# Conflicts: # apps/desktop/electron/main.ts # hermes_cli/backup.py # hermes_cli/config.py # hermes_cli/plugin_catalog.py # hermes_cli/plugins_cmd.py # hermes_cli/plugins_cmd_catalog.py # hermes_cli/plugins_discovery.py # hermes_cli/profiles.py # hermes_cli/update_cmd_deps.py # pyproject.toml # tests/gateway/test_dm_topics.py # tests/hermes_cli/test_config.py # tests/hermes_cli/test_plugins_cmd.py # tests/hermes_cli/test_update_autostash.py # tests/tools/test_lazy_deps.py # tools/lazy_deps.py # tools/skill_ledger.py # utils.py # website/docs/user-guide/security.md
disk-cleanup
Auto-tracks and cleans up ephemeral files created during Hermes Agent sessions — test scripts, temp outputs, cron logs, stale chrome profiles.
Scoped strictly to $HERMES_HOME and /tmp/hermes-*.
Originally contributed by @LVT382009 as a
skill in PR #12212. Ported to the plugin system so the behaviour runs
automatically via post_tool_call and on_session_end hooks — the agent
never needs to remember to call a tool.
How it works
| Hook | Behaviour |
|---|---|
post_tool_call |
When write_file / terminal / patch creates a file matching test_*, tmp_*, or *.test.* inside HERMES_HOME, track it silently as test / temp / cron-output. |
on_session_end |
If any test files were auto-tracked during this turn, run quick cleanup (no prompts). |
Deletion rules (same as the original PR):
| Category | Threshold | Confirmation |
|---|---|---|
test |
every session end | Never |
temp |
>7 days since tracked | Never |
cron-output |
>14 days since tracked | Never |
| empty dirs under HERMES_HOME | always | Never |
research |
>30 days, beyond 10 newest | Always (deep only) |
chrome-profile |
>14 days since tracked | Always (deep only) |
| files >500 MB | never auto | Always (deep only) |
Slash command
/disk-cleanup status # breakdown + top-10 largest
/disk-cleanup dry-run # preview without deleting
/disk-cleanup quick # run safe cleanup now
/disk-cleanup deep # quick + list items needing prompt
/disk-cleanup track <path> <category> # manual tracking
/disk-cleanup forget <path> # stop tracking
Safety
is_safe_path()rejects anything outsideHERMES_HOMEor/tmp/hermes-*- Windows mounts (
/mnt/cetc.) are rejected - The state directory
$HERMES_HOME/disk-cleanup/is itself excluded $HERMES_HOME/logs/,memories/,sessions/,skills/,plugins/, and config files are never tracked- User project trees (
workspace/,projects/,plans/,home/,patches/,skins/,themes/,contributors/,profiles/,backups/) andkanban/(task attachments/workspaces) are never tracked or swept, even for files namedtest_*/tmp_* - A tracked directory under a protected top level (e.g.
cache/, which holds terminal snapshots) is never removed; only its files age out. Stale entries are logged asSKIPPEDand dropped - Backup/restore is scoped to
tracked.json— the plugin never touches agent logs - Atomic writes:
.tmp→ backup → rename