7 Commits

Author SHA1 Message Date
yubingz
7de3148b3c chore(catalog): bump desensitize pin to 2dbf63d (help follows /desensitize lang)
2dbf63d 增加了四项语言相关的修正,都是「命令看起来没生效」的成因:

- help 在用户显式 /desensitize lang <x> 之后跟随该语言(未表态时仍用 help_language)
- lang 接受本地写法别名(cn / 中文 / english / 双语)
- 未知子命令先报一行带近似建议的提示,再给用法块(原先静默打印用法)
- lang <非法值> 保持原值而非回落 both

同时修好 tests/test_behavior_parity.py(改为加载仓库内夹具,此前因安装目录改为包布局
而必然 ModuleNotFoundError),并把 test_ui_language.py 同步到新契约。

版本随之 1.3.0 → 1.4.0。
2026-09-27 12:30:36 -07:00
yubingz
4698b3ad64 chore(catalog): bump desensitize pin to bea37d3 (install/upgrade docs)
Advances the pin from 8dc7c75 to bea37d3. Adds an upgrade section to the
README: replace the plugin directory wholesale, keep backups OUTSIDE
~/.hermes/plugins/ (a sibling directory with a plugin.yaml is loaded as a
second plugin under the same name, which made /desensitize lang look like
it had no effect while the loaded copy was an old one), and a snippet to
print the loaded plugin key/version when a change seems not to apply.
2026-09-27 12:30:36 -07:00
yubingz
336692fd7d chore(catalog): bump desensitize pin to 8dc7c75 (lang subcommand, English help)
Advances the pin from 6385779 to 8dc7c75 and the catalog version to 1.3.0.

Adds an in-session language switch and splits help onto its own language:

  /desensitize lang en|zh|both    switch output language (this session only)
  ui.help_language                help language, default en

Help no longer follows ui.language. Help is what a user reads when they do
not yet know the plugin, so its default is the one readable by everyone, and
`ui.language: zh` no longer hides it from a non-Chinese reader. Setting
help_language to zh or both restores the previous behavior.

`lang` deliberately does not persist: language is a session preference, and
writing it to disk leaves a surprise behind on the next terminal or locale.

Validator: OK: 1 file(s) valid
2026-09-27 12:30:36 -07:00
yubingz
dfec0f9349 chore(catalog): bump desensitize pin to 6385779 (configurable output language)
Follows the pin forward from acd1263 to 6385779 and the version to 1.2.0.

Beyond the bilingual feedback already in acd1263, the command output language
is now a config option rather than a hardcoded choice: `ui.language` accepts
`both` (English + Chinese, English first — default), `en` (English only), or
`zh` (Chinese only), settable in ~/.hermes/desensitize.yaml or via
DESENSITIZE_UI__LANGUAGE. An unrecognized value warns and falls back to both.

Hardcoding `both` left an international user with English interleaved with
Chinese and no way to turn the Chinese off; `en` is for the reader who cannot
read Chinese at all. The default stays `both` because the plugin targets
Chinese-language conversation, so both drops no reader.

Validator: OK: 1 file(s) valid
2026-09-27 12:30:36 -07:00
yubingz
c80f1ffc4b chore(catalog): bump desensitize pin to acd1263 (bilingual command output)
Advances the pin from 9684e1b to acd1263 and the catalog version to 1.1.0.

The plugin's /desensitize feedback is now bilingual with English first: the
on/off/model/timeout/chunk confirmations, the status field labels, the error
strings, and the model sub-command usage all carry an English default, matching
the usage block that was already bilingual. Command output is the only surface
a non-Chinese reader sees, so Chinese-only replies made that path unreadable
for them.

Requested in review of #122574 (plugin.py:975-1035, 1049-1063).
2026-09-27 12:30:36 -07:00
yubingz
214b0d1c7a chore(catalog): bump desensitize pin to 5e41d29
Addresses review items on
NousResearch/hermes-agent#118727:

- Declares runtime deps in the plugin manifest (jieba, PyYAML) so the
  catalog capability probe passes; the deps previously lived only in the
  repo-root pyproject.toml, which the loader does not read for a subdir
  plugin.
- English defaults for the command description; status/help are bilingual.
- Discloses the semantic layer's egress: pre-redaction text goes to the
  configured LLM, and provider=openai without base_url falls back to
  api.siliconflow.cn (remote). Default provider=ollama stays local.
- Status output now prints the resolved endpoint instead of a hardcoded
  label, plus an Egress line.
2026-09-26 11:42:24 -07:00
yubingz
941ffdcca6 feat(plugin-catalog): add desensitize (community, tools)
Chinese-context PII redaction. Adds one catalog entry pinning
yubingz/hermes-desensitize at 8ef2d22.

The gap this fills: the catalog has secret redaction (vaultknox: API keys,
tokens, passwords — a 28-pattern English key-format registry) and, as open
proposals, English/Western PII middleware (#102922) and document-scoped
anonymization (#102049). None of them recognize Chinese-language entities,
which are a different problem rather than a translation of the English one:

- Person names have no whitespace or capitalization boundary; the name is
  identifiable only by part-of-speech, not token shape.
- Company and institution names are marker-SUFFIXED (有限公司 / 研究院 /
  分行), so recognition keys off the tail with a variable-length run before it.
- Addresses are hierarchical and recursive across 省/市/区/县/街道.
- Magnitudes are written with the unit attached (3.5 亿元), so masking digits
  alone still leaks the scale.

Capabilities declared (verified against the pinned commit by loading it
through the real plugin loader against a temp HERMES_HOME — all four hooks
register, and provides_tools / provides_middleware are genuinely empty):

    provides_hooks: pre_llm_call, pre_api_request, transform_llm_output,
                    post_llm_call
    provides_tools: []
    requires_env: []

Design note for review: it uses the existing hook pair rather than
register_middleware("llm_request", ...) as in #102922. Hooks were sufficient
and need no new surface; if middleware is the preferred long-term seam for
message-rewriting plugins, that is worth settling before more plugins are
written against hooks. Raised in #118722.

The entry's description carries a Disclosure paragraph, following the
vaultknox precedent, covering the parts a reviewer should not have to
discover by reading the code: inbound messages and outbound replies are both
rewritten, placeholders are code-generated and can over-match, company names
are matched greedily (a modifier is absorbed into the placeholder),
magnitude masking drops the numeric value and fires only on configured
trigger words, and the placeholder mapping is memory-only.

Structural check: `python3 scripts/validate_plugin_catalog.py
plugin-catalog/desensitize.yaml` -> OK, 1 file(s) valid.

No contributors/emails file is needed: yflmq001@users.noreply.github.com is
already mapped.

Fixes #118722
2026-09-26 11:42:24 -07:00