Moves sha and docs_url to a4843d82c0b2c8443830b79f5e0a19b8a78a8303 (v0.19.2, peeled
commit). Capabilities block unchanged and re-verified at that commit.
Signed-off-by: SmokeDev <degensmoke@gmail.com>
Moves the pin from 8aeac6a6 to 4764f687, the peeled commit of tag v0.19.1.
The only source change on the auth surface is #146 (read-only Codex lane,
authored by @teknium1), merged as-is. plugin.yaml changed only its version
field; hook registrations, tools, middleware and required env are unchanged
against the declared capabilities block.
Signed-off-by: SmokeDev <degensmoke@gmail.com>
Registers superagents-lab/hermes-search1api (v0.1.0) — five tools backed by
the Search1API API: search1api_search, search1api_news, search1api_crawl,
search1api_sitemap, search1api_trending. Vendored official Python SDK; only
third-party dependency is httpx (already a Hermes core dependency).
hermes plugins validate (main @ 6005aa1): all checks pass, security scan
safe; declared tools match registrations.
Submitted by the plugin repo owner (superagents-lab).
The pinned tree now carries an Agent Plugins v1 plugin.json at the repo
root, so 'hermes plugins validate' passes and the catalog installer
finds its manifest. Security scan clean (no cautions).
New pin: 347ce44a1e71173285b2943a7a97bbdece8327b2
Split out from drkpxl/drkpxl-skills so the entry matches the product:
one skill, one repo, name on the tin. The new repo contains only the
morning-briefing skill. Entry name, repo URL, SHA pin, description,
and category all updated.
Community skills collection by the repo owner (drkpxl). Anchor skill:
morning-briefing — a personal daily newspaper that gathers weather,
calendar, AQI, curated 36-hour news (Reddit RSS + X + web search with
per-story QR codes), and newsletter digests, renders a single 8.5x11
newsprint page, and prints it every morning.
Also bundles: Tiny Air (US AQI via MCP), Bro, Copywriting, Delegate to
pi, Prototype, Research, Requesting Code Review.
SKILL.md follows the HARDLINE authoring standards (validated: 54-char
description, modern section order, native tool references). SHA pinned
at d81a9b5ee427a378839828d4a8eab3925468b7ce.
Adopts the DNS-rebinding-pinned transport hardening (repo issues #2/#3,
PR #3) and the starter-feed/settings failure-surfacing + SSRF-gated icon
proxy fix (issue #6, PR #8). Full range in
tony-simons-aiowa/hermes-newswire deccdc4..e6b438e (13 commits):
Security-relevant highlights:
- All outbound fetches (feeds, redirects, icons) now go through a pinned
transport: the SSRF gate's validated address set is bound to the actual
connection — no second DNS lookup, so DNS rebinding/TOCTOU has no
window; the plugin fails closed if the pin seam changes.
- New GET /icon.json proxies favicons through the same gate and returns
base64 data URLs — the renderer's <img> no longer performs unpinned
DNS resolutions of feed-controlled hostnames. 64 KB cap enforced
mid-transfer; image content-type allowlist; bounded, normalized TTL
cache.
- Renderer surfaces backend failures (settings/sources banners,
starter-feed inline errors) instead of silent no-ops.
Capabilities unchanged (all empty — dashboard plugin, no tools/hooks/
env). Verification at the new pin: 129 pytest, 33 renderer interaction
checks, 26 ESM render smoke, hermes plugins validate clean.
Self-hosted Memobase (user profile + event timeline) as a MemoryProvider.
Hybrid BM25 + vector + entity RRF recall, temporal boost on time-window
queries, and a conditional cross-encoder rerank.
The reranker is opt-in with no default endpoint: it runs only when the
deployment sets both rerank_base_url and rerank_api_key, so a default
install talks only to the user's own Memobase server.
Pinned to 4e8e447 of fred0m/hermes-memobase-provider. Declares the two env
vars the install must prompt for.
Owner-submitted (anotherchu/billing). Desktop-half-only package: root
plugin.yaml + desktop/plugin.js, no __init__.py — the manifest-only path
home-dashboard also takes, so the capability probe is skipped.
At the pinned commit: scripts/validate_plugin_catalog.py passes;
`hermes plugins validate` passes (manifest fields, requires_hermes,
built-in collisions); the CI's pinned-source clone/checkout/validate
sequence was reproduced locally. Self-updater grep over every .js file:
clean. requires_hermes ">=0.19" — the desktop plugin SDK surface and the
billing.state gateway RPC both exist as of v2026.7.20 (0.19.0).
Kiro CLI (AWS) as a Hermes model provider via the external-process (ACP)
seam — a ProviderProfile spawning `kiro-cli acp` over stdio, extending the
in-tree copilot-acp shim. Pinned to v0.1.0 (fe95ccba), which is
E2E-verified: discovery via both install paths, live completion through
kiro-cli 2.22.0, plugin test suite 5/5 green at that commit.
Pins emadalsaba/hermes-session-styler at the commit that passes the pinned-source gate.
Capabilities declared empty: the plugin contributes no agent tools, hooks, middleware or env vars —
the whole implementation is the desktop half.