Skip to content

fix(hermes): bound and frame injected memory as JSON evidence - #9

Draft
carlosrve wants to merge 1 commit into
integration/memory-20261006from
fix/hermes-memory-context-framing-20261008
Draft

carlosrve wants to merge 1 commit into
integration/memory-20261006from
fix/hermes-memory-context-framing-20261008

Conversation

@carlosrve

@carlosrve carlosrve commented Oct 9, 2026 •

Copy link
Copy Markdown
Owner

Automatically injected recall/reflect text is currently raw text under an instruction-like preamble. Frame that evidence with a fixed JSON shape, escape wrapper/fence characters inside its strings, and bound the encoded block to 16,000 characters without breaking JSON. The default preamble identifies the block as untrusted evidence; an explicitly configured recall_prompt_preamble still wins. Manual tool-result formatting is unchanged.

Related existing public report: vectorize-io#5424; prior reference implementation vectorize-io#4676 by @yingliang-zhang. This is defense in depth, not a claim of model-level protection or a new vulnerability disclosure. The maintained fork carries the feature under upstream's external-PR policy.

Validation: four deterministic cases cover escaped wrappers/fences, Unicode round trips, valid bounded JSON for escape-heavy input and custom-preamble preservation. This branch passed 70 provider tests (two host probes skipped without host settings); the combined candidate passed all 81. Full repository lint passed on the combined candidate. Exact-head fork CI remains required.

A separate hs_llm_core test uses the actual shared formatter/preamble, a real answer model and the existing independent LLM judge. It has NOT been executed in this credential-free rehearsal: structural tests do not demonstrate that any particular model follows the boundary. Semantic acceptance remains a separate gate before adoption.

Base: integration/memory-20261006 at e211b2b. No deployment, bank changes or paid model calls.

Exact-head CI update: all eight Memory fork CI jobs passed in run 37880535713. This remains draft until the opt-in real-LLM/independent-judge acceptance test is executed and documented. No credentials were used for CI.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant