* chore(guards): allow the public Hermes platform name in tests The banned entry targeted conflating the public NousResearch agent with private deployment names. gbrain now documents and tests against the public platform (README hero, claw-test runner, install door e2e), so the public name is legal in tests; private fork names remain banned. Drops the three now-inert allowlist entries. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * feat(claw-test): hermes runner, live staging + success oracles, friction diff HermesRunner (hermes -z one-shot, HERMES_BIN > which hermes, allowlist env with HERMES_HOME + OPENROUTER_API_KEY delta). Live mode now stages the scenario before the agent turn (fresh-install: brain + routing stub + init; upgrade: seed-first) and verifies outcomes after it: doctor must parse and report healthy/warnings, scenario-declared query + files_exist oracles are enforced for every kind, and upgrades use a non-mutating schema-version probe that must reach LATEST_VERSION. Missing upgrade seed dumps fail loudly in BOTH modes (a silent skip false-greened the upgrade lane). Bare gbrain in live runs resolves through a per-run PATH shim; when gbrain itself runs under the bun runtime the harness synthesizes a launcher back into cli.ts instead of handing children the bun binary. gbrain friction diff --base/--compare: identity is (kind, phase, digit-collapsed 80-char prefix); severity compares as a per-severity distribution (integer proportion test) so redistribution and delight-to-friction flips always surface; run start/end phase markers carry agent + scenario for agent-name resolution. Hardening from the adversarial gate: every harness child runs under a wall-clock timeout with process-group kill + exit-fallback settle; scenario names and declared brief/brain/seed paths are confined to the scenario dir; child friction merges require a regular file, cap size, and keep only valid JSONL lines; crashed runs stamp a non-zero end marker; GBRAIN_* routing vars are scrubbed from child env; agent stdin closes at spawn; argv agent/scenario values are charset-guarded. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * test(hermes): real-binary install door e2e + generic workspace compat Door e2e registers this checkout's gbrain into a hermetic Hermes home via the real CLI (single --env flag with multiple values, piped confirm, enabled:true + mcp test as the success discriminators), the direct-YAML surface, and a paid one-shot smoke turn proving MCP recall of a seeded synthetic fact with a NO-GBRAIN-TOOL negative control. Triple-gated (opt-in env + resolvable binary + non-empty anthropic key) so it can never burn tokens by accident; anthropic-only auth because a second visible provider key mis-routes hermes provider auto-detection. Helpers copy exactly ONE provider key from the operator's env file, never the whole file, and scrub all provider keys from child env. workspace-generic-compat pins the documented any-repo-with-a-workspace install flow (detection tier, scaffold additivity, resolver health) on a generic fixture; the Hermes-behavior proof lives in the door test. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * ci: label-gated hermes-door job + e2e hermeticity scrub hermes-door provisions a pinned Hermes release: installer digest verified before execution, payload tag+commit flags ASSERTED post- install via rev-parse (an installer that ignores unknown flags can never run unpinned upstream code next to secrets), secretless install step, loud-fail preconditions, zero-pass-refuses-green, evidence scrubbed three ways before upload, and unconditional credential cleanup for self-hosted-runner safety. real-agent-e2e gains the door file + opt-in env. run-e2e.sh scrubs HERMES_* alongside OPENCLAW_*; e2e-test-map narrows claw-test core changes to their e2e suite. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * docs: hermes + openclaw MCP guides, CLI pin notes, harness reference updates Per-client docs for Hermes (observed-behavior guide incl. flag-order and multi-key gotchas) and OpenClaw; HERMES-CLI-PIN records every pinned CLI behavior + the CI pin posture. README MCP table rows, INSTALL_FOR_AGENTS hermes block, TESTING/KEY_FILES current-state rewrites (two runners, oracle semantics, diff identity), TODOS closure (hermes runner done, friction diff shipped, follow-ups filed) and the llms bundle regenerated in the same commit. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * chore: bump version and changelog (v0.45.10.0) Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * docs: release sync — verb-count drift, hermes link, discovery rows, harness knobs Cross-referencing the diff against every .md surfaced drift beyond this wave: the memory-verbs surface prose still said five verbs (the frozen protocol grew context_pack + delta additively), docs/INSTALL.md linked a wrong Hermes repo and missed the new HERMES/OPENCLAW per-client guides, the door-suite doc pinned a tool COUNT that tracks the op catalog, the friction protocol skill missed the diff subcommand, and the claw-test KEY_FILES entry lacked the harness env knobs. Comment counts in heavy-tests.yml corrected (three triggers; four door tests). llms bundle regenerated in the same commit. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * ci: quote inner expansion in evidence-scrub path strip (shellcheck SC2295) Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * chore: re-bump to v0.45.12.0 (user-pinned past the contested 0.45.11.0 slot) Two sibling PRs already claim 0.45.11.0; pinning one slot higher avoids a second merge-race re-bump. All version locations move together: VERSION, package.json, CHANGELOG entry header, openclaw.plugin.json, bootstrap runbook stamp, regenerated template stamp, CLAUDE.md example cell, llms bundle. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> --------- Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
4.2 KiB
Connect GBrain to Hermes
This page is the MCP-registration reference for Hermes (the NousResearch
hermes-agent). For the full brain install — CLI, engine, skills, dream cycle — follow INSTALL_FOR_AGENTS.md first; this page wires the finished brain into Hermes over stdio MCP.
Hermes spawns gbrain serve as a local stdio subprocess. No server, no tunnel,
no token needed. Works with both PGLite and Supabase engines.
Register (recommended)
printf 'Y\n' | hermes mcp add gbrain --env GBRAIN_HOME=$HOME --connect-timeout 60 --command $(which gbrain) --args serve
hermes mcp add performs a real MCP handshake and tool discovery at add time,
then prompts Enable all N tools? [Y/n/select]:. Three gotchas, all observed:
--argsmust be the LAST option. Everything after it — including a misplaced--env— is swallowed into the server argv. To pass several environment variables, list them all after ONE--envflag (--env A=1 B=2); repeating the flag replaces the earlier values and the server is saved disabled when its handshake then fails. Put--envand--connect-timeoutbefore--command, exactly as above.- Pipe the
Yin non-interactive contexts. EOF on the enable-tools prompt printsCancelled.and saves nothing. The pipedYsaves the server with all tools enabled. - The exit code is 0 even on connection failure or cancel. Never assert on
mcp add's exit status — verify withhermes mcp listandhermes mcp test gbrain(below).
Direct config (equally supported)
The add command writes an mcp_servers block into $HERMES_HOME/config.yaml
(default ~/.hermes/config.yaml). You can write it yourself instead:
mcp_servers:
gbrain:
command: gbrain
args:
- serve
env:
GBRAIN_HOME: /home/alice-example
connect_timeout: 60.0
enabled: true
To remove gbrain, delete this block (or set enabled: false to disable
without losing the config).
Verify
hermes mcp list # table row: gbrain ... ✓ enabled
hermes mcp test gbrain # exits 0 and prints the discovered tool list
Then one real round-trip:
hermes -z "ask my gbrain brain: what did I import most recently?"
hermes -z prints the final answer on stdout (benign notices may appear on
stderr). Inside Hermes, gbrain's tools appear namespaced as
mcp_gbrain_<tool> (e.g. mcp_gbrain_search).
Headless auth + model pin
For cron jobs, CI, or any non-TTY run, Hermes needs a provider key and a default model configured without the interactive picker:
-
Put the key in
$HERMES_HOME/.env:ANTHROPIC_API_KEY=sk-ant-... # or OPENROUTER_API_KEY / OPENAI_API_KEY -
Pin the model non-interactively (
hermes modelis interactive-only — never use it in scripts or CI):hermes config set model.default anthropic/claude-haiku-4.5 hermes config get model.default # reads it back
Pair with cron
Hermes cron is fully non-interactive, which makes it a natural scheduler for brain maintenance:
hermes cron create --name gbrain-sync '0 */4 * * *' 'Run gbrain sync and report anything unusual'
hermes cron tick # run due jobs once and exit — deterministic testing
hermes cron list
See docs/guides/cron-schedule.md for the full brain maintenance protocol (sync, embed, dream cycle).
Troubleshooting
hermes doctor— global health check (installation, config, providers). It's not a per-server assertion; usehermes mcp test gbrainfor that.agent failed: No inference provider configured(exit 1) — Hermes has no model key. Set one in$HERMES_HOME/.envand pinmodel.defaultas above.- Relocating Hermes — both the installer and the runtime honor
HERMES_HOME. All state (config.yaml,.env,SOUL.md, cron, logs) lives under it; the default is~/.hermes. Export it consistently or the gbrain registration lands in a config file the runtime never reads.
Documented against Hermes Agent v0.20.0 (2026.8.3). Dev-facing observed-behavior notes (exact flag semantics, exit-code caveats, CI pin values) live in HERMES-CLI-PIN.md.