:

Review the findings in the Security tab. Update the affected dependencies if a patched version is available.

Adds a reviewable in-app install path for Hermes plugins:
hermes://plugin/install?repo=owner/repo (and Settings -> Plugins ->
Install from Git) opens a confirmation modal showing the repo identity
and source links, shallow-clones to probe for agent and/or desktop
plugin artifacts, lets the user pick components, then installs — agent
side through the gateway's new plugins.manage `install` action (wrapping
the existing dashboard_install_plugin), desktop side through a new
Electron git-install module with subdir-escape guards, a 60s clone
timeout, non-interactive git env, and insecure-scheme warnings. Never
auto-installs; hybrid repos get one dialog. Legacy plugin-agent /
plugin-desktop deeplinks route into the same modal.

Salvaged from PR #82735 by @serefyarar (net diff applied onto current
main as a single authored commit; the branch carried merge commits).
The preview screenshot PNG from the original branch was intentionally
not carried over — images live in PR bodies, not the repo.
@teknium1
teknium1 force-pushed the salvage/plugin-install-deeplink branch from 3e502aa to 999cd3a Compare August 18, 2026 21:31
@teknium1
teknium1 merged commit 359e09f into main Aug 18, 2026
108 of 110 checks passed
@teknium1
teknium1 deleted the salvage/plugin-install-deeplink branch August 18, 2026 21:45
teknium1 added a commit that referenced this pull request Aug 18, 2026
The deeplink-driven plugin install flow shipped in #89464 (salvage of
#82735 by @serefyarar) had no docs. Adds:

- user-guide/features/plugins.md: "One-click install links (Desktop)"
  section under Managing plugins — link forms (repo/enable/force), the
  confirm-first dialog contract (never auto-installs, same install-time
  security scanning as the CLI), hybrid-repo behavior, legacy
  plugin-agent/plugin-desktop routing, hermes-dev:// in dev builds, and
  the no-SDK anchor example. Cross-links the MCP "Add to Hermes link"
  equivalent.
- developer-guide/desktop-plugin-sdk.md: "Distributing with an install
  link" section so plugin authors find the link form next to the
  packaging docs.
lisajlau pushed a commit to lisajlau/hermes-agent that referenced this pull request Aug 20, 2026
The deeplink-driven plugin install flow shipped in NousResearch#89464 (salvage of
NousResearch#82735 by @serefyarar) had no docs. Adds:

- user-guide/features/plugins.md: "One-click install links (Desktop)"
  section under Managing plugins — link forms (repo/enable/force), the
  confirm-first dialog contract (never auto-installs, same install-time
  security scanning as the CLI), hybrid-repo behavior, legacy
  plugin-agent/plugin-desktop routing, hermes-dev:// in dev builds, and
  the no-SDK anchor example. Cross-links the MCP "Add to Hermes link"
  equivalent.
- developer-guide/desktop-plugin-sdk.md: "Distributing with an install
  link" section so plugin authors find the link form next to the
  packaging docs.
@Enough1122

Copy link
Copy Markdown

AI code review — automated review for reference; please use your judgment.

  • path traversal: desktopPluginFolderName filters ''/'.'/'desktop' from subdir segments but not '..'. A deeplink like repo=owner/repo/plugins/foo/.. passes resolveSubdirWithin (it resolves inside the clone) yet yields folder name '..', so targetDir = desktopPluginsRoot/..; with force=1 the pre-install fsp.rm(targetDir, {recursive:true}) would delete outside the plugins root. Reject/sanitize .. segments when deriving the folder name.
  • security posture (positive): array-args spawn (no shell), GIT_TERMINAL_PROMPT=0 + askpass neutering, 60s SIGKILL clone timeout, subdir-escape guard, inbound-deeplink scheme allowlist, and confirm-first modal are all the right calls; agent installs ride the existing dashboard_install_plugin scan gate.
  • duplication: resolvePluginGitUrl and the GitHub URL parsing are duplicated near-verbatim between electron/desktop-plugin-install.ts and src/lib/plugin-source-urls.ts; drift between the two will produce browse-links that disagree with what's actually cloned. Consider extracting a shared pure module.
  • nit: i18n strings hardcode ~/.hermes/plugins/ as display text (agentTargetLocal) — cosmetic today, but reads wrong for non-default profiles.
  • footprint: extends the existing plugins.manage gateway method instead of adding a tool — correct rung on the ladder; tests are behavior-based (no source-reading/change-detector patterns).

bobaba76 pushed a commit to bobaba76/hermes-agent that referenced this pull request Aug 27, 2026
The deeplink-driven plugin install flow shipped in NousResearch#89464 (salvage of
NousResearch#82735 by @serefyarar) had no docs. Adds:

- user-guide/features/plugins.md: "One-click install links (Desktop)"
  section under Managing plugins — link forms (repo/enable/force), the
  confirm-first dialog contract (never auto-installs, same install-time
  security scanning as the CLI), hybrid-repo behavior, legacy
  plugin-agent/plugin-desktop routing, hermes-dev:// in dev builds, and
  the no-SDK anchor example. Cross-links the MCP "Add to Hermes link"
  equivalent.
- developer-guide/desktop-plugin-sdk.md: "Distributing with an install
  link" section so plugin authors find the link form next to the
  packaging docs.
melon-xf added a commit to melon-xf/hermes-agent that referenced this pull request Sep 3, 2026
The deeplink-driven plugin install flow shipped in NousResearch#89464 (salvage of
NousResearch#82735 by @serefyarar) had no docs. Adds:

- user-guide/features/plugins.md: "One-click install links (Desktop)"
  section under Managing plugins — link forms (repo/enable/force), the
  confirm-first dialog contract (never auto-installs, same install-time
  security scanning as the CLI), hybrid-repo behavior, legacy
  plugin-agent/plugin-desktop routing, hermes-dev:// in dev builds, and
  the no-SDK anchor example. Cross-links the MCP "Add to Hermes link"
  equivalent.
- developer-guide/desktop-plugin-sdk.md: "Distributing with an install
  link" section so plugin authors find the link form next to the
  packaging docs.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

comp/desktop Electron desktop app (apps/desktop/*) comp/plugins Plugin system and bundled plugins P3 Low — cosmetic, nice to have type/feature New feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants