Skip to content

fix(security-guidance): declare hooks in plugin manifest - #97765

Closed
tachyon-r wants to merge 2 commits into
NousResearch:mainfrom
tachyon-r:fix/security-guidance-hook-manifest
Closed

tachyon-r wants to merge 2 commits into
NousResearch:mainfrom
tachyon-r:fix/security-guidance-hook-manifest

Conversation

@tachyon-r

@tachyon-r tachyon-r commented Aug 29, 2026 •

Copy link
Copy Markdown

Summary

  • replace the unused hooks manifest field with provides_hooks
  • verify manifest declarations match the hooks registered by the plugin
  • make the touched discovery test's config write explicitly UTF-8

Verification

  • 26 focused plugin and manifest-validation tests passed
  • Ruff, Windows-footgun, and diff checks passed
  • current Windows CI failure is in an unrelated desktop-update progress test

@tachyon-r

Copy link
Copy Markdown
Author

CI note: the only failing leaf check is the unrelated Windows timing test tests/test_desktop_update_windows_progress.py::test_progress_advances_while_the_orchestrator_blocks (/progress unresponsive until deadline). Full Python tests, lint/typing, e2e, macOS, Nix, OSV, and both Docker builds passed. I attempted to rerun failed jobs, but GitHub requires repository admin rights for reruns on this fork PR.

Failing job: https://github.com/NousResearch/hermes-agent/actions/runs/33242270456/job/99073528077

@alt-glitch alt-glitch added type/bug Something isn't working comp/plugins Plugin system and bundled plugins P3 Low — cosmetic, nice to have labels Aug 29, 2026
@tachyon-r
tachyon-r force-pushed the fix/security-guidance-hook-manifest branch from d3dfe29 to 6440b3b Compare August 30, 2026 17:38
@tachyon-r tachyon-r changed the title fix: declare security-guidance hooks in manifest fix(security-guidance): declare hooks in plugin manifest Aug 30, 2026
@tachyon-r
tachyon-r force-pushed the fix/security-guidance-hook-manifest branch 6 times, most recently from 028407b to 5ed2374 Compare September 6, 2026 09:36
@tachyon-r
tachyon-r force-pushed the fix/security-guidance-hook-manifest branch from bde9db8 to 467cad7 Compare September 11, 2026 00:18
chelsealong added a commit to chelsealong/hermes-agent that referenced this pull request Sep 11, 2026
…ct prior claim

The previous commit stated this was "the same fix already applied to
security-guidance in NousResearch#97765." That was false: security-guidance/plugin.yaml
has used the legacy `hooks:` key since it was added in NousResearch#33131 and was never
touched by NousResearch#97765. It has the identical undeclared-hooks bug fixed elsewhere
in this PR — register() calls ctx.register_hook() for pre_tool_call and
transform_tool_result directly, so it qualifies under this PR's own
criterion for inclusion, and validate_plugin_dir() confirms the same
"undeclared hooks registered (not in provides_hooks)" failure.

Rename its hooks: key to provides_hooks: and add it to the parametrized
admission-check test so it's covered alongside the other three plugins.
@teknium1

Copy link
Copy Markdown
Collaborator

Thanks @tachyon-r — both commits cherry-picked as-is; together with #108386 this resolves #108371.

Salvaged into #118841 with your authorship preserved (merge 74f726c). Thank you!

@teknium1 teknium1 closed this Sep 22, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

comp/plugins Plugin system and bundled plugins P3 Low — cosmetic, nice to have type/bug Something isn't working

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants