From 40989563ec2b701ec6fa9a5131b913105e953927 Mon Sep 17 00:00:00 2001 From: teknium1 <127238744+teknium1@users.noreply.github.com> Date: Sat, 26 Sep 2026 11:20:59 -0700 Subject: [PATCH] chore(plugin-catalog): review disclosure for hermes-town --- plugin-catalog/hermes-town.yaml | 11 ++++++++++- 1 file changed, 10 insertions(+), 1 deletion(-) diff --git a/plugin-catalog/hermes-town.yaml b/plugin-catalog/hermes-town.yaml index c898e95c10..597227f4db 100644 --- a/plugin-catalog/hermes-town.yaml +++ b/plugin-catalog/hermes-town.yaml @@ -2,7 +2,16 @@ name: hermes-town repo: https://github.com/sxuff/hermes-town sha: f3b89401fafde0cd3ebaaccf01ea9e658bc66ff9 subdir: integrations/hermes-town-plugin -description: Local pixel-art town where every Hermes session is a resident and every tool call walks to a building. Passive lifecycle bridge to a loopback-only server; prompts, arguments, and output never leave the process. +description: >- + Local pixel-art town where every Hermes session is a resident and every tool call walks to a + building. Passive lifecycle bridge to a loopback-only server; prompts, arguments, and output never + leave the process. Disclosure — version 0.3.0 bundles the Town Node server and a prebuilt browser + app inside the plugin directory and adds a hermes town setup/start/status/stop/open command tree. + Nothing is downloaded and no npm install runs at any point; node (^20.19 or >=22.12) must already be + installed and is launched only by the explicit hermes town start command, bound to 127.0.0.1 only. + Runtime state, a 0600 bridge token, a bounded event journal and rotated server logs are written + under HERMES_HOME/hermes-town/runtime/. On start the server also reads HERMES_HOME/cron/jobs.json + (job id and enabled flag only) to place one resident per enabled scheduled job. maintainer: sxuff tier: community category: tools