Catalog trust bugs from the 2026-09-21 plugin audit (lane 3, F1-F6, F9): - F1 (high): a URL-installed repo shipping its own .hermes-catalog.json rendered as catalog:official everywhere and marked the real entry "installed". Provenance now lives on the installer-owned .install-metadata.json record (catalog block written by _install_plugin_core, sha = checked-out commit); read_catalog_sidecar never reads the tree. Pre-fix installs are adopted once when the installer record agrees (pinned at the sidecar sha, cloned from the entry's repo). - F2: removed.yaml bypassed by git@/ssh:///http:///www. spellings. _normalize_repo canonicalises to host/owner/repo (scheme, user, www., .git, slashes dropped). - F6: removed.yaml consulted for INSTALLED plugins too: git-pull update, enable and gate_manifest (load) refuse recalled plugins, offline (in-tree + cached live list). --allow-removed is recorded on the install record and exempts it. - F5: install NAME --ref X recorded the catalog pin, so list/TUI/update claimed the reviewed pin while HEAD differed. Recorded sha is the checked-out one. - F3: re-pin replaced the whole tree, losing the installer-created config.yaml, data and user patches with no warning. Untracked/ignored files are carried into the new tree; edits to tracked files are copied to <HERMES_HOME>/plugins-backup/<name>-<sha8>/ with a warning. - F4: a manifest rename between pins left the OLD dir installed and enabled. The stale dir is removed and the enabled flag follows the new name. - F9: dashboard payload `removed` list now includes live removals. repin_catalog_plugin returns RepinResult(sha, changed, installed_name, warnings); CLI, dashboard and TUI callers surface the warnings and the new name.
Website
This website is built using Docusaurus, a modern static website generator.
Reading the docs on GitHub? The Markdown under
docs/is authored for the rendered site at https://hermes-agent.nousresearch.com/docs/. Cross-page links are relative Markdown paths, so they follow through on GitHub's file viewer too. Every page on the site has an Edit this page link that opens the source file here.
Authoring links in docs/
- Link to another page with a relative Markdown path, anchors included:
[Profiles](../user-guide/profiles.md),[Bundles](../user-guide/features/skills.md#skill-bundles). Docusaurus turns the file path into the page route; GitHub follows the same path. Site routes (/user-guide/profiles,/docs/user-guide/profiles) only work on the rendered site — GitHub resolves them as repository paths and 404s, and the/docs/form also emits/docs/zh-Hans/docs/...404s in the zh-Hans build becausebaseUrlis already/docs/. python3 website/scripts/check_doc_links.pyfails on any route-style link in hand-authored pages (EN and the zh-Hans mirror);--fixrewrites them. It runs in theDocs Site Checksworkflow. Generated pages (user-guide/skills/{bundled,optional},reference/*skills-catalog.md) are produced byscripts/generate-skill-docs.py, which emits the same relative form.- Pin
{#anchor}on cross-linked headings so the zh-Hans mirror keeps the same id.
Installation
yarn
Local Development
yarn start
This command starts a local development server and opens up a browser window. Most changes are reflected live without having to restart the server.
Build
yarn build
This command generates static content into the build directory and can be served using any static contents hosting service.
Deployment
Using SSH:
USE_SSH=true yarn deploy
Not using SSH:
GIT_USER=<Your GitHub username> yarn deploy
If you are using GitHub pages for hosting, this command is a convenient way to build the website and push to the gh-pages branch.
Diagram Linting
CI runs ascii-guard to lint docs for ASCII box diagrams. Use Mermaid (````mermaid`) or plain lists/tables instead of ASCII boxes to avoid CI failures.