Files
hermes-agent/plugins/disk-cleanup
kshitijk4poor f0df5e05b1 fix(disk-cleanup): harden and gate the per-candidate git tracked check
_git_tracks hand-rolled `git ls-files` without windows_hide_flags, an
isolated git env or stdin=DEVNULL. It runs from the synchronous
post_tool_call hook, so on a windowless Windows host each test_*/tmp_*
candidate could flash a console (#54220/#56747 class), and an inherited
GIT_DIR/GIT_WORK_TREE would point it at the wrong repo. Reuse
hermes_cli.source_check._git_ok, which already does all three and returns
False on any failure. The timeout drops to 5s (ls-files needs no more).

git reads the argument as a pathspec, so an untracked `test_[1].py` or
`tmp_*` glob-matched a tracked sibling and was never cleaned. Prefix it
with `:(literal)`.

Only spawn git when a .git exists at or above HERMES_HOME (HERMES_HOME is
a checkout, or sits inside a dotfiles repo). Without one, no repo can
track the file, so a stock install now does a few stats and skips the
process spawn on every qualifying tool call.

Drop the docstring paragraph that repeated _git_tracks' rationale.
2026-09-27 01:36:34 +05:30
..

disk-cleanup

Auto-tracks and cleans up ephemeral files created during Hermes Agent sessions — test scripts, temp outputs, cron logs, stale chrome profiles.

Scoped strictly to $HERMES_HOME and /tmp/hermes-*.

Originally contributed by @LVT382009 as a skill in PR #12212. Ported to the plugin system so the behaviour runs automatically via post_tool_call and on_session_end hooks — the agent never needs to remember to call a tool.

How it works

Hook Behaviour
post_tool_call When write_file / terminal / patch creates a file matching test_*, tmp_*, or *.test.* inside HERMES_HOME, track it silently as test / temp / cron-output.
on_session_end If any test files were auto-tracked during this turn, run quick cleanup (no prompts).

Deletion rules (same as the original PR):

Category Threshold Confirmation
test every session end Never
temp >7 days since tracked Never
cron-output >14 days since tracked Never
empty dirs under HERMES_HOME always Never
research >30 days, beyond 10 newest Always (deep only)
chrome-profile >14 days since tracked Always (deep only)
files >500 MB never auto Always (deep only)

Slash command

/disk-cleanup status                     # breakdown + top-10 largest
/disk-cleanup dry-run                    # preview without deleting
/disk-cleanup quick                      # run safe cleanup now
/disk-cleanup deep                       # quick + list items needing prompt
/disk-cleanup track <path> <category>    # manual tracking
/disk-cleanup forget <path>              # stop tracking

Safety

  • is_safe_path() rejects anything outside HERMES_HOME or /tmp/hermes-*
  • Windows mounts (/mnt/c etc.) are rejected
  • The state directory $HERMES_HOME/disk-cleanup/ is itself excluded
  • $HERMES_HOME/logs/, memories/, sessions/, skills/, plugins/, and config files are never tracked
  • User project trees (workspace/, projects/, plans/, home/, patches/, skins/, themes/, contributors/, profiles/, backups/) and kanban/ (task attachments/workspaces) are never tracked or swept, even for files named test_*/tmp_*
  • A tracked directory under a protected top level (e.g. cache/, which holds terminal snapshots) is never removed; only its files age out. Stale entries are logged as SKIPPED and dropped
  • Backup/restore is scoped to tracked.json — the plugin never touches agent logs
  • Atomic writes: .tmp → backup → rename