Skip to content

feat(wisdom): add Hermes Collective Wisdom Agent V1 - #94266

Merged
benbarclay merged 157 commits into
NousResearch:mainfrom
shannonsands:codex/hermes-wisdom-consumption
Sep 11, 2026
Merged

benbarclay merged 157 commits into
NousResearch:mainfrom
shannonsands:codex/hermes-wisdom-consumption

Conversation

@shannonsands

@shannonsands shannonsands commented Aug 24, 2026 •

Copy link
Copy Markdown

Deadline Handoff (September 10)

The user has deferred acceptance checks to a later consolidated session and requested code completion without further hardening or broad test expansion. The current implementation is complete and pushed across Agent e7de0c4c22, Gateway PR #255, and Portal 1edbc697c. This is code completion, not acceptance or merge readiness.

The last code gap fixed was policy-specific offline Not Now suppression. Its shorter/longer-period cases reproduced the defect; 154 focused tests across six files plus Ruff/whitespace checks pass. Legacy JSON mutation controls are retired; native review expiry/Recheck and receipt-bound operation outcomes are implemented, not outstanding infrastructure work.

Deferred together: live surface/two-member acceptance, deployed compatibility/recovery checks, manager-email provider/recipient/schedule enablement, release CI/review and deployment. The existing demo is unchanged; the offline-expiry fix is not yet serving. The three undecided product-owner copy choices remain unchanged. The internal integration tracker preserves the full deferred checklist.

Latest: Saved Command Approvals (September 10)

Agent f7ec19830c and 9ed3255599 complete the command wiring for local CLI/TUI, Telegram and Slack install/update reviews, including old unversioned buttons. Final approvals survive callback-memory loss, remain bound to the reviewed version and selected update policy, and require a fresh review when expired. Wrong-actor/address controls and repeated application remain guarded. No extra approval step was added.

Command replies use passive saved reviews rather than queueing duplicate notifications. Rendering is not recorded as successful platform delivery. Live platform acceptance and delivery/recovery verification remain separate.

Focused verification: 305 tests passed across nine files, plus 40 setup-execution tests. Real service, SQLite, files and adapter dispatch are exercised with fixture transports. Ruff and whitespace checks pass. CI on f7ec19830c found two setup fixtures missing required security metadata; both are corrected by e4883b15bf without weakening production checks. Final-head CI is pending; the maintainer ci-reviewed gate remains outstanding.

Deadline priority: finish existing integration/live checks and release gates, not expand speculative hardening or unit coverage. The user-approved local demo restart now serves Agent e4883b15bf; all services, team scopes, Telegram polling, Slack Socket Mode and authenticated Portal management pass smoke checks. No skill was reset, installed or published, and no test card was injected. Gateway/Portal versions, persistent data and disabled email settings are unchanged. Full manual Desktop/Dashboard UAT remains deferred. Email environment/recipient approval and provider/scheduling evidence remain outstanding. Historical checkpoints below are retained as evidence, not current completion claims.

September 10 expired review reads

  • Agent 3f8a80b7e9 shows expired native reviews as Expired with Recheck when opened, expanded or listed, rather than retaining an unusable confirmation control. Reads do not renew consent, record outcomes, upload or apply work. Completed operations keep their completed state.
  • Reproduced on both Telegram and Slack callback paths. Final local verification: 1,049 tests passed, one skipped, across 46 files; Ruff and diff checks passed. New-head CI and live stale-control acceptance remain open.
  • The preceding 69f1f28663 functional CI passed; the required ci-reviewed gate remains unresolved. No gate bypass or running-demo update.

September 10 shared review copy validation

  • Agent 69f1f28663 aligns browse, version history, group views and full reviews with icon-first security checks and no redundant Pass label. PR3 professionalism copy is preserved.
  • Public discovery uses aggregate statuses only; detailed findings remain private. Local scan and fixed share summaries use no issues detected, without removing the required Gateway-check warning or security disclaimer.
  • Final local validation: 1,047 tests passed, one skipped, across 46 files; command-controller tests exercise Telegram HTML and Slack blocks. Ruff and diff checks pass. Live delivery and new-head CI remain separate acceptance gates.
  • Previous head ddd83974aa functional CI passed; the required ci-reviewed label gate remains unresolved. No gate bypass. Running demo stays at Agent 20bdfc0248, Gateway 4ab34b3, Portal 1edbc697cc; neither publisher-evidence nor this cleanup has been adopted there.

Latest checkpoint: reviewed publisher usage (September 10)

Agent ddd83974aa adds an editable, dated Publisher usage (client-reported) summary to new agent-prepared sharing packages. Counts come from the local skill ledger, not the model; only totals and the seven-day date range are included. They may span local revisions and are not proof of successful outcomes. No recorded usage means no invented claim.

The existing author-description review and three-hash approval cover this copy. It stays local until approved upload, remains frozen across later invocations/retries, and can be edited or removed. Stale approval cannot publish edits; recheck produces fresh consent. Exact-version recipient inspection retains the approved text. Manual private-draft creation does not silently append usage telemetry. Recipient guidance no longer invents publisher reliance when evidence is absent.

Validation: 957 Wisdom tests passed, one skipped, across 44 files; 129 focused tests, Ruff and whitespace checks pass. The native queue/CAS regression covers both retained and removed evidence and fails when the summary connection is removed. These are isolated integration tests, not fresh live Telegram/Slack/Portal publication acceptance.

Contract pin is Gateway 4ab34b3e8e8a172a1440fb01b917093fdb9165ee, OpenAPI SHA-256 3c38558c4da0d0ee4242bef3e29c70276daa1d17cb34aff4fb1139993bdff2f0. Its retired legacy prose-bearing POST routes return authenticated 410; current typed native delivery is unchanged. Schema/vector pins are unchanged.

All source is pushed. New-head CI remains to be verified. On the prior 20bdfc0248 head, actual test/lint/build jobs passed, but the existing ci-reviewed maintainer label gate and its aggregate failed; no label was added or bypassed. The approved local demo restart uses that prior tested Agent head with aligned Gateway/Portal. This publisher-evidence change is not yet adopted into the running demo. Production rollout and the remaining cross-surface acceptance gates are still open.

Earlier checkpoint: analytics contract alignment (September 10)

Head a695cbef2e4afd86d2a0124160db65a4a1dfc22b updates only the checked-in Gateway OpenAPI and contract pin to 9ab95ef6114268e6f2ef356051be914761f1f969. The generic analytics contract rejects private/free-form metadata and routes verification claims through receipt-bound outcomes. The Agent does not currently call that generic endpoint; no telemetry emitter or opt-in behavior was added.

Contract/hash-vector verification, six focused contract tests, Ruff and whitespace checks pass. The prior 1,152-test result below applies to the preceding implementation head, not a fresh full-suite run for this pin-only update. Current-head remote CI is running. The review-label gate requires a maintainer's ci-reviewed approval for the existing .github/workflows/ci.yaml change removing two unsupported sparse-checkout inputs from the local detect-changes action. No label was added or gate bypassed. This administrative gate is distinct from the test jobs; no overall CI-pass claim is made.

The local demo still serves 3a0dc84031. No files were installed, no cards were manually delivered, and no rollout settings were enabled. Native browse/install recovery after Not Now and the remaining broader acceptance gates stay open.

Earlier checkpoint: exact checks before command confirmation (September 10)

Head 3a0dc84031db6bc7596227b77c2ad83f994f8afa adds exact-version security and advisory professionalism reviews to install/update command confirmations. The compact card and Show/Hide checks share the native advice presentation. Expanding preserves the approval receipt and Back navigation without creating another plan or applying files. Pending/blocked/unavailable security withholds quick confirmation; advisory professionalism absence remains explicit. Metadata failures stay retryable and a changed version/content hash fails as stale.

Eight new regression cases failed before the fix. Final validation: 1,152 tests across 55 files pass, zero failures, one Linux-only skip on macOS; Ruff, whitespace and contract-pin verification pass. A real Gateway/service/controller probe used a temporary store, created one exact-v1 plan, and exercised Telegram/Slack rendering with the same receipt. No live platform delivery or installation is claimed.

This head now serves the local demo after an owned-process restart. The messaging control socket confirms the exact commit; Telegram polling, Slack Socket Mode, team-scoped authentication and Gateway/Dashboard health pass. Real Portal numeric-entry/save/reload and stale-policy rejection also pass, with the original policy restored. At that earlier checkpoint, remote CI had no visible run, and actual native browse/install/deferred-card acceptance remains unverified. Live local owner/member policy authorization now passes, including rejected member writes and unchanged policy state. The broader lifecycle, deployed-environment authorization, privacy, setup and email acceptance work remains open.

Earlier checkpoint: installation-aware discovery (September 10)

Head 3eb0fc45c1436a8e4f12eda9095d81c8cef84626 fixes browse/detail Install controls that ignored existing managed installations. Private views show the active current-team version, remove redundant Install for current/newer local versions, and offer Review update for older versions through the existing checked plan and separate confirmation. Uninstalled skills retain exact-version Install. Group browse/pagination neither read nor expose device installation state.

Eight regression cases reproduced failures before the fix. Twelve new cases cover real temporary SQLite, inactive/foreign-team isolation, wrong-actor refusal, update-plan dispatch without apply, pagination refresh, and Telegram/Slack renderers. The selected regression suite passes 1,144 tests across 55 files, zero failures, one Linux-only skip on macOS. Ruff, whitespace and contract verification pass.

Read-only checks with the patched controller against the real demo Gateway/local store confirm current, outdated and uninstalled behavior. No actual platform send/install is claimed. The serving demo remains on Agent 07e7cc63b2; this fix was developed in an isolated checkout. New-head CI and runtime adoption remain separate. Prior head's code/security/platform jobs, Docker and Nix passed; the review-label and aggregate gates failed, Desktop E2E skipped.

Live numeric-policy save/reload, native installation, deferred-card recovery and the broader lifecycle/privacy/setup/email acceptance scope remain open.

Earlier checkpoint: private package review navigation (September 10)

Head 07e7cc63b25a66e82edf3870cf618bbd64cfb3ac keeps Back to first page on the explicit read-only page action. The previous callback entered legacy Portal review and uploaded the private draft; a rendered-callback regression reproduced that behavior. Package review pages also offer Not Now through existing scoped deferral, preserving the package and separate exact-hash approval.

Validation: 1,775 Python tests across 55 files passed, zero failures, one Linux-only skip on macOS. The new two-case invariant covers wrong-actor denial, actual callback dispatch, no upload during navigation/deferral, retained hashes and subsequent explicit approval. Existing Desktop review suites passed 34 tests and Dashboard review/activity passed 14. Ruff, whitespace and contract verification passed.

Previous-head CI 34426156864 passed code/security/platform jobs; Desktop E2E skipped, review-label and aggregate gates failed. Docker 34426154883 and Nix 34426154732 passed. New-head CI is separate. No review labels, live messages or serving demo changed. Live review/cancel, recovery and broader cross-surface acceptance remain open.

Earlier checkpoint: queued feed coalescing (September 10)

Head 0d7208f0db4adf413121320a0cda6b77126acec4 keeps only the newest automatic publication/update recommendation eligible per team and skill. Same-version duplicates retain their original assessment identity. Explicit requests and informational notices remain separate.

Coalescing fences obsolete unsent leases and pending consent during ingestion, claim and pre-send checks. Historical, in-flight and uncertain delivery records remain intact; late receipts still settle their existing reservation. No schema or Gateway API changes.

1,773 tests / 55 files pass, zero failures, one Linux-only skip on macOS. Two parameterized invariants cover 20 cases; 14 cases reproduced the original regression. Ruff, diff checks and contract verification pass. Tests use isolated local stores and injected Gateway responses, not live platform acceptance.

Previous-head CI 34425246659 passed code/test/security/platform jobs; Desktop E2E skipped; review-label and aggregate gates failed. New-head CI is separate. Demo processes and real messages are untouched. Live recommendation/relevance acceptance and the remaining lifecycle/privacy/setup/email scope stay open.

Earlier checkpoint: proactive notification settings (September 10)

Head dcc04cfb89fa22f4ac95e45d80e797565748c233 adds scoped Notification settings shortcuts to Telegram/Slack advice and digests, with read-only opening, separate duration confirmation, and Back to the current inbox. Local notifications include /wisdom mute. Slack callbacks now retain the originating profile rather than the adapter default.

1,753 tests / 54 files pass, zero failures, one Linux-only skip on macOS. Missing shortcuts and secondary-profile routing were reproduced red before the fix. Ruff, diff checks and unchanged contract pins pass. Live platform acceptance is not claimed.

Prior-head CI 34424343759 passed code/test/security/platform jobs; Desktop E2E skipped; review-label and aggregate gates failed. New-head CI remains required. Serving demo and real messages are unchanged. Recommendation coalescing, lifecycle/privacy/setup/email work and live two-member acceptance remain open.

Earlier checkpoint: authenticated feed reactivation (September 10)

Head 8763317176db213e1b4f82f68618487a0e0864de completes the signed-out feed catch-up implementation; live acceptance remains separate.

  • Setup checkpoints signed-out announcements silently using existing authenticated feed pages before restoring authority. First-time discovery is retained, and future arrivals after the checkpoint remain eligible. No new Gateway API or timestamp-based cursor inference.
  • Schema v12 binds the cursor to organization/registered installation and persists the resume requirement. HTTP failure, stalled paging and the 100-page bound leave setup resumable from its last page. Generation checks fence logout during capability, registration, catch-up and final activation.
  • Team/account changes cannot reuse another scope's cursor. Only a Gateway-confirmed identity ownership conflict generates a new installation ID; revocation and other failures do not. Existing installation/moderation reconciliation and operation/delivery journals are preserved.
  • 1,748 tests across 54 files pass, zero failures, one Linux-only skip on macOS. Two new parameterized invariants cover 48 cases across current/v11/v10 databases, same-team/team/account reauthentication, HTTP/stalled/bounded paging, restart, future arrivals, logout races and revoked identity refusal. Ruff, diff checks and contract verification pass. Tests use temporary profiles and injected HTTP responses, not real-platform UAT.
  • Prior-head CI 34423209982 passed code/test jobs; only the maintainer review-label gate and aggregate failed. New-head CI remains required. No labels/gates bypassed.
  • Serving demo, real credentials/messages, policies, email and rollout switches are untouched. Live auth/recovery acceptance, broader lifecycle/privacy/setup/email integration, coordinated deployment and two-member UAT remain open.

Earlier checkpoint: feed sign-out race (September 10)

Head 05398394973e2f2ea74df0b613a6a8916c8385de builds on the upstream merge below.

  • Sign-out retires cached feed notices without deleting history, cursor or delivery receipts. A persisted local generation fences HTTP page commits, so a pre-logout response cannot recreate notices or advance the cursor, even after same-team re-verification. Signed-out polls stop before HTTP.
  • SQLite schema v11 adds the generation in place. Ten cases across two invariants cover fresh/legacy databases, local and Telegram/Slack pending notices, restart, receipt retention and late responses through the real Wisdom client. Five behavioral cases failed before the fix.
  • 884 Wisdom tests across 41 files pass, zero failures, one Linux-only skip on macOS. Ruff and diff checks pass. Tests use temporary profiles and injected HTTP transport; no live-platform acceptance is claimed.
  • Merge-head CI 34422560795 finished with code/test/security/platform jobs passing and Desktop E2E skipped. Only the maintainer review-label gate and its aggregate failed; neither was bypassed. This new head needs its own CI result.
  • Still open: unfetched events accumulated while signed out, authenticated cursor catch-up/account scoping, and live reauthentication. Existing installation/moderation reconciliation must remain intact. The broader integration, privacy, lifecycle, setup, email and two-member acceptance scope remains open.
  • Serving demo, real credentials, messages, policies and rollout settings are unchanged.

Earlier checkpoint: revocation and upstream reconciliation (September 10)

Head 4cb8acce32dcafaf54922647a6c8a6f40e6a77e9 merges upstream 145c713f1691b44bc485ce0ce4818cdb0e9c396b. GitHub now reports MERGEABLE. No workflow run/check is listed for this head yet; remote CI remains required.

  • Preserves both Desktop Collective and upstream Plugins workspaces, their deep links and profile-scoped APIs. Retains upstream Dashboard plugin catalog fields alongside Wisdom APIs.
  • Includes 7640894a0c: confirmed persisted terminal Nous revocation now cancels queued advice even with a cached client. Ordinary expiry and transient connectivity/server failures do not cancel offline work. Real auth refresh/SQLite regressions use temporary profiles and injected HTTP 401/503 responses; two cases failed before the fix.
  • Reconciled validation: 1,690 Python tests across 52 files passed, zero failed, one Linux-only skip on macOS; 42 Desktop Skills tests passed, including both routing cases; full Desktop typecheck passed. Full Dashboard check passed 335 tests, typecheck and lint (28 existing warnings). Focused Desktop lint has four existing test warnings and no errors. Contract verification passes with Gateway 8a888d68129c20ff6ae40f4ca7bb4a28d72de5a5.
  • Signed-out feed replay is not fixed yet: profile-global cursor scoping, cached unassessed rows, catch-up after reauthentication and in-flight response fencing remain under review. Authoritative installation/moderation state must still reconcile.
  • No serving demo, credentials, messages, policies or rollout switches changed. Full lifecycle/privacy/setup/email work, coordinated deployment and live two-member acceptance remain open. Earlier checkpoint notes below are historical where superseded here.

Explicit account sign-out checkpoint (September 10)

Head 4398afcac4219e319fab276e901d09e5df969a84 connects the shared Nous disconnect path to profile-local Wisdom cancellation.

  • Retires pending/assessing/ready/fallback advice and pending confirmation controls. Clears verified organization and session/control availability. Re-verifying the team does not replay the old event or accept late model completion. Unrelated provider logout is unchanged.
  • Preserves operation journals and immutable delivery reservations. Already-dispatched sends become uncertain; matching late receipts persist while signed out, without authorizing a new send or resurrecting the session. Wrong-destination receipts are rejected. Settlement resumes after team re-verification.
  • Five new regression cases failed on the previous implementation. All 870 Wisdom tests pass, one Linux-only skip on macOS; 73 auth/delivery tests pass after final assertions. Ruff and diff checks pass. Tests use real auth files/SQLite in temporary profiles with fixture remote claim/settlement responses.
  • User documentation explains team re-verification via the existing setup command. No serving demo, actual credential, live message or rollout setting changed.
  • New-head CI, terminal token revocation, feed events published during a signed-out interval and live surface reauthentication remain open. This does not close the full logout/no-replay acceptance requirement.

Stable Portal-link checkpoint (September 10)

Review and notification cards were guessing the Portal team slug from the organization ID. This only works when the ID suffix happens to equal the slug.

Head dc370df585c5098dffad2b03fa6d97dd4d86cd18 uses one URL builder for service results and consumption notifications. It preserves the opaque team ID, configured Portal origin and exact published version in authenticated stable entry points.

  • Requires Portal companion 71b24f11b11eef4000d82917d3bd703337aed649 to deploy first. Portal resolves current membership and the current team slug at click time; rendering cards adds no account API request.
  • Existing URL install-reference parsing remains compatible. Local service, notification, mediation, publication and qualification regressions: 861 tests across 39 Wisdom files passed, one Linux-only skip on macOS. Ruff and diff checks passed.
  • Corrected one legacy test fixture that returned None from the string-valued Portal base URL helper. Production missing-config behavior still supplies the default Portal origin.
  • New-head CI and real-platform navigation acceptance remain open. Previously delivered malformed links are not automatically rewritten. The serving demo, profiles, credentials, settings and live messages are unchanged.

Coordinated contract checkpoint (September 10)

Head 7f794e71ddb178879929c0d3207cbf2b6df6384f aligns Agent and Portal on Gateway 8a888d68129c20ff6ae40f4ca7bb4a28d72de5a5. The diff adds only manager-email service endpoints and schemas; no existing Agent endpoint/schema changed. This pin does not grant the Agent service-only mail authority or enable a sender.

  • Updated the checked-in Gateway OpenAPI artifact and its verified SHA-256 to f04a2b260ecc669a35c8845461df632202efee8e42ac561ae17104ef28db0075. Package-manifest and canonical-vector artifacts remain byte-identical to Gateway, with their existing hashes unchanged.
  • Local canonical verifier and Ruff pass. 858 Wisdom tests across 38 files passed, zero failures, one platform skip, using the canonical isolated test runner.
  • All 28 cross-repository HTTP/socket E2E drivers passed against Gateway 8a888d6 and this Agent source, including current Slack parity and tenant-leakage checks. Production adapters/router code were exercised with disposable Redis and temporary Agent home; platform APIs were harnesses, not real Telegram/Slack UAT. Owned resources were removed.
  • Gateway main CI at 8a888d6 and Portal main CI at e4d01270c are verified green. Agent CI 34365790163 at this head passed code/test/security/platform jobs; Desktop E2E was skipped. The maintainer review-label gate and aggregate failed. No gate or label was bypassed. Live coordinated deployment, legacy Unicode compatibility/recovery, setup/lifecycle/email and full surface acceptance remain open. No serving demo checkout, profile, credential, organization setting or rollout switch changed.

Historical missing prerequisite recovery checkpoint (September 9)

Current head: 2294bb1d91216d96aa68444537f5ae3c29c62c34.

  • Missing setup commands/environment variables now receive native prerequisite reviews with their names, purpose and publisher handoff guidance. Missing items offer Recheck, never confirmation; Desktop receives the same canonical controls.
  • Recheck refreshes the exact-version facts without running commands or recording acknowledgement. Deferred reviews can be explicitly reopened, restart preserves continuation, and a requirement disappearing before confirmation cannot pass.
  • Environment values are configured privately using the existing active-profile environment workflow, not through chat or command arguments. The guidance distinguishes presence from successful verification and calls out profile reload after editing.
  • Local validation: 1,679 Python tests across 49 files passed, zero failures, one Linux-only skip on macOS. Sixteen new cases cover both copy modes, commands/variables, restart, deferral, changed packages, foreign actors, removal before confirmation, real verification execution and private-value exclusion from cards/model input/journals. Final wording passed the 16 focused cases again. Existing Desktop coverage: 50 tests across eight files. Ruff and diff checks pass.
  • Temporary profiles, injected provider responses and simulated transport receipts only. No running demo, credential, live message or rollout setting changed. Live cross-surface acceptance, richer inline credential-entry UI and remote execution contexts remain open, along with the full tracked objective.
  • Prior-head CI 34344889449 at 477ab7c541: code/test jobs passed; Desktop E2E skipped; maintainer review-label gate and aggregate failed. No gates bypassed; new-head CI remains separate.

Automatic-update setup handoff checkpoint (September 9)

Earlier checkpoint head: 477ab7c5411dc1166050becab957a590ce42c138.

  • Completed policy-authorized automatic updates now commit a durable setup handoff with the update journal. Setup starts from the recorded exact-version operation, without inventing user consent.
  • The eligible private session prepares the next step using its configured model. Native approval and terminal permission are still required before execution. Fixed-copy mode keeps setup enabled; absent models wait without consuming retries.
  • Existing setup controls and Not Now retain ownership. An old unconfirmed update offer does not suppress setup after an automatic update. Changed package/session authority invalidates a pending proposal, and prior-version verification cannot establish current readiness.
  • Local validation: 1,663 Python tests across 48 files passed, zero failures, one platform-specific skip. Includes 32 new cases across both automatic modes and copy modes, restart, missing models, stale proposals, deferred steps, prior update offers, actor isolation, real approved verification execution once, and transactional failure/recovery. Ruff and diff checks pass.
  • Temporary profiles, injected provider responses and simulated transport receipts were used. No running demo, live message, credential or rollout setting changed. This is not live Telegram/Slack/Desktop UAT. Credential/prerequisite UX, remote execution contexts and live setup/restart acceptance remain open, along with the broader tracked objective.
  • Prior-head CI 34343132595 at da3bff45f4: code/test jobs passed, Desktop E2E skipped, maintainer review-label gate and aggregate failed. No labels or gates bypassed; new-head CI remains pending separately.

Desktop setup review checkpoint (September 9)

Earlier checkpoint head: da3bff45f428c2fc4292d1534baae5a9fdd25891.

  • Desktop now displays canonical setup instructions, the complete proposed command and local execution context, step-specific consent, progress and interruption recovery controls. Completed install/update receipts offer Check setup.
  • The existing API accepts setup status/recovery/recheck actions and continues to authorize them through the consent service. Linked controls retain their actual id; passive views cannot apply actions. Polls preserve explicit recovery review while invalidating changed approval state.
  • Older backends retain their supported three-action path with full review and setup-specific labels. Missing instructions cannot be approved; compatibility copy is translated in all six locales.
  • Local validation: 1,631 Python tests across 47 files, zero failures, one Linux-only skip on macOS; 50 Desktop tests and 3 Dashboard tests; Desktop TypeScript and Ruff pass; ESLint has zero errors and one existing ref-cleanup warning. Chromium component checks at 1280, 390 and 320 px verify an untruncated 1,012-character command, no horizontal overflow, explicit actions and passive views.
  • No live demo, profile, org setting or platform messages changed. Browser checks use the actual component/CSS with a simulated action harness; they are not live Electron or messaging setup UAT. Credential/prerequisite UX, remote execution contexts, automatic-update handoff and live cross-surface restart/setup acceptance remain open.
  • Previous-head CI 34340968834 completed with code/test jobs passing, Desktop E2E skipped, and the maintainer review-label gate/aggregate failing. No gate was bypassed. New-head CI must be evaluated separately.

This checkpoint supersedes the earlier Desktop setup implementation-gap note only. Other remaining work and live acceptance gates below are unchanged.

Missing-model setup recovery checkpoint (September 9)

Earlier checkpoint head: 05520a9bac823e920aae0ebbd330c8b237ae217a.

  • Missing session models now leave setup pending without spending retry attempts or selecting a different provider. Workers can deliver prepared reviews and deterministic prerequisites without a cached agent; other model-dependent work remains unclaimed. Private-session, recent-activity, connection, turn and approval guards remain in force.
  • Completed native install/update/setup cards offer Check setup. It reads actual installed/version evidence, returns an existing unfinished review, explains missing-model waits and requires Recheck for expired approval. It never authorizes, replays or enqueues a command. Reconnecting/selecting the conversation's model and sending a message resumes its existing handoff.
  • Validation: 1,622 Python tests passed across 47 files, zero failures, one Linux-only skip on macOS. After adding default-agent/no-model worker cases, 95 focused tests passed. Coverage includes repeated missing-model waits with zero attempts, re-created mediator resumption, real approved setup/verification, paused/expired control access, foreign-actor refusal and old-version invalidation. Ruff and diff checks pass. No frontend build or live-platform UAT was run for this checkpoint.
  • Prior-head CI 34339674517 completed with code/test jobs passing. Only the maintainer review-label gate and aggregate failed; Desktop E2E was skipped. No gate was bypassed. New-head CI remains pending.
  • Next discovered gap: Desktop mediation still uses generic update controls for setup. Full canonical guidance/command display, setup-specific confirmations and progress/recovery controls are required before Desktop setup is complete. Credential/prerequisite guidance, supported remote execution contexts, automatic-update handoff and live cross-surface restart/setup UAT also remain open.
  • The live demo is unchanged. All four demo live acceptance gates and broader cross-repository requirements below remain open.

Fixed-copy setup scheduling checkpoint (September 9)

Earlier fixed-copy checkpoint: 0809c2bbce3c5d1f7045fa8ef770294cbf7317c3. Its remaining-work notes are historical where the latest checkpoint explicitly supersedes them.

  • Fixed notification copy no longer disables explicit install/update/setup continuation. The existing private idle workers claim only user-requested work in fixed mode; unsolicited backlog consumes no model attempts. Notification sender behavior, owner/session guards, separate native approval and receipt-backed delivery remain intact.
  • The native inbox and Desktop/Dashboard retain requested reviews in fixed mode. Inspection/presentation tools remain enabled with Wisdom; there is still no model-facing confirmation or execution bypass. A copy-mode change is checked again before sending unsolicited advice.
  • Validation: 1,613 Python tests across 47 files passed, zero failures, one Linux-only skip on macOS. Includes all 642 TUI server tests, real managed installation/update and approved setup/verification in both modes, real-ledger Telegram/Slack/local worker delivery, mode-change fencing and untouched unsolicited backlog. Desktop mediation: eight tests; Dashboard activity: three tests. Ruff, diff checks and targeted frontend lint pass, with one existing lint warning in each frontend. No full frontend build/typecheck or live platform UAT was run for this checkpoint.
  • Previous-head CI 34337858459 completed with all code/test jobs passing. The maintainer review-label gate and its aggregate failed; neither was bypassed. New-head CI is pending.
  • Still open: no-active-model scheduling/recovery, credential/prerequisite UX, remote execution contexts, automatic-update handoff, live cross-surface setup/restart UAT and the broader lifecycle/privacy/delivery requirements below. All four demo findings retain their live acceptance gates. The serving demo remains untouched.

Guided setup handoff checkpoint (September 9)

Earlier guided-handoff head: a4efb1514a4504d628c7d3e66676b5a1df2f60b7. Historical remaining-work notes below are superseded only where explicitly addressed by the latest checkpoint.

  • Native Install/Update and successful setup steps atomically queue continuation for the same private session. In agent delivery mode, the existing idle-session worker uses that session's model to propose one declared prerequisite, setup command or verification step at a time. No proposal executes without native confirmation and terminal permission.
  • Handoffs inspect exact installed bytes and canonical guidance, minimize model evidence, validate structured output and recheck lease, package, session address and competing consent. Missing guidance, unsafe/unspecified commands and uncertain execution stop progression. Not Now does not reproduce a review.
  • Receipts now say Files installed/updated, not ready. Setup cards retain the explanation and full exact command when reopened. Readiness requires the approved verification result and prerequisites; an update invalidates prior readiness and queued readiness notices are checked again before delivery.
  • Validation: 949 tests passed across 46 files, zero failures, one Linux-only skip on macOS. Final focused run after explanation rendering: 120 passed. The handoff cases exercise real managed install/update, native approvals, real local commands, persisted restart continuation, deferral, changed packages/addresses, competing controls, secret rejection and expired leases.
  • Prior-head CI run 34336208974 exposed two test preconditions: an optional Telegram SDK and the fixed-copy opt-out branch. Those are explicit now; both affected files passed locally (700 tests, with the SDK installed). New-head/minimal-SDK CI remains pending. The separate maintainer review-label gate has not been bypassed.
  • Still open: fixed-copy/no-active-model setup scheduling, richer credential/prerequisite guidance, supported remote execution contexts, automatic-update handoff, live cross-surface setup/restart UAT and the broader integration gates below. The serving demo remains unchanged.

Native setup and demo-fix checkpoint (September 9)

Earlier recovery checkpoint: 4831fe5a4f928a2b5b47ed63391403c79261f9cd. This is an implementation checkpoint, not rollout approval.

  • Agent-generated card copy is the default, with fixed copy retained as an explicit opt-out. Private browse offers native install review, and explicit access after Not Now creates a fresh install control without resuming unsolicited reminders. Delivery wording distinguishes queued work from an accepted provider receipt.
  • Installed setup inspection reads canonical installed guidance and exact package/version evidence. Each prerequisite, setup command and verification step requires separate native approval. Existing terminal permissions remain enforced, credentials are never requested in chat, and no remote sandbox is silently replaced with host execution.
  • Durable execution records distinguish starting, running, completed and unknown outcomes. Duplicate confirmations never replay commands; only actual process completion supplies an exit result. Required steps and prerequisites precede verification, and updates invalidate prior readiness.
  • Native Review interruption allows an owner to explicitly acknowledge stopped commands and checked side effects before clearing an uncertain attempt. Known-running work cannot be cleared. Recheck opens fresh approval without executing. Startup/recovery locking and atomic state updates prevent expired leases or late responses from bypassing that decision.
  • Current validation: 939 Python tests passed across 46 files, zero failures, one Linux-only skip on macOS. The focused recovery/lock/guide run passed 34 tests. Tests exercise real temporary managed installations, native callbacks, local processes, permission denial, unknown results, startup races and cross-process lock release. Ruff and diff checks passed.
  • Still open: automatic Install/Update setup handoff, credential/prerequisite UX, supported remote execution contexts, full setup/restart UAT and the remaining cross-repository lifecycle/privacy/delivery requirements. The four demo findings retain live acceptance gates; the numeric-input fix is in the companion Portal change, not this PR.
  • The serving demo was not restarted or changed. New-head CI is pending; earlier suite counts below are historical and do not establish current live acceptance.

Current integration checkpoint (September 9)

Earlier copy-integration checkpoint: cab214e277bbea9e2a5a7b9e25ab92934b43c2e5. Upstream reconciliation is committed at 5de466f376; all 22 conflicts were resolved while preserving upstream router, runner, TUI and sender ownership boundaries.

  • Native exact-package consent, durable delivery receipts and client-reported operation outboxes remain wired. Telegram command-policy checks remain fail-closed for primary routed and secondary multiplex profiles.
  • Desktop/Dashboard local review supports one exact-package confirmation for open publication or moderated submission. Full manual UAT for those two surfaces remains deferred.
  • Merge validation: 1,975 Python tests across 65 affected files, 150 Desktop tests, 44 Dashboard tests, both frontend typechecks, Ruff and compatibility-pointer audit passed.
  • Contract follow-up: pins Gateway 60cd2d6b613ae3cd4a6e65155d1142006d907e78. The three producer artifacts are byte-identical across Gateway, Agent and Portal. All content hash vectors, including Unicode ordering, are verified; 186 focused Agent tests passed.
  • The earlier 28-driver connector E2E result was against 17c7812788, not this new head. No real platform messages, publications, demo restarts or database mutations were performed during reconciliation.
  • Remaining gates include guided setup, cross-client privacy/preferences/recovery, lifecycle/email completion and live two-member acceptance. Affected older Unicode-hash drafts need re-review; previously stored versions require compatibility/recovery review before deployment. Rollout remains incomplete.

September 9 CI follow-up

  • Fixed six shared/Desktop lint errors after reconciliation.
  • Preserved historical CLI dispatch coverage while allowing new convention handlers; added a behavioral Wisdom dispatch regression.
  • Split raw/envelope and optional Telegram SDK receipt cases so minimal installations retain receipt coverage. The real SDK case passed locally.
  • Validation: 38 Python tests, six Desktop mediation tests, shared typecheck/lint, full Desktop typecheck/lint and focused Ruff passed. Desktop lint retains 146 warnings and zero errors.
  • The three files named in the product-owner handoff pass on this base: 48 tests. Fork PR Architecture planning #3 was subsequently integrated as described below.
  • Remote CI for this new head is still required. The maintainer ci-reviewed label gate has not been bypassed.

Product-owner copy integration

Fork PR #3 at 1ec627710 is integrated with its contributor commits preserved. Copy was ported to the upstream-extracted Telegram/Slack Wisdom mixins.

  • Reviewed labels, organization spelling, common card titles and final-position share questions are integrated. The three undecided product choices remain unchanged.
  • Fixed regressions found during review: completed/deferred cards no longer ask to share again; native and fixed professionalism projections now agree while preserving Show/Hide checks and separate security status.
  • Editorial guidance remains evidence-grounded, with no pressure or invented benefit.
  • Validation: 820 Python tests across 37 files passed, plus 48 focused tests after the last projection adjustment; 13 Desktop candidate/mediation tests passed; full Dashboard checks passed 331 tests plus typecheck/lint. Full Desktop typecheck/lint and focused Ruff passed. Existing lint warnings remain (Desktop 146, Dashboard 28).
  • Five regression assertions were demonstrated failing before the integration fixes. No live platform messages or demo restarts were used for this verification. New-head remote CI is still required.

Original V1 scope

This is the Agent-side implementation of Hermes Collective Wisdom V1. It delivers the local contribution and managed-consumption loop: private candidate qualification, owner-reviewed publication, explicit installation, compatibility checks, updates, notifications, uninstall, CLI, Dashboard, Desktop, Telegram, and Slack workflows.

Rollout remains disabled until the reconciled Gateway and Portal heads are deployed, live cross-repository tenant-isolation UAT is recorded, implementation screenshots are captured against that stack, and product-owner dogfood sign-off is recorded.

Privacy and qualification

  • Uses a profile-scoped wisdom/wisdom.db with restrictive database/WAL/SHM permissions, transactional migrations, stable local identities, source snapshots, candidate state, hash-bound review receipts, installations, and crash-recovery journals.
  • Keeps usage, refinement, stability, ranking, dismissal, candidate, and capability-inventory data local; explicit setup is the disclosure and organization-activation boundary.
  • Qualifies bounded on-device usage, meaningful refinements, and stable local skills without mutating prompt history or cache state.
  • Generates optional human-readable editorial metadata for qualified legacy skills without rewriting user-owned source files. Generated copy is stored with the local candidate and applied only to the owner-visible contribution overlay.
  • Runs a durable, tool-free, hash-bound professionalism review through auxiliary.background_review; failures become advisory unavailable results and never strand the contribution flow.

Consent-bound publication

  • Prepares strict instruction-only packages: one root SKILL.md, one root skill.manifest.json, and narrowly allowlisted inert UTF-8 support text.
  • Rejects scripts, executables, active templates, binaries, symlinks/hardlinks, package-manager manifests, hostile paths, collisions, oversized content, malformed UTF-8, and markdown references to excluded active content.
  • Uploads only the private review package, reconstructs the full authoritative closure, and binds consent to content, author-description, package-manifest, and server-revision hashes.
  • Revalidates those four bindings before every approval/publication resume path; stale receipts cannot be consumed or published.
  • Renders deterministic Security checks separately from advisory, model-assessed Professionalism checks across private surfaces; public notifications receive aggregate statuses only.

Managed consumption

  • Installs into a dedicated _wisdom/<org-id>/<slug> namespace with exact-byte staging and canonical content verification.
  • Plans and applies against fresh Gateway authority, immutable bytes, current local scans, and current compatibility.
  • Supports manual, auto-with-notice, and required modes. No automatic mode, including REQUIRED, applies when either local scanner reports any finding.
  • Preserves modified required-update bytes as an unmanaged fork, performs atomic managed-directory replacement, reconciles ledgers, and recovers interrupted operations.
  • Validates install, fork, uninstall, and trash paths against their managed roots.
  • Keeps Telegram and Slack public homes limited to collective publication notices and Portal links; device-local install/update state and mutation controls remain DM-only.

Interfaces

  • CLI: hermes wisdom setup|status|scan|suggest|candidates|review|approve|decline|list|show|install|versions|check|update|uninstall
  • Stable human and --json output plus documented exit categories.
  • Dashboard and Desktop discovery, candidate review, contribution, version, installation, update, uninstall, compatibility, and notification surfaces.
  • Telegram and Slack qualification, review, publication, preview, version, install, and navigation cards.
  • One profile-scoped FastAPI boundary; renderers never receive Gateway credentials or its base URL.

Review follow-up

Addressed from the review at head c252b4e8:

  • A-1: REQUIRED no longer bypasses scanner findings in either planning or execution.
  • A-2: automatic editorial enrichment no longer writes to the canonical SKILL.md; generated fields remain local until copied into the explicit owner-review overlay.
  • A-3: SQLite database, WAL, and SHM files are normalized to 0600 while the profile Wisdom directory remains 0700.
  • A-4: owner and candidate publication-resume paths share the same four-way receipt validation as direct approval.
  • A-5: public Telegram delivery now matches Slack's public-safe filtering and excludes mutation controls.
  • A-8/A-9: markdown-link reference boundaries and fork/uninstall recovery path containment are hardened.
  • N-1: professionalism review timestamps now use the Gateway's canonical JavaScript ISO form (YYYY-MM-DDTHH:mm:ss.sssZ) for both successful and unavailable results.

Left explicit for follow-up rather than changing product semantics in this review pass:

  • A-6: whether non-SKILL.md support-file changes alone should count as a meaningful refinement.
  • A-7: the residual source-copy TOCTOU window beyond the existing before/after source fingerprint check.

Contract and rollout order

The current contract is pinned to:

Merge/deploy order: finalize Gateway PR #255 and the remaining integration, refresh both consumer contracts from the final Gateway commit, then deploy Gateway and Portal before enabling this Agent head. The consumers now align with the producer commit above. Re-pin if further Gateway changes alter the contract; coordinated deployment and remaining live acceptance gates are not complete.

Historical V1 validation

These results describe the earlier V1 checkpoint, not a fresh full-suite run on the current head.

  • merged upstream main at 593aa74c6182ce2e5e23bc102daaaae71710c05d
  • pytest tests/wisdom -q: 199 passed
  • focused post-merge Gateway routing tests: 6 passed
  • scripts/verify_wisdom_contract.py: passed with the pinned commit and digest
  • Ruff on all touched Python modules/tests: passed
  • Web typecheck: passed
  • Desktop renderer, Electron, and E2E typechecks: passed
  • git diff --check: passed

Original V1 checkpoint head: ff8efcb29766de5614ba758684465b3e3c2c8828. Current head is listed above.

September 10: Legacy Install Controls Require Fresh Review

Agent ac4f427cf3 replaces immediate apply from unversioned Telegram/Slack install/update buttons with the shared exact-package review and a separate scoped confirmation. Receipt-only legacy confirmations offer current browse navigation without reading or applying their receipt. Callbacks bind user, profile, organization, chat, thread and Slack workspace; explicit DM continuation may change conversation but not workspace authority.

Agent fc5e72374f also fixes approval lifetime: Show/Hide checks cannot renew the underlying review. Even a still-valid transport token cannot approve after the original deadline. Expired projections offer Recheck, which refreshes plan/check evidence without applying and requires a new confirmation. Install refresh preserves the selected version and update mode.

Validation: four clock-controlled cases fail against the pre-fix controller and pass with the fix. Actual adapter/WisdomService/SQLite/staging/file tests prove no write on expired confirmation, no apply on Recheck, no cross-user/thread/workspace confirmation, no silent latest-version substitution, and no duplicate installation record on repeated success. The 58-file suite passes 1,289 tests (one Linux-only skip), with all 74 command tests passing after the policy-preservation addition; Ruff and whitespace pass.

Functional CI for ac4f427cf3 passed. Its required maintainer ci-reviewed label and aggregate gate remain red; no gate was bypassed. New-head CI for fc5e72374f is independent and pending. Live acceptance, runtime adoption and remaining native-command migration are still open. The running demo is unchanged.

September 10: Native Install Policy Prerequisite

Agent 8ebddcc37a preserves explicit future-update policy choices through durable native review, expiry/Recheck and exact install application. A changed choice requires a new pending approval; in-flight/uncertain delivery is not replaced. Compact and expanded native cards show the selected policy. This prepares command-to-native migration; that wiring and live acceptance remain open.

Validation: 1,301 tests passed across 59 files, one Linux-only skip; 77 changed-path tests passed after final text alignment; Ruff and whitespace checks passed. New cases exercise real WisdomService, SQLite and managed files with fixture registry/scan/bootstrap. Previous fc5e72374f functional CI passed but the maintainer ci-reviewed gate remains outstanding. New-head CI is separate. Demo and email enablement are unchanged.

September 10: Native Card Edit Outcomes

Agent a476df3e80 reports failed Telegram card edits instead of swallowing them; only definite rich-format rejection falls back, and an already-current message is successful. Slack reports an unusable edit address rather than returning success. Both native adapters are tested with real WisdomService/SQLite/file installation: a failed edit followed by the same confirmation retry updates saved completion without a second install or a new card. Provider and registry transports are fixtures.

Validation: 1,308 tests passed across 59 files, one Linux-only skip; Ruff and whitespace checks passed. Previous 8ebddcc37a functional CI passed; the maintainer review-label gate remains outstanding. New-head CI is separate. Command-to-native migration, live acceptance, and demo adoption remain open; the demo was not changed.


Model: OpenAI Codex
Harness: Codex desktop

@shannonsands
shannonsands force-pushed the codex/hermes-wisdom-consumption branch 2 times, most recently from 20f9db1 to daeb6f1 Compare August 24, 2026 22:53
@alt-glitch alt-glitch added type/feature New feature or request P3 Low — cosmetic, nice to have comp/agent Core agent runtime: loop, agent_init, prompt builder, context-compression, responses endpoint comp/cli CLI entry point, hermes_cli/, setup wizard comp/desktop Electron desktop app (apps/desktop/*) comp/dashboard Web dashboard / control panel UI (dashboard/, landing) tool/skills Skills system (list, view, manage) area/config Config system, migrations, profiles needs-decision Awaiting maintainer decision before any implementation sweeper:risk-compatibility Sweeper risk: may break existing users, config, migrations, defaults, or upgrades labels Aug 24, 2026
@shannonsands shannonsands changed the title feat(wisdom): add managed consumption workflows feat(wisdom): add Hermes Wisdom Agent V1 Aug 24, 2026
@shannonsands
shannonsands force-pushed the codex/hermes-wisdom-consumption branch from daeb6f1 to 74f4268 Compare August 25, 2026 04:16
@shannonsands shannonsands changed the title feat(wisdom): add Hermes Wisdom Agent V1 feat(wisdom): add Hermes Collective Wisdom Agent V1 Aug 25, 2026
@shannonsands
shannonsands force-pushed the codex/hermes-wisdom-consumption branch from 74f4268 to 77d7563 Compare August 25, 2026 04:22
@shannonsands
shannonsands force-pushed the codex/hermes-wisdom-consumption branch 4 times, most recently from 0b91d98 to de04ed6 Compare August 25, 2026 05:33
@shannonsands
shannonsands force-pushed the codex/hermes-wisdom-consumption branch from de04ed6 to 65d3f10 Compare August 25, 2026 05:35
@shannonsands
shannonsands requested a review from a team September 11, 2026 00:07
@shannonsands

Copy link
Copy Markdown
Author

Contract follow-up pushed at fe6e247. No new Agent review findings were present. Gateway review fixes are now consumed consistently: Agent and Portal #1022 both pin 16bd05e81b134d1ab8bb230aade6f6de9010cae3 with OpenAPI digest b46f0db55befbb682a392fc0c1015ed0a9a81e02d5ad9337c29347802972937d. Manifest/vectors are unchanged; the user-facing-only delivery/subagent guard remains intact.

Six contract tests and the contract verifier pass. All three cross-repo release smoke drivers pass against real Postgres/MinIO, including worker/SQLite recovery and moderated publication. No runtime/demo restart was performed.

@shannonsands

Copy link
Copy Markdown
Author

Review follow-up pushed at 8dd35a5.

Blank Slate regression fixed in ac0b088. The minimal setup now derives disabled-bundle exclusions from resolved tool overlap, so wisdom_consent cannot subtract present_wisdom_consent from the retained skills bundle. The existing no-overlap invariant remains unchanged. Added a model-tool-definition check demonstrating consent survives when Wisdom is available; the ordinary unconfigured minimal surface is still covered.

The two anonymous-auth failures are baseline-attributed and fixed. CI tested merge c6a2453 against main 45a6101. Both failures reproduce on that unmodified main in an isolated worktree:

  • TestTokenAcquisitionSeam::test_tool_gateway_token_path_reexchanges
  • TestConnectorTokenPath::test_connector_path_replaces_a_dead_credential_once

Upstream 173105c changed _RESOLVE_TOKEN_CACHE from a nullable single slot to a per-profile dictionary, but this fixture still assigned None. Merged main 45a6101 without conflicts in 089b89b, preserving contributor history, then corrected the fixture to an empty dictionary in 8dd35a5. No production auth workaround or weakening of the profile isolation was added.

Validation: canonical scripts/run_tests.sh, fresh HOME/HERMES_HOME, retries disabled: 219 passed across Blank Slate, anonymous auth, token memo, staging allowlist, Wisdom mediation/store and Gateway mediation. This includes delegated/background-session rejection tests. Ruff and git diff --check pass. Full Linux CI must rerun on this head; the existing ci-reviewed label gate remains maintainer-owned.

The inherited Privy ready-timeout weakness is retained as a separate non-blocking follow-up, not folded back into this Wisdom PR. Gateway/Portal heads, rollout flags and the running demo were not changed.

@benbarclay benbarclay left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approving as hermes-agent-core reviewer for the pyproject.toml / web/package.json / package-lock.json touches (setuptools include for hermes_wisdom + contracts package-data; @testing-library/react devDependency). CI green on 0924f79; blank-slate and anon-auth failures verified fixed locally.

@benbarclay
benbarclay merged commit a6ee31f into NousResearch:main Sep 11, 2026
37 checks passed
teknium1 added a commit that referenced this pull request Sep 11, 2026
Reverts the in-tree org skill-marketplace: hermes_wisdom package, three
model tools, CLI/gateway/desktop/dashboard/Telegram/Slack surfaces.

Later non-Wisdom work on shared files (guest onboarding i18n, dashboard
startup schema, Slack adapter, tui_gateway) is kept; Wisdom-only call
sites and config were stripped from those files.
teknium1 added a commit that referenced this pull request Sep 11, 2026
Reverts the in-tree org skill-marketplace: hermes_wisdom package, three
model tools, CLI/gateway/desktop/dashboard/Telegram/Slack surfaces.

Later non-Wisdom work on shared files (guest onboarding i18n, dashboard
startup schema, Slack adapter, tui_gateway) is kept; Wisdom-only call
sites and config were stripped from those files.
x-Ai added a commit to x-Ai/hermes-agent that referenced this pull request Sep 12, 2026
teknium1 added a commit that referenced this pull request Sep 17, 2026
#94266 shipped Collective Wisdom as an 80k-line in-tree feature spanning a
core package, three model tools, CLI/gateway/TUI/dashboard/desktop surfaces
and Telegram/Slack adapters; #108507 deleted it. This brings the capability
back at the footprint it should have had: one bundled plugin under
plugins/wisdom/ with zero core edits.

- package.py: the Gateway's instruction-only contract (allowed paths, size
  caps, canonical content-manifest + author-description hashing, manifest
  schema v1). Byte-exact against the Gateway's published hash vectors.
- client.py: /v1/sync/wisdom/ over the shared Nous sync identity; every
  downloaded blob and the whole package are hash-verified before use.
- service.py: browse / show / status / install / update / uninstall /
  share, each mutation behind a caller-supplied confirm() so nothing is
  applied without a human seeing the exact version, hashes and Gateway
  verdicts. Installs live under skills/_wisdom/<org>/<slug>/ and are
  indexed like any other skill.
- __init__.py: tools wisdom_browse / wisdom_install / wisdom_share (visible
  only when the Nous token carries wisdom:* scopes), the /wisdom slash
  command and `hermes wisdom` CLI. Model-tool consent rides the same human
  approval gate as dangerous shell commands (fail-closed when unattended).

Dropped on purpose: proactive advice queues, delivery leases, weekly agent
review, Telegram/Slack card adapters, Desktop/dashboard panels, the 13k-line
vendored OpenAPI document and the demo stack. Those are product surface for a
later plugin iteration, not core.
teknium1 added a commit that referenced this pull request Sep 17, 2026
#94266 shipped Collective Wisdom as an 80k-line in-tree feature spanning a
core package, three model tools, CLI/gateway/TUI/dashboard/desktop surfaces
and Telegram/Slack adapters; #108507 deleted it. This brings the capability
back at the footprint it should have had: one bundled plugin under
plugins/wisdom/ with zero core edits.

- package.py: the Gateway's instruction-only contract (allowed paths, size
  caps, canonical content-manifest + author-description hashing, manifest
  schema v1). Byte-exact against the Gateway's published hash vectors.
- client.py: /v1/sync/wisdom/ over the shared Nous sync identity; every
  downloaded blob and the whole package are hash-verified before use.
- service.py: browse / show / status / install / update / uninstall /
  share, each mutation behind a caller-supplied confirm() so nothing is
  applied without a human seeing the exact version, hashes and Gateway
  verdicts. Installs live under skills/_wisdom/<org>/<slug>/ and are
  indexed like any other skill.
- __init__.py: tools wisdom_browse / wisdom_install / wisdom_share (visible
  only when the Nous token carries wisdom:* scopes), the /wisdom slash
  command and `hermes wisdom` CLI. Model-tool consent rides the same human
  approval gate as dangerous shell commands (fail-closed when unattended).

Dropped on purpose: proactive advice queues, delivery leases, weekly agent
review, Telegram/Slack card adapters, Desktop/dashboard panels, the 13k-line
vendored OpenAPI document and the demo stack. Those are product surface for a
later plugin iteration, not core.
RMK-Studio-90 added a commit to RMK-Studio-90/hermes-agent that referenced this pull request Sep 18, 2026
3-way merge (base ad03f20) of upstream release 0.21.2 (939e45c)
into the RMK integration baseline (4bded63). 0 conflicts.

- upstream 64 commits: wisdom-v1 removal (NousResearch#94266), relay/turn_author
  metadata, deepseek-flash vision metadata, desktop/UI fixes
- RMK 25 commits preserved: adaptive smart routing, graph engine,
  background-review, docker atexit drain
- agent/routing/*, turn_context, turn_usage, turn_api_error and
  chat_completion_helpers are untouched by upstream in this window:
  the verified routing repair survives the merge unchanged.
- state.db / SessionDB core untouched by upstream in this window.

Next: verify routing suites, run_agent baseline, targeted DB/gateway/
desktop tests against this merge, then live provider smoke.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/config Config system, migrations, profiles comp/agent Core agent runtime: loop, agent_init, prompt builder, context-compression, responses endpoint comp/cli CLI entry point, hermes_cli/, setup wizard comp/dashboard Web dashboard / control panel UI (dashboard/, landing) comp/desktop Electron desktop app (apps/desktop/*) needs-decision Awaiting maintainer decision before any implementation P3 Low — cosmetic, nice to have sweeper:risk-compatibility Sweeper risk: may break existing users, config, migrations, defaults, or upgrades tool/skills Skills system (list, view, manage) type/feature New feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants