Pins the localsend catalog entry to 28dfd30ccd — the revision that merges
the catalog security review's hardening (teknium1's review on this PR:
share-root allowlist with realpath checks on send and receive, LAN-only
peer gate, mandatory PIN with crypto-safe generation, 2 GiB transfer cap),
plus bumps the entry to v1.19.0.
The receiver can now serve TLS for peers that force encryption, announcing the
certificate fingerprint a peer pins. Sender certificates are not validated -
stdlib Python cannot accept arbitrary self-signed client certificates - which is
documented next to the limit rather than implied.
Pins the reviewed commit for v1.17.0 and fills in the entry contract the rest of
the catalog uses: tier, category, docs_url, requires_hermes, version, and the
capability declarations (three tools, no hooks, no middleware, no env vars).
Card image rebuilt from a real capture of the plugin's desktop pane.
Stop now reports a genuinely stopped receiver (the payload previously said
stopped=true and running=true at once), plus a contract test pinning the
desktop pane's ctx.rest paths to the backend routes.
Repins to the v1.16.0 commit: the plugin can now send to peers in LocalSend's
default HTTPS mode, presenting a persistent device certificate, announcing its
SHA-256 fingerprint in LocalSend's uppercase-hex format, and pinning the peer's
certificate against the fingerprint it advertised.
Repins to the v1.15.0 commit, which adds the desktop half — a LOCALSEND pane,
status-bar chip and three palette commands — and a dashboard backend at
/api/plugins/localsend/. The agent tools are unchanged.
LocalSend (open-source AirDrop alternative) peer-to-peer transfer for Hermes:
localsend_discover, localsend_send and localsend_receive. Standard-library
implementation of LocalSend Protocol v2.2 with no runtime dependencies.
Owner submission of https://github.com/tylerbrevard/hermes-localsend, pinned to
49dcb1f0c18ff2a25a2f3c9d89fa021307afbcde (tag v1.12.2).
2cc23a9 -> c4123fbdb315137b40e4c5b4b5fd3eb2298dae66. The pinned commit runs its suite on ubuntu-latest, macos-latest and
windows-latest (actions/runs/35520540211, all green), so windows is declared in platforms instead of
being excluded without explanation, and the README now gives the manual install route that Windows
needs because install.sh is a POSIX shell script.
What CI found and fixed on the way to that green run, all of it reaching the plugin only through this
branch: an in-place overwrite of a multi-frame image failed on Windows because the input's read handle
(and the mapping Pillow uses for single-strip BMP/TIFF/PNG/P) was still open at the rename; a
read-only target is refused by Windows even with the mode restored afterwards, so the attribute is
cleared for the rename and put back either way; WinError 5/32 from an external holder is retried
briefly; release/rename/chmod hold the plugin's guard lock; and converting a JPEG with EXIF
orientation 5-8 to TIFF no longer fails its own verification (Pillow's TIFF reader applies the tag,
so the file legitimately reads back transposed).
Diff adopted: 5 commits, tools.py +158/-23, tests +366, README +5, 135 tests (134 + 1 platform skip
on Windows).
b1eb2585 -> 2cc23a99a6df9238b25cd5dc118946563afb1bd9. The new commit adds a linux/macOS/Windows test matrix and the two platform
guards it needed, so the pinned code is now tested on every platform the entry claims plus Windows.
Diff being adopted: .github/workflows/tests.yml (new), tests/test_image_utils.py and
tests/test_competition_fixes.py (platform guards only). No plugin behaviour changes.
Review feedback: the trust-boundary limitation lives in the PR body and the
repo README, but a catalog reader may never open either. Add an inline comment
on the entry naming the limitation and where it is documented.
Comment-only; the pinned sha is unchanged.
Herald lets Hermes agent profiles dispatch work to each other: async dispatch
to a target profile's API server with SSE completion, synchronous multi-turn
chat, model-selectable in-process subagents, a durable SQLite run ledger,
fail-closed per-target model-route discovery, and host-owned bare LLM
inference. 12 tools, no core tool collisions.
Pinned at v1.1.1 (1d185a9e). requires_hermes >=0.21.0: the approval-consent
gate imports tools.approval_prompt.request_elicitation_consent, which first
exists in 0.21.0.
The entry pinned 88e5b023, which is the annotated tag OBJECT for v0.1.2 —
40 hex, but not a commit. Git peels the ref on checkout and detaches at the
commit it points to (02c4dd06), so the installer's revision guard saw
tag-sha != HEAD and refused:
Error: Checked-out revision '02c4dd06...' does not match requested
commit '88e5b023...'.
The entry was therefore uninstallable: `hermes plugins install kiro-acp`
failed for everyone, at the pin, with no way through.
Pin the commit the tag points at (same tree as reviewed; the tag was created
on a commit that is also the current main tip). Verified end to end:
`--ref 88e5b023` fails with the mismatch above, `--ref 02c4dd06` installs.
Swept all 194 catalog entries for the same class: this was the only pin that
names a tag object.
Adds one plugin-catalog entry for trajectoire-ai/hermes-structured-aux-models,
a `kind: model-provider` plugin that registers the `structured-aux` provider.
The plugin accepts the OpenAI-shaped `chat.completions.create()` call Hermes'
auxiliary client makes and translates it into a bounded Jev decision request on
OpenRouter, mapping the typed answer back — so auxiliary tasks (approval, MCP
sampling, compression) get a bounded decision instead of a free-form chat
prompt. It fails open: any request it cannot express as a decision raises, so
Hermes falls back to the operator's own auxiliary provider.
- tier: community, category: models
- pin: e5c49b081ad04adca2ee3edc601b09ede6cee4c5 (v0.1.0, repo released)
- capabilities: no tools, hooks or middleware registered; no required env vars
(the OpenRouter credential resolves env -> profile .env -> Hermes credential
pool, so no duplicate secret is demanded at install time)
- requires_hermes: ">=0.21" — the plugin seams were verified against v0.21.0
Verified locally against the admission gate at the pinned sha:
`python3 scripts/validate_plugin_catalog.py plugin-catalog/` -> OK: 187 files valid
`hermes plugins validate --install-deps <dir>` -> Validation passed (13/13 checks,
security scan: safe, capability probe: registered provider structured-aux)