feat(wisdom): add Hermes Collective Wisdom Agent V1 - #94266
benbarclay merged 157 commits into
Conversation
20f9db1 to
daeb6f1
Compare
daeb6f1 to
74f4268
Compare
74f4268 to
77d7563
Compare
0b91d98 to
de04ed6
Compare
de04ed6 to
65d3f10
Compare
|
Contract follow-up pushed at fe6e247. No new Agent review findings were present. Gateway review fixes are now consumed consistently: Agent and Portal #1022 both pin 16bd05e81b134d1ab8bb230aade6f6de9010cae3 with OpenAPI digest b46f0db55befbb682a392fc0c1015ed0a9a81e02d5ad9337c29347802972937d. Manifest/vectors are unchanged; the user-facing-only delivery/subagent guard remains intact. Six contract tests and the contract verifier pass. All three cross-repo release smoke drivers pass against real Postgres/MinIO, including worker/SQLite recovery and moderated publication. No runtime/demo restart was performed. |
|
Review follow-up pushed at 8dd35a5. Blank Slate regression fixed in ac0b088. The minimal setup now derives disabled-bundle exclusions from resolved tool overlap, so wisdom_consent cannot subtract present_wisdom_consent from the retained skills bundle. The existing no-overlap invariant remains unchanged. Added a model-tool-definition check demonstrating consent survives when Wisdom is available; the ordinary unconfigured minimal surface is still covered. The two anonymous-auth failures are baseline-attributed and fixed. CI tested merge c6a2453 against main 45a6101. Both failures reproduce on that unmodified main in an isolated worktree:
Upstream 173105c changed _RESOLVE_TOKEN_CACHE from a nullable single slot to a per-profile dictionary, but this fixture still assigned None. Merged main 45a6101 without conflicts in 089b89b, preserving contributor history, then corrected the fixture to an empty dictionary in 8dd35a5. No production auth workaround or weakening of the profile isolation was added. Validation: canonical scripts/run_tests.sh, fresh HOME/HERMES_HOME, retries disabled: 219 passed across Blank Slate, anonymous auth, token memo, staging allowlist, Wisdom mediation/store and Gateway mediation. This includes delegated/background-session rejection tests. Ruff and git diff --check pass. Full Linux CI must rerun on this head; the existing ci-reviewed label gate remains maintainer-owned. The inherited Privy ready-timeout weakness is retained as a separate non-blocking follow-up, not folded back into this Wisdom PR. Gateway/Portal heads, rollout flags and the running demo were not changed. |
benbarclay
left a comment
There was a problem hiding this comment.
Approving as hermes-agent-core reviewer for the pyproject.toml / web/package.json / package-lock.json touches (setuptools include for hermes_wisdom + contracts package-data; @testing-library/react devDependency). CI green on 0924f79; blank-slate and anon-auth failures verified fixed locally.
Reverts the in-tree org skill-marketplace: hermes_wisdom package, three model tools, CLI/gateway/desktop/dashboard/Telegram/Slack surfaces. Later non-Wisdom work on shared files (guest onboarding i18n, dashboard startup schema, Slack adapter, tui_gateway) is kept; Wisdom-only call sites and config were stripped from those files.
Reverts the in-tree org skill-marketplace: hermes_wisdom package, three model tools, CLI/gateway/desktop/dashboard/Telegram/Slack surfaces. Later non-Wisdom work on shared files (guest onboarding i18n, dashboard startup schema, Slack adapter, tui_gateway) is kept; Wisdom-only call sites and config were stripped from those files.
This reverts commit 0dcadf6.
#94266 shipped Collective Wisdom as an 80k-line in-tree feature spanning a core package, three model tools, CLI/gateway/TUI/dashboard/desktop surfaces and Telegram/Slack adapters; #108507 deleted it. This brings the capability back at the footprint it should have had: one bundled plugin under plugins/wisdom/ with zero core edits. - package.py: the Gateway's instruction-only contract (allowed paths, size caps, canonical content-manifest + author-description hashing, manifest schema v1). Byte-exact against the Gateway's published hash vectors. - client.py: /v1/sync/wisdom/ over the shared Nous sync identity; every downloaded blob and the whole package are hash-verified before use. - service.py: browse / show / status / install / update / uninstall / share, each mutation behind a caller-supplied confirm() so nothing is applied without a human seeing the exact version, hashes and Gateway verdicts. Installs live under skills/_wisdom/<org>/<slug>/ and are indexed like any other skill. - __init__.py: tools wisdom_browse / wisdom_install / wisdom_share (visible only when the Nous token carries wisdom:* scopes), the /wisdom slash command and `hermes wisdom` CLI. Model-tool consent rides the same human approval gate as dangerous shell commands (fail-closed when unattended). Dropped on purpose: proactive advice queues, delivery leases, weekly agent review, Telegram/Slack card adapters, Desktop/dashboard panels, the 13k-line vendored OpenAPI document and the demo stack. Those are product surface for a later plugin iteration, not core.
#94266 shipped Collective Wisdom as an 80k-line in-tree feature spanning a core package, three model tools, CLI/gateway/TUI/dashboard/desktop surfaces and Telegram/Slack adapters; #108507 deleted it. This brings the capability back at the footprint it should have had: one bundled plugin under plugins/wisdom/ with zero core edits. - package.py: the Gateway's instruction-only contract (allowed paths, size caps, canonical content-manifest + author-description hashing, manifest schema v1). Byte-exact against the Gateway's published hash vectors. - client.py: /v1/sync/wisdom/ over the shared Nous sync identity; every downloaded blob and the whole package are hash-verified before use. - service.py: browse / show / status / install / update / uninstall / share, each mutation behind a caller-supplied confirm() so nothing is applied without a human seeing the exact version, hashes and Gateway verdicts. Installs live under skills/_wisdom/<org>/<slug>/ and are indexed like any other skill. - __init__.py: tools wisdom_browse / wisdom_install / wisdom_share (visible only when the Nous token carries wisdom:* scopes), the /wisdom slash command and `hermes wisdom` CLI. Model-tool consent rides the same human approval gate as dangerous shell commands (fail-closed when unattended). Dropped on purpose: proactive advice queues, delivery leases, weekly agent review, Telegram/Slack card adapters, Desktop/dashboard panels, the 13k-line vendored OpenAPI document and the demo stack. Those are product surface for a later plugin iteration, not core.
3-way merge (base ad03f20) of upstream release 0.21.2 (939e45c) into the RMK integration baseline (4bded63). 0 conflicts. - upstream 64 commits: wisdom-v1 removal (NousResearch#94266), relay/turn_author metadata, deepseek-flash vision metadata, desktop/UI fixes - RMK 25 commits preserved: adaptive smart routing, graph engine, background-review, docker atexit drain - agent/routing/*, turn_context, turn_usage, turn_api_error and chat_completion_helpers are untouched by upstream in this window: the verified routing repair survives the merge unchanged. - state.db / SessionDB core untouched by upstream in this window. Next: verify routing suites, run_agent baseline, targeted DB/gateway/ desktop tests against this merge, then live provider smoke.
Deadline Handoff (September 10)
The user has deferred acceptance checks to a later consolidated session and requested code completion without further hardening or broad test expansion. The current implementation is complete and pushed across Agent
e7de0c4c22, Gateway PR #255, and Portal1edbc697c. This is code completion, not acceptance or merge readiness.The last code gap fixed was policy-specific offline Not Now suppression. Its shorter/longer-period cases reproduced the defect; 154 focused tests across six files plus Ruff/whitespace checks pass. Legacy JSON mutation controls are retired; native review expiry/Recheck and receipt-bound operation outcomes are implemented, not outstanding infrastructure work.
Deferred together: live surface/two-member acceptance, deployed compatibility/recovery checks, manager-email provider/recipient/schedule enablement, release CI/review and deployment. The existing demo is unchanged; the offline-expiry fix is not yet serving. The three undecided product-owner copy choices remain unchanged. The internal integration tracker preserves the full deferred checklist.
Latest: Saved Command Approvals (September 10)
Agent
f7ec19830cand9ed3255599complete the command wiring for local CLI/TUI, Telegram and Slack install/update reviews, including old unversioned buttons. Final approvals survive callback-memory loss, remain bound to the reviewed version and selected update policy, and require a fresh review when expired. Wrong-actor/address controls and repeated application remain guarded. No extra approval step was added.Command replies use passive saved reviews rather than queueing duplicate notifications. Rendering is not recorded as successful platform delivery. Live platform acceptance and delivery/recovery verification remain separate.
Focused verification: 305 tests passed across nine files, plus 40 setup-execution tests. Real service, SQLite, files and adapter dispatch are exercised with fixture transports. Ruff and whitespace checks pass. CI on
f7ec19830cfound two setup fixtures missing required security metadata; both are corrected bye4883b15bfwithout weakening production checks. Final-head CI is pending; the maintainerci-reviewedgate remains outstanding.Deadline priority: finish existing integration/live checks and release gates, not expand speculative hardening or unit coverage. The user-approved local demo restart now serves Agent
e4883b15bf; all services, team scopes, Telegram polling, Slack Socket Mode and authenticated Portal management pass smoke checks. No skill was reset, installed or published, and no test card was injected. Gateway/Portal versions, persistent data and disabled email settings are unchanged. Full manual Desktop/Dashboard UAT remains deferred. Email environment/recipient approval and provider/scheduling evidence remain outstanding. Historical checkpoints below are retained as evidence, not current completion claims.September 10 expired review reads
3f8a80b7e9shows expired native reviews as Expired with Recheck when opened, expanded or listed, rather than retaining an unusable confirmation control. Reads do not renew consent, record outcomes, upload or apply work. Completed operations keep their completed state.69f1f28663functional CI passed; the requiredci-reviewedgate remains unresolved. No gate bypass or running-demo update.September 10 shared review copy validation
69f1f28663aligns browse, version history, group views and full reviews with icon-first security checks and no redundant Pass label. PR3 professionalism copy is preserved.ddd83974aafunctional CI passed; the requiredci-reviewedlabel gate remains unresolved. No gate bypass. Running demo stays at Agent20bdfc0248, Gateway4ab34b3, Portal1edbc697cc; neither publisher-evidence nor this cleanup has been adopted there.Latest checkpoint: reviewed publisher usage (September 10)
Agent
ddd83974aaadds an editable, dated Publisher usage (client-reported) summary to new agent-prepared sharing packages. Counts come from the local skill ledger, not the model; only totals and the seven-day date range are included. They may span local revisions and are not proof of successful outcomes. No recorded usage means no invented claim.The existing author-description review and three-hash approval cover this copy. It stays local until approved upload, remains frozen across later invocations/retries, and can be edited or removed. Stale approval cannot publish edits; recheck produces fresh consent. Exact-version recipient inspection retains the approved text. Manual private-draft creation does not silently append usage telemetry. Recipient guidance no longer invents publisher reliance when evidence is absent.
Validation: 957 Wisdom tests passed, one skipped, across 44 files; 129 focused tests, Ruff and whitespace checks pass. The native queue/CAS regression covers both retained and removed evidence and fails when the summary connection is removed. These are isolated integration tests, not fresh live Telegram/Slack/Portal publication acceptance.
Contract pin is Gateway
4ab34b3e8e8a172a1440fb01b917093fdb9165ee, OpenAPI SHA-2563c38558c4da0d0ee4242bef3e29c70276daa1d17cb34aff4fb1139993bdff2f0. Its retired legacy prose-bearing POST routes return authenticated 410; current typed native delivery is unchanged. Schema/vector pins are unchanged.All source is pushed. New-head CI remains to be verified. On the prior
20bdfc0248head, actual test/lint/build jobs passed, but the existing ci-reviewed maintainer label gate and its aggregate failed; no label was added or bypassed. The approved local demo restart uses that prior tested Agent head with aligned Gateway/Portal. This publisher-evidence change is not yet adopted into the running demo. Production rollout and the remaining cross-surface acceptance gates are still open.Earlier checkpoint: analytics contract alignment (September 10)
Head
a695cbef2e4afd86d2a0124160db65a4a1dfc22bupdates only the checked-in Gateway OpenAPI and contract pin to9ab95ef6114268e6f2ef356051be914761f1f969. The generic analytics contract rejects private/free-form metadata and routes verification claims through receipt-bound outcomes. The Agent does not currently call that generic endpoint; no telemetry emitter or opt-in behavior was added.Contract/hash-vector verification, six focused contract tests, Ruff and whitespace checks pass. The prior 1,152-test result below applies to the preceding implementation head, not a fresh full-suite run for this pin-only update. Current-head remote CI is running. The review-label gate requires a maintainer's
ci-reviewedapproval for the existing.github/workflows/ci.yamlchange removing two unsupported sparse-checkout inputs from the local detect-changes action. No label was added or gate bypassed. This administrative gate is distinct from the test jobs; no overall CI-pass claim is made.The local demo still serves
3a0dc84031. No files were installed, no cards were manually delivered, and no rollout settings were enabled. Native browse/install recovery after Not Now and the remaining broader acceptance gates stay open.Earlier checkpoint: exact checks before command confirmation (September 10)
Head
3a0dc84031db6bc7596227b77c2ad83f994f8afaadds exact-version security and advisory professionalism reviews to install/update command confirmations. The compact card and Show/Hide checks share the native advice presentation. Expanding preserves the approval receipt and Back navigation without creating another plan or applying files. Pending/blocked/unavailable security withholds quick confirmation; advisory professionalism absence remains explicit. Metadata failures stay retryable and a changed version/content hash fails as stale.Eight new regression cases failed before the fix. Final validation: 1,152 tests across 55 files pass, zero failures, one Linux-only skip on macOS; Ruff, whitespace and contract-pin verification pass. A real Gateway/service/controller probe used a temporary store, created one exact-v1 plan, and exercised Telegram/Slack rendering with the same receipt. No live platform delivery or installation is claimed.
This head now serves the local demo after an owned-process restart. The messaging control socket confirms the exact commit; Telegram polling, Slack Socket Mode, team-scoped authentication and Gateway/Dashboard health pass. Real Portal numeric-entry/save/reload and stale-policy rejection also pass, with the original policy restored. At that earlier checkpoint, remote CI had no visible run, and actual native browse/install/deferred-card acceptance remains unverified. Live local owner/member policy authorization now passes, including rejected member writes and unchanged policy state. The broader lifecycle, deployed-environment authorization, privacy, setup and email acceptance work remains open.
Earlier checkpoint: installation-aware discovery (September 10)
Head
3eb0fc45c1436a8e4f12eda9095d81c8cef84626fixes browse/detail Install controls that ignored existing managed installations. Private views show the active current-team version, remove redundant Install for current/newer local versions, and offer Review update for older versions through the existing checked plan and separate confirmation. Uninstalled skills retain exact-version Install. Group browse/pagination neither read nor expose device installation state.Eight regression cases reproduced failures before the fix. Twelve new cases cover real temporary SQLite, inactive/foreign-team isolation, wrong-actor refusal, update-plan dispatch without apply, pagination refresh, and Telegram/Slack renderers. The selected regression suite passes 1,144 tests across 55 files, zero failures, one Linux-only skip on macOS. Ruff, whitespace and contract verification pass.
Read-only checks with the patched controller against the real demo Gateway/local store confirm current, outdated and uninstalled behavior. No actual platform send/install is claimed. The serving demo remains on Agent
07e7cc63b2; this fix was developed in an isolated checkout. New-head CI and runtime adoption remain separate. Prior head's code/security/platform jobs, Docker and Nix passed; the review-label and aggregate gates failed, Desktop E2E skipped.Live numeric-policy save/reload, native installation, deferred-card recovery and the broader lifecycle/privacy/setup/email acceptance scope remain open.
Earlier checkpoint: private package review navigation (September 10)
Head
07e7cc63b25a66e82edf3870cf618bbd64cfb3ackeeps Back to first page on the explicit read-only page action. The previous callback entered legacy Portal review and uploaded the private draft; a rendered-callback regression reproduced that behavior. Package review pages also offer Not Now through existing scoped deferral, preserving the package and separate exact-hash approval.Validation: 1,775 Python tests across 55 files passed, zero failures, one Linux-only skip on macOS. The new two-case invariant covers wrong-actor denial, actual callback dispatch, no upload during navigation/deferral, retained hashes and subsequent explicit approval. Existing Desktop review suites passed 34 tests and Dashboard review/activity passed 14. Ruff, whitespace and contract verification passed.
Previous-head CI 34426156864 passed code/security/platform jobs; Desktop E2E skipped, review-label and aggregate gates failed. Docker 34426154883 and Nix 34426154732 passed. New-head CI is separate. No review labels, live messages or serving demo changed. Live review/cancel, recovery and broader cross-surface acceptance remain open.
Earlier checkpoint: queued feed coalescing (September 10)
Head
0d7208f0db4adf413121320a0cda6b77126acec4keeps only the newest automatic publication/update recommendation eligible per team and skill. Same-version duplicates retain their original assessment identity. Explicit requests and informational notices remain separate.Coalescing fences obsolete unsent leases and pending consent during ingestion, claim and pre-send checks. Historical, in-flight and uncertain delivery records remain intact; late receipts still settle their existing reservation. No schema or Gateway API changes.
1,773 tests / 55 files pass, zero failures, one Linux-only skip on macOS. Two parameterized invariants cover 20 cases; 14 cases reproduced the original regression. Ruff, diff checks and contract verification pass. Tests use isolated local stores and injected Gateway responses, not live platform acceptance.
Previous-head CI
34425246659passed code/test/security/platform jobs; Desktop E2E skipped; review-label and aggregate gates failed. New-head CI is separate. Demo processes and real messages are untouched. Live recommendation/relevance acceptance and the remaining lifecycle/privacy/setup/email scope stay open.Earlier checkpoint: proactive notification settings (September 10)
Head
dcc04cfb89fa22f4ac95e45d80e797565748c233adds scoped Notification settings shortcuts to Telegram/Slack advice and digests, with read-only opening, separate duration confirmation, and Back to the current inbox. Local notifications include/wisdom mute. Slack callbacks now retain the originating profile rather than the adapter default.1,753 tests / 54 files pass, zero failures, one Linux-only skip on macOS. Missing shortcuts and secondary-profile routing were reproduced red before the fix. Ruff, diff checks and unchanged contract pins pass. Live platform acceptance is not claimed.
Prior-head CI
34424343759passed code/test/security/platform jobs; Desktop E2E skipped; review-label and aggregate gates failed. New-head CI remains required. Serving demo and real messages are unchanged. Recommendation coalescing, lifecycle/privacy/setup/email work and live two-member acceptance remain open.Earlier checkpoint: authenticated feed reactivation (September 10)
Head
8763317176db213e1b4f82f68618487a0e0864decompletes the signed-out feed catch-up implementation; live acceptance remains separate.34423209982passed code/test jobs; only the maintainer review-label gate and aggregate failed. New-head CI remains required. No labels/gates bypassed.Earlier checkpoint: feed sign-out race (September 10)
Head
05398394973e2f2ea74df0b613a6a8916c8385debuilds on the upstream merge below.34422560795finished with code/test/security/platform jobs passing and Desktop E2E skipped. Only the maintainer review-label gate and its aggregate failed; neither was bypassed. This new head needs its own CI result.Earlier checkpoint: revocation and upstream reconciliation (September 10)
Head
4cb8acce32dcafaf54922647a6c8a6f40e6a77e9merges upstream145c713f1691b44bc485ce0ce4818cdb0e9c396b. GitHub now reports MERGEABLE. No workflow run/check is listed for this head yet; remote CI remains required.7640894a0c: confirmed persisted terminal Nous revocation now cancels queued advice even with a cached client. Ordinary expiry and transient connectivity/server failures do not cancel offline work. Real auth refresh/SQLite regressions use temporary profiles and injected HTTP 401/503 responses; two cases failed before the fix.8a888d68129c20ff6ae40f4ca7bb4a28d72de5a5.Explicit account sign-out checkpoint (September 10)
Head
4398afcac4219e319fab276e901d09e5df969a84connects the shared Nous disconnect path to profile-local Wisdom cancellation.Stable Portal-link checkpoint (September 10)
Review and notification cards were guessing the Portal team slug from the organization ID. This only works when the ID suffix happens to equal the slug.
Head
dc370df585c5098dffad2b03fa6d97dd4d86cd18uses one URL builder for service results and consumption notifications. It preserves the opaque team ID, configured Portal origin and exact published version in authenticated stable entry points.71b24f11b11eef4000d82917d3bd703337aed649to deploy first. Portal resolves current membership and the current team slug at click time; rendering cards adds no account API request.Coordinated contract checkpoint (September 10)
Head
7f794e71ddb178879929c0d3207cbf2b6df6384faligns Agent and Portal on Gateway8a888d68129c20ff6ae40f4ca7bb4a28d72de5a5. The diff adds only manager-email service endpoints and schemas; no existing Agent endpoint/schema changed. This pin does not grant the Agent service-only mail authority or enable a sender.f04a2b260ecc669a35c8845461df632202efee8e42ac561ae17104ef28db0075. Package-manifest and canonical-vector artifacts remain byte-identical to Gateway, with their existing hashes unchanged.8a888d6and this Agent source, including current Slack parity and tenant-leakage checks. Production adapters/router code were exercised with disposable Redis and temporary Agent home; platform APIs were harnesses, not real Telegram/Slack UAT. Owned resources were removed.8a888d6and Portal main CI ate4d01270care verified green. Agent CI34365790163at this head passed code/test/security/platform jobs; Desktop E2E was skipped. The maintainer review-label gate and aggregate failed. No gate or label was bypassed. Live coordinated deployment, legacy Unicode compatibility/recovery, setup/lifecycle/email and full surface acceptance remain open. No serving demo checkout, profile, credential, organization setting or rollout switch changed.Historical missing prerequisite recovery checkpoint (September 9)
Current head:
2294bb1d91216d96aa68444537f5ae3c29c62c34.34344889449at477ab7c541: code/test jobs passed; Desktop E2E skipped; maintainer review-label gate and aggregate failed. No gates bypassed; new-head CI remains separate.Automatic-update setup handoff checkpoint (September 9)
Earlier checkpoint head:
477ab7c5411dc1166050becab957a590ce42c138.34343132595atda3bff45f4: code/test jobs passed, Desktop E2E skipped, maintainer review-label gate and aggregate failed. No labels or gates bypassed; new-head CI remains pending separately.Desktop setup review checkpoint (September 9)
Earlier checkpoint head:
da3bff45f428c2fc4292d1534baae5a9fdd25891.34340968834completed with code/test jobs passing, Desktop E2E skipped, and the maintainer review-label gate/aggregate failing. No gate was bypassed. New-head CI must be evaluated separately.This checkpoint supersedes the earlier Desktop setup implementation-gap note only. Other remaining work and live acceptance gates below are unchanged.
Missing-model setup recovery checkpoint (September 9)
Earlier checkpoint head:
05520a9bac823e920aae0ebbd330c8b237ae217a.34339674517completed with code/test jobs passing. Only the maintainer review-label gate and aggregate failed; Desktop E2E was skipped. No gate was bypassed. New-head CI remains pending.Fixed-copy setup scheduling checkpoint (September 9)
Earlier fixed-copy checkpoint:
0809c2bbce3c5d1f7045fa8ef770294cbf7317c3. Its remaining-work notes are historical where the latest checkpoint explicitly supersedes them.34337858459completed with all code/test jobs passing. The maintainer review-label gate and its aggregate failed; neither was bypassed. New-head CI is pending.Guided setup handoff checkpoint (September 9)
Earlier guided-handoff head:
a4efb1514a4504d628c7d3e66676b5a1df2f60b7. Historical remaining-work notes below are superseded only where explicitly addressed by the latest checkpoint.34336208974exposed two test preconditions: an optional Telegram SDK and the fixed-copy opt-out branch. Those are explicit now; both affected files passed locally (700 tests, with the SDK installed). New-head/minimal-SDK CI remains pending. The separate maintainer review-label gate has not been bypassed.Native setup and demo-fix checkpoint (September 9)
Earlier recovery checkpoint:
4831fe5a4f928a2b5b47ed63391403c79261f9cd. This is an implementation checkpoint, not rollout approval.Current integration checkpoint (September 9)
Earlier copy-integration checkpoint:
cab214e277bbea9e2a5a7b9e25ab92934b43c2e5. Upstream reconciliation is committed at5de466f376; all 22 conflicts were resolved while preserving upstream router, runner, TUI and sender ownership boundaries.60cd2d6b613ae3cd4a6e65155d1142006d907e78. The three producer artifacts are byte-identical across Gateway, Agent and Portal. All content hash vectors, including Unicode ordering, are verified; 186 focused Agent tests passed.17c7812788, not this new head. No real platform messages, publications, demo restarts or database mutations were performed during reconciliation.September 9 CI follow-up
Product-owner copy integration
Fork PR #3 at
1ec627710is integrated with its contributor commits preserved. Copy was ported to the upstream-extracted Telegram/Slack Wisdom mixins.Original V1 scope
This is the Agent-side implementation of Hermes Collective Wisdom V1. It delivers the local contribution and managed-consumption loop: private candidate qualification, owner-reviewed publication, explicit installation, compatibility checks, updates, notifications, uninstall, CLI, Dashboard, Desktop, Telegram, and Slack workflows.
Rollout remains disabled until the reconciled Gateway and Portal heads are deployed, live cross-repository tenant-isolation UAT is recorded, implementation screenshots are captured against that stack, and product-owner dogfood sign-off is recorded.
Privacy and qualification
wisdom/wisdom.dbwith restrictive database/WAL/SHM permissions, transactional migrations, stable local identities, source snapshots, candidate state, hash-bound review receipts, installations, and crash-recovery journals.auxiliary.background_review; failures become advisoryunavailableresults and never strand the contribution flow.Consent-bound publication
SKILL.md, one rootskill.manifest.json, and narrowly allowlisted inert UTF-8 support text.Managed consumption
_wisdom/<org-id>/<slug>namespace with exact-byte staging and canonical content verification.REQUIRED, applies when either local scanner reports any finding.Interfaces
hermes wisdom setup|status|scan|suggest|candidates|review|approve|decline|list|show|install|versions|check|update|uninstall--jsonoutput plus documented exit categories.Review follow-up
Addressed from the review at head
c252b4e8:REQUIREDno longer bypasses scanner findings in either planning or execution.SKILL.md; generated fields remain local until copied into the explicit owner-review overlay.0600while the profile Wisdom directory remains0700.YYYY-MM-DDTHH:mm:ss.sssZ) for both successful and unavailable results.Left explicit for follow-up rather than changing product semantics in this review pass:
SKILL.mdsupport-file changes alone should count as a meaningful refinement.Contract and rollout order
The current contract is pinned to:
d51078fd30ed461542dfbbf25a5b810b6b5120364ab34b3e8e8a172a1440fb01b917093fdb9165ee3c38558c4da0d0ee4242bef3e29c70276daa1d17cb34aff4fb1139993bdff2f064d0010eada1d79fa16309e9fd715faf77b6186360ea0b095182b2bdaeec5714eff9b596d1bd9c46eda287b7231b11c35e5c0ae3b193e645d5b0a421b7570974Merge/deploy order: finalize Gateway PR #255 and the remaining integration, refresh both consumer contracts from the final Gateway commit, then deploy Gateway and Portal before enabling this Agent head. The consumers now align with the producer commit above. Re-pin if further Gateway changes alter the contract; coordinated deployment and remaining live acceptance gates are not complete.
Historical V1 validation
These results describe the earlier V1 checkpoint, not a fresh full-suite run on the current head.
mainat593aa74c6182ce2e5e23bc102daaaae71710c05dpytest tests/wisdom -q: 199 passedscripts/verify_wisdom_contract.py: passed with the pinned commit and digestgit diff --check: passedOriginal V1 checkpoint head:
ff8efcb29766de5614ba758684465b3e3c2c8828. Current head is listed above.September 10: Legacy Install Controls Require Fresh Review
Agent
ac4f427cf3replaces immediate apply from unversioned Telegram/Slack install/update buttons with the shared exact-package review and a separate scoped confirmation. Receipt-only legacy confirmations offer current browse navigation without reading or applying their receipt. Callbacks bind user, profile, organization, chat, thread and Slack workspace; explicit DM continuation may change conversation but not workspace authority.Agent
fc5e72374falso fixes approval lifetime: Show/Hide checks cannot renew the underlying review. Even a still-valid transport token cannot approve after the original deadline. Expired projections offer Recheck, which refreshes plan/check evidence without applying and requires a new confirmation. Install refresh preserves the selected version and update mode.Validation: four clock-controlled cases fail against the pre-fix controller and pass with the fix. Actual adapter/WisdomService/SQLite/staging/file tests prove no write on expired confirmation, no apply on Recheck, no cross-user/thread/workspace confirmation, no silent latest-version substitution, and no duplicate installation record on repeated success. The 58-file suite passes 1,289 tests (one Linux-only skip), with all 74 command tests passing after the policy-preservation addition; Ruff and whitespace pass.
Functional CI for
ac4f427cf3passed. Its required maintainerci-reviewedlabel and aggregate gate remain red; no gate was bypassed. New-head CI forfc5e72374fis independent and pending. Live acceptance, runtime adoption and remaining native-command migration are still open. The running demo is unchanged.September 10: Native Install Policy Prerequisite
Agent
8ebddcc37apreserves explicit future-update policy choices through durable native review, expiry/Recheck and exact install application. A changed choice requires a new pending approval; in-flight/uncertain delivery is not replaced. Compact and expanded native cards show the selected policy. This prepares command-to-native migration; that wiring and live acceptance remain open.Validation: 1,301 tests passed across 59 files, one Linux-only skip; 77 changed-path tests passed after final text alignment; Ruff and whitespace checks passed. New cases exercise real WisdomService, SQLite and managed files with fixture registry/scan/bootstrap. Previous
fc5e72374ffunctional CI passed but the maintainerci-reviewedgate remains outstanding. New-head CI is separate. Demo and email enablement are unchanged.September 10: Native Card Edit Outcomes
Agent
a476df3e80reports failed Telegram card edits instead of swallowing them; only definite rich-format rejection falls back, and an already-current message is successful. Slack reports an unusable edit address rather than returning success. Both native adapters are tested with real WisdomService/SQLite/file installation: a failed edit followed by the same confirmation retry updates saved completion without a second install or a new card. Provider and registry transports are fixtures.Validation: 1,308 tests passed across 59 files, one Linux-only skip; Ruff and whitespace checks passed. Previous
8ebddcc37afunctional CI passed; the maintainer review-label gate remains outstanding. New-head CI is separate. Command-to-native migration, live acceptance, and demo adoption remain open; the demo was not changed.Model: OpenAI Codex
Harness: Codex desktop