Fix punctuation mismatch: the English adult-fiction few-shot example used
a full-width CJK closing bracket in English text; switched to ASCII
parentheses. Reinforce kernel resynced (SHA256 identical). selftest 69/69.
Kernel changes validated by the author: two English few-shot mirrors added
(alongside the Chinese anchors); HASTE host-adaptation section removed
(no attributable effect; clauses covered by SUPREME DIRECTIVE + Output
contract; kernel now byte-identical to the reviewed upstream text);
six README titles fixed to the real version (were stale since rename).
selftest 69/69; budget 3435/section, 6870 dual.
Bilingual UI per Hermes agent/i18n standard: en default + zh catalog,
language via HERMES_LANGUAGE > display.language. Also fixes the command
name leftover from the rename (armor → jailbreak).
Per Teknium review: name must describe function (refusal removal).
Catalog entry + repo + manifest renamed to hermes-jailbreak-kernel
(v1.5.0), English-first description, re-pinned to a643013.
Validation at new pin: selftest 54/54, plugins validate passed.
Four owner-submitted entries, each pinned to a released tag:
- chronicle (memory) v5.8.35 — local-first SQLite memory + context
compression; registers the memory-provider and context-engine slots.
- custodian (automation) v3.0.1 — operations monitor for a Hermes
install: log/cron/journal scanning, Tier-1 auto-repair, issue ledger.
- identity (tools) v1.0.1 — view/edit the identity files, switch profile,
per-line staleness tracking.
- pocket-watch (desktop) v1.0.1 — dashboard-only cron companion pane.
Each entry mirrors the manifest at the pinned commit; scripts/validate_plugin_catalog.py
passes on the whole plugin-catalog/ tree locally.
Moves the pin 885ba10 -> 602393b so `hermes plugins update` delivers the
second half of plugin issue #14: native's per-request context no longer
carries the message cache breakpoint, so long tool-heavy sessions stop
re-writing their whole history to cache every round (plugin #30 + #31).
Hermes's 14-day `[tool.uv] exclude-newer` quarantine applies to Hermes's own
dependencies only (uv lock/sync, `hermes update`, LAZY_DEPS extras via
`ensure()`). A plugin's declared `python_dependencies` install under the
PLUGIN's policy: `install_specs(policy="plugin")` runs uv with `--no-config`
from any cwd, still inside the core constraints file.
Reverses item 3 of #118841, which ran the uv tier with cwd=<checkout> for
every install so the quarantine reached plugin deps from any cwd. That made
catalog re-pins floored on a <14-day release uninstallable (#120076:
"only hindsight-client<=0.9.2 is available"; #114530 held on the same gate).
Maintainer ruling (Teknium): "plugins dont have to abide by our 14 day rule
btw. They can have their own security policy on that. Only hermes'
dependencies themselves have to. We should recommend that they do this for
their plugins and we should give guidance to plugin devs that they should
though."
- tools/lazy_deps.py: INSTALL_POLICIES ("core" | "plugin"); `_uv_policy_args`
replaces `_uv_policy_cwd`; `_venv_pip_install(policy=)` defaults to core
(ensure/LAZY_DEPS), `install_specs(policy=)` defaults to plugin.
- hermes_cli/plugin_python_deps.py: `resolve()` passes policy="plugin".
- Docs: developer guide "Dependency security policy" section, catalog README
admission rule 9, AGENTS.md pinning policy — plugin authors are responsible
for their deps and strongly recommended to pin upper bounds, floor on the
oldest API-compatible version and run their own release quarantine
(`uv --exclude-newer` in their CI); operators can set UV_EXCLUDE_NEWER.
- Tests: the #118841 cwd test is replaced by two invariants — a plugin install
carries `--no-config` and no checkout cwd (red on base), a core lazy install
keeps the checkout cwd and no `--no-config`.
Picks up today's merged plugin fixes: the picker lists every model the CLI
advertises instead of dropping rows the pinned table does not know (#28,
luccapinto), a logged-out CLI explains itself instead of a bare Native API
error (#23, MaxFreedomPollard), the native child runs in one cwd per client so
the prompt-cache prefix stays stable (#26, co-authored jcperdomoybarra), and
reasoning-off requests complete on Fable instead of a 400 on
thinking.type.disabled (#27, neurowave). Plugin version unchanged (0.3.0); the
card art URL follows the pin.
Picks up the plugin's merged fix: Opus 5.5 is a pinned 1M-context route and the
`opus` alias resolves to it (plugin PR #19). Plugin version unchanged (0.3.0);
the card art URL follows the pin.
First two of the built-in memory providers whose maintainers now own the plugin. Same provider
name, config section, data and tools as the in-tree copies, so a later removal from core migrates
users via hermes_cli/memory_provider_migration. Nothing is removed here.
Pins the maintainer-owned copy of the formerly bundled plugins/memory/hindsight at
dc75038866a3966b5bf5c82ff57c7a758bb4070a (tree identical to tag v0.10.1). Same provider name,
memory.hindsight section, data dir and tool names, so hermes_cli/memory_provider_migration.py
can install it for existing users once the bundled copy leaves core.
hermes-nvidia#2 rewrites both skills' connection guidance for Hermes: the
plugin connects the server; when the tools are missing the model relays
Hermes's unavailable sentence and stops instead of registering the server
itself, probing ports or reading server.json. Tool contracts unchanged.
The onboarding card needs to list catalog plugins beside the hosted
connectors (NS-960 D1, D4) and grey a plugin whose app is absent (D5).
The catalog had no curated flag, and the manage_catalog row left
app_state empty.
- `onboarding: true` and `title` on catalog entries (loader, validator,
docs); set on blender, nvidia-app and nvidia-broadcast.
- hermes_cli/plugin_catalog_presence.py reads the plugin.json at the
catalog's pinned commit once per pin and judges its app declaration with
the hermes_platform resolver the installer and the Plugins-tab pill use.
No declaration or an unreadable one is `unknown`, never `present`.
- `plugins.manage action=onboarding` lists the curated entries this OS
runs (platform mismatch is the only exclusion) with app_state and the
sentence the card greys the row with.
- manage_catalog plugin rows now carry app_state and the catalog title.
- A live entry that differs from the in-tree entry at the same pin (new
metadata) now follows the same newer-catalog rule as a new pin, so a
checkout that adds `onboarding` is not masked by a published doc that
predates it.
Two portable Agent Plugins from NousResearch/hermes-nvidia, one per NVIDIA application, each in its
own subdir of the repo and pinned to 5023f3a4ea. Both declare the application they need through
the plugin.json extensions namespace: install is refused when the app is absent or too old
(NS-942), and the tools appear only while the app is running (NS-943). `platforms: [windows]` is
the catalog-level gate; the declaration is the per-server gate.
Proven live on two Windows machines (ARM64 laptop and x64 desktop): 12 NVIDIA App tools and
10 NVIDIA Broadcast tools registered from real sessions; the x64 desktop installed the package from
the desktop deep link and the model called the tools. The evidence rows are in the plugin repo.
The repository is private until release. The catalog CI clone step is expected to fail for these
two entries until the repo is flipped public; the static validation job passes (240 entries).
Picks up the plugin's merged fixes: empty-input tool calls no longer fail the
request (#2), Haiku 4.5 requests no longer send adaptive thinking, top-level
schema combinators are stripped before the native validator, the claude CLI is
resolved on the env PATH, and relay/native failures now name their real cause
instead of only the admission denial. Plugin version unchanged (0.3.0); the
card art URL follows the pin.
Salvage split of #118458: tamahermes is held (request-changes on the
catalog subdir importing the package from an out-of-tree checkout); the
two clean protean entries land here.
Salvage of #118562: the catalog name must match the plugin manifest
name (sabi-metadata) or 'hermes plugins install' produces a plugin dir
named after the manifest with a catalog sidecar under a different key.