Adds one plugin-catalog entry for trajectoire-ai/hermes-structured-aux-models,
a `kind: model-provider` plugin that registers the `structured-aux` provider.
The plugin accepts the OpenAI-shaped `chat.completions.create()` call Hermes'
auxiliary client makes and translates it into a bounded Jev decision request on
OpenRouter, mapping the typed answer back — so auxiliary tasks (approval, MCP
sampling, compression) get a bounded decision instead of a free-form chat
prompt. It fails open: any request it cannot express as a decision raises, so
Hermes falls back to the operator's own auxiliary provider.
- tier: community, category: models
- pin: e5c49b081ad04adca2ee3edc601b09ede6cee4c5 (v0.1.0, repo released)
- capabilities: no tools, hooks or middleware registered; no required env vars
(the OpenRouter credential resolves env -> profile .env -> Hermes credential
pool, so no duplicate secret is demanded at install time)
- requires_hermes: ">=0.21" — the plugin seams were verified against v0.21.0
Verified locally against the admission gate at the pinned sha:
`python3 scripts/validate_plugin_catalog.py plugin-catalog/` -> OK: 187 files valid
`hermes plugins validate --install-deps <dir>` -> Validation passed (13/13 checks,
security scan: safe, capability probe: registered provider structured-aux)
One-time, explicit copy of provider credentials from one profile to other
profiles from a desktop page. Owner submission (rule 5): repo and tag v1.0.1
pinned at 1599d21d1bce11d94424f749531dadf8d619f42c.
The pin merged in #115599 (eb1ac9b) carries a security gap found during that
review: the run_command_evaluator capability was never consulted, because
AutonomyPolicy was never constructed anywhere in src/. A project at autonomy
level 0 still executed command-type objective evaluators, since the security
allowlist constrains which executable may run and never whether running is
permitted at all.
4f733a8 wires the policy in and fails closed below level 3.
Verified at the new sha against a clean NousResearch/hermes-agent main
checkout: doctor_plugin ok with no findings, read_declaration resolves both
deps from pyproject. Upstream repo gates all pass.
The entry pinned 1.5.0/3bb0a64. v1.5.2 fixes the visualizer layout on
phone, tablet and foldable (navigation was removed below 640px, the
topbar and filter bar overflowed their frame, touch targets were 25px).
The pin is what the installer resolves, so a stale one ships the old UI.
Local-first LanceDB vector memory provider. Registers the memory provider
`lancedb-suite` (the catalog key `lancedb` belongs to the upstream project
lancedb/hermes-agent-memory, which registers the same provider name — the
mnemosyne precedent), pinned at v1.5.0.
The plugin lives in the repository's `plugin/` subdirectory; the pin is a
40-character commit that is also the v1.5.0 tag.
Checks, run at the pinned sha:
- `hermes plugins validate`: all checks green, `security scan — safe`
(the scanner runs on the `plugin/` subdir the CI clones, not the whole repo)
- declared capabilities match reality: the 8 declared tools are exactly the 8
the provider registers
- no self-updating code under the scanned sources
- `hermes plugins install 3L0935/hermes-lancedb-memory-suite/plugin` verified
end to end into a clean HERMES_HOME
Notable behaviour: automatic memory injection is off by default
(`memory.lancedb-suite.auto_prefetch: true` restores it). The core splices
prefetch output onto the user message as relevant context, and a measured
ambiguous query pulled an unrelated memory through the vector path, so recall
is a tool call rather than a push.
One community entry, category memory: Compartment's native Hermes memory
provider, pinned to the commit that adds its register(ctx) entry point and
declares the engine as a plugin dependency. Capabilities are empty, as the
admission probe records for a memory provider.