Automatic version history for the built-in memory (MEMORY.md, USER.md),
SOUL.md and skills/, with `hermes memory-rewind` to browse, diff and restore
any past version. Pinned at 130ec1fff681624fc2f12aad9c16fda69efdef1e
(v1.0.0) of AhmetArif0/hermes-memory-rewind, subdir memory-rewind.
Moves the pin to the 0.3.1 docs release and states the disclosure once: only the configured server receives data, and a completed turn sends a fixed marker.
Bumps the pinned sha to the v1.1.2 release and version to 1.1.2.
v1.1.2 fixes the codex-telegram-notify attribution/link and suppresses
duplicate lifecycle notifications for Telegram-origin sessions, while
preserving existing subagent/smart-approval filtering.
Standalone MemoryProvider plugin for CortexLayer (github.com/Cortex-Layer/cortexlayer-hermes-plugin),
a linked-page long-term memory service with link-expansion retrieval. Platform mode only
(hosted api.cortexlayer.net, API-key authenticated) — implements the required lifecycle, all
5 memory tools (memory_add/retrieve/update/delete/relink), and the on_session_end /
on_pre_compress hooks (checkpoint API v2).
Owner submission (I maintain the plugin repo). Manually verified end-to-end against a real
Hermes instance before this submission (multi-turn conversation, confirmed sync_turn/prefetch
working with the profile's built-in memory disabled to remove ambiguity).
Move the 2.8.0 pin from f15fe1216cbb8cec3ddd61e8ff12936180cc5f42 to
e47e956f9bb00b0897b028bcd53c162a2d64665a, the cleaned public lineage
(branch public-main). Same tree (byte-identical, 549722b) and therefore
the same 2.8.0 code: f15fe12's history still carries the employer name
in 7 older versions of tests/test_extraction_hygiene.py plus one old
commit message with an offensive handle, which public clones would
surface; e47e956 is exactly that history with those two strings removed.
Only the commit SHAs differ.
All 8 SHA-pinned references (sha, docs_url, image, 5 screenshots) moved.
Validation at the new pin (fresh clone of public-main):
hermes plugins validate --install-deps plugins/entropicmem ->
Validation passed (known EM-213 capability warns only).
scripts/validate_plugin_catalog.py -> OK; all 7 pinned URL targets
resolve authenticated at e47e956.
Bump the catalog pin from 2.7.0 (437c89b7) to 2.8.0 at
f15fe1216cbb8cec3ddd61e8ff12936180cc5f42, the EntropicMem S1 hotfix
release merge (EM-101..EM-118). Same tree as the superseded merge
commit; all 8 SHA-pinned URLs (docs_url, image, 5 screenshots, repo)
moved to the new pin; entry version 2.8.0 matches plugin.yaml and
pyproject.toml at the pin.
Validation at the pinned commit: hermes plugins validate
--install-deps plugins/entropicmem -> Validation passed (expected
memory-provider capability warns only: provides_tools/provides_hooks
are carried by the registered MemoryProvider, which the capability
probe cannot see; unchanged from the 2.7.0 admission).
scripts/validate_plugin_catalog.py -> OK.
Addresses review items on
NousResearch/hermes-agent#118727:
- Declares runtime deps in the plugin manifest (jieba, PyYAML) so the
catalog capability probe passes; the deps previously lived only in the
repo-root pyproject.toml, which the loader does not read for a subdir
plugin.
- English defaults for the command description; status/help are bilingual.
- Discloses the semantic layer's egress: pre-redaction text goes to the
configured LLM, and provider=openai without base_url falls back to
api.siliconflow.cn (remote). Default provider=ollama stays local.
- Status output now prints the resolved endpoint instead of a hardcoded
label, plus an Egress line.
Chinese-context PII redaction. Adds one catalog entry pinning
yubingz/hermes-desensitize at 8ef2d22.
The gap this fills: the catalog has secret redaction (vaultknox: API keys,
tokens, passwords — a 28-pattern English key-format registry) and, as open
proposals, English/Western PII middleware (#102922) and document-scoped
anonymization (#102049). None of them recognize Chinese-language entities,
which are a different problem rather than a translation of the English one:
- Person names have no whitespace or capitalization boundary; the name is
identifiable only by part-of-speech, not token shape.
- Company and institution names are marker-SUFFIXED (有限公司 / 研究院 /
分行), so recognition keys off the tail with a variable-length run before it.
- Addresses are hierarchical and recursive across 省/市/区/县/街道.
- Magnitudes are written with the unit attached (3.5 亿元), so masking digits
alone still leaks the scale.
Capabilities declared (verified against the pinned commit by loading it
through the real plugin loader against a temp HERMES_HOME — all four hooks
register, and provides_tools / provides_middleware are genuinely empty):
provides_hooks: pre_llm_call, pre_api_request, transform_llm_output,
post_llm_call
provides_tools: []
requires_env: []
Design note for review: it uses the existing hook pair rather than
register_middleware("llm_request", ...) as in #102922. Hooks were sufficient
and need no new surface; if middleware is the preferred long-term seam for
message-rewriting plugins, that is worth settling before more plugins are
written against hooks. Raised in #118722.
The entry's description carries a Disclosure paragraph, following the
vaultknox precedent, covering the parts a reviewer should not have to
discover by reading the code: inbound messages and outbound replies are both
rewritten, placeholders are code-generated and can over-match, company names
are matched greedily (a modifier is absorbed into the placeholder),
magnitude masking drops the numeric value and fires only on configured
trigger words, and the placeholder mapping is memory-only.
Structural check: `python3 scripts/validate_plugin_catalog.py
plugin-catalog/desensitize.yaml` -> OK, 1 file(s) valid.
No contributors/emails file is needed: yflmq001@users.noreply.github.com is
already mapped.
Fixes#118722