The Devs-Foundation/mnemosyne entry (created 2026-08-10, last push 2026-08-11, 0 stars) is
unrelated to the Mnemosyne project per its maintainers and registers the same memory-provider
name, which makes memory.provider: mnemosyne ambiguous. It is delisted (plain removal, not the
removed.yaml blocklist: nothing malicious) and welcome back under a distinct name. The official
mnemosyne-oss submission (#113581, wrapper shape validated end to end) takes the bare key.
requires_hermes floor set to the first release that carries #113851 (0.21.4 or later).
README gains the delist-vs-remove distinction and the provider-name collision rule.
subdir moves to integrations/hermes-catalog, the directory plugin shape
from #113851 (plugin.yaml kind exclusive, __init__.py shim, dependency
pyproject). sha 17abb10 is the merge of mnemosyne-oss/mnemosyne#974.
Tool list trimmed to the 37 tools register() exposes in an isolated
probe; requires_hermes >=0.22.
Symptom: a third of catalog entries (23 of 71 pinned trees scanned today) could not be
installed from the Desktop. The install path runs plugin_guard on every clone and a
caution verdict needs a confirmation; the CLI prompts, the Desktop/dashboard path
passes no decision callback, so caution became "Security scan blocked".
Root cause: admission (hermes plugins validate + catalog CI) never ran the scanner, so a
pin could be approved by a human and still trip the installer.
Fix, both halves:
- validate_plugin_dir gains a "security scan" check: dangerous fails the entry, caution
is reported as warnings so the reviewer reads the findings before merging the pin.
pinned-source-validate in plugin-catalog-ci.yml therefore runs the identical scanner.
- _install_plugin_core accepts reviewed_pin=<catalog sha>; when the checked-out revision
equals it, caution is accepted without a prompt. dangerous still blocks (a signature
added after review is what the backstop is for). Raw-URL installs, --ref overrides
and a checkout at any other revision keep the current behaviour.
Live: dashboard_install_plugin('weather') on origin/main -> BLOCKED caution; after -> ok.
Multi-provider usage/balance for the Hermes Desktop status bar (OpenCode,
OpenRouter, DeepSeek, Kimi, NovitaAI, ZAI, Alibaba, Arcee, plus
gateway-native Claude/Codex/Cursor/Nous).
Pinned at ba0652c (includes validated home directory and config file
integrity checks). 38/38 tests pass. No agent tools, hooks, or middleware.
No env vars required at runtime.
One installable package (agent half + desktop half) that puts a mode selector in
the desktop composer: ask / agent / plan / debug. The mode's operating note rides
the turn's model-facing bytes via pre_llm_call, so the durable row, the bubble and
the session title keep exactly what the user typed; ask mode is enforced read-only
through pre_tool_call. No core change, no renderer rebuild.
Pinned at 4f4e1c0b36165d84a9e2db7c71516f5a0c627d72 - the v2.0.0 package commit
(gates: 103 pytest cases, the desktop-half smoke test, hermes plugins validate,
and the repo's CI).
The plugin shipped in Sugar 3.10.2 and is now merged to main
(eade16940789bc1f927af090f8a3b475e537eddd). Structural validator and
the pinned-source clone + hermes plugins validate both re-verified
against the new pin.
Sugar is a local-first persistent memory provider: SQLite on the user's
machine with project and global scopes and guideline-aware search.
- Tier: community, category: memory
- Source pinned to 37cbe10b33e08f04a5d91826475716ab5c315a49
(roboticforce/sugar, hermes-plugin subdir)
- No standalone tools/hooks/middleware; registers a memory provider
with three agent tools (sugar_store, sugar_search, sugar_list_recent)
- Works on hermes-agent >= 0.19 (verified against PyPI 0.19.0 and
main 0.21.3: plugins validate passes, full provider E2E passes on
both versions)
- No network access, no API key, no self-updating code; all data stays
in the user's ~/.sugar/ and project .sugar/ SQLite databases
repo social banners are 2:1, so that shape fills the slot without a crop;
the recommended size is in the README/docs. Desktop AgentPluginRow gains
catalog_version to match the generated contract.
The 40-hex sha stays the release, but nobody reads one. Entries may now add
`version: "1.4.0"` (free-form, <=32 chars, never parsed) and `image:` (an https
URL on raw.githubusercontent.com / github.com / *.githubusercontent.com).
Why GitHub-only: the Desktop catalog browser deliberately never fetches from
third-party hosts, and a raw URL pinned to the entry commit is as immutable as
the sha it decorates.
Readers updated together: PluginCatalogEntry + entry_from_mapping (drop with a
warning, entry survives), validate_plugin_catalog.py (admission error), the
site extractor (drop, never fatal), the /docs/plugins card (banner + version
pill + "1.4.0 @ abcd1234" pin), the CLI table/info (pin_label), the TUI-gateway
plugin row (catalog_version -> Desktop "Update to 1.4.0"), and the Desktop
catalog detail header (image).
Three authors merged the sweep fix PRs overnight; each entry pins the merge
commit, which validates ok in a bare pip install -e . venv and scans safe/caution.
hermes-telemetry persists to local SQLite only (its one outbound call fetches a
public pricing list), so the telemetry opt-in policy is not engaged.
The plugins from the 2026-09-15 sweep that were held back for reasons that are
now resolved: Gondola failed only the validator bug fixed in 5f9042be;
hermes-intelligent-memory lives in plugin/intelligent_memory (subdir entry);
inkbox merged our provides_hooks fix (pinned at the merged commit);
home-dashboard and obsidian-memory are manifest-only dashboard plugins whose
probe skip was misread as a warning to hold on. All five validate ok in a bare
pip install -e . venv at the pinned sha; scanner verdicts safe/caution.
Every entry is pinned to the commit reviewed on 2026-09-15 and passed, at that
commit: `hermes plugins validate` (declared tools/hooks/middleware match
registrations, no built-in tool collisions) in both the main venv and a bare
`pip install -e .` venv, `tools.plugin_guard.scan_plugin` with a non-dangerous
verdict, a self-updater grep over every .js file, and a vendor-credential-store
write grep over every .py file. Capabilities and requires_env are copied from
each plugin.yaml; category was assigned by hand.
Teknium ruled that maintainers may add batches of community plugins from a
reviewed sweep instead of waiting for each owner to submit. Rule 5 and the
user-guide checklist now say so, and give authors the explicit right to adjust
or remove a swept-in entry via their own PR.
The Memory Wiki from #89940 (salvage of #31244 by @Araja119) ships as a
standalone plugin in NousResearch/hermes-memory-wiki instead of landing in
core; this entry lists it in the catalog at the repo's reviewed commit.
The pin is the repo's first commit (younger than the two-week maturity
window) and needs the repo owner's explicit waiver to merge.
Tab-to-grill a draft in the Desktop composer: one high-leverage decision per rung with a
recommended answer, then a faithful execution brief placed in the composer for review.
Owner-submitted; no self-updater; empty capability block matches register() at the pin.
Teknium's call: most community submissions are Desktop panes, so an entry
without a category lands on the Desktop shelf; "other" becomes "general" for
plugins that genuinely span areas. Shelf order puts Desktop first. The six
entries merged today (pets-all, newswire, auto-titler, live-voice,
metamask-wallet, web-octen) get explicit categories.
The catalog page was one undifferentiated grid filtered only by tier, so a
memory provider sat between two Desktop panes. Entries now carry an optional
``category`` (memory | desktop | platform | web | tools | voice | automation |
models | other, default other) that the loader, the admission validator and
the site extractor all understand.
/docs/plugins renders one shelf per category in browse mode, a category pill
row under the tier pills, a clickable category chip on every card, and a
results bar (active category, count, clear) when a filter or search flattens
the view. ``hermes plugins catalog`` gains a Category column and groups by it.
All 18 shipped entries are categorised. Unknown categories fail admission
(same contract as tier) so a typo cannot create a phantom shelf.