复制安装命令
用 Codex 或 Claude 安装复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它先审查 Skill 页面再帮你安装。
复制前请先查看来源、License 和安全提示。
A self-improving version of Hermes Agent — it researches improvements,
用 Codex 或 Claude 安装复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它先审查 Skill 页面再帮你安装。
复制前请先查看来源、License 和安全提示。
来源文件:README.md
A self-improving version of Hermes Agent — it researches improvements, proposes them, and updates itself daily. You keep using Hermes as usual; it gets better on its own.
The self-improving AI agent built by Nous Research. It's the only agent with a built-in learning loop — it creates skills from experience, improves them during use, nudges itself to persist knowledge, searches its own past conversations, and builds a deepening model of who you are across sessions. Run it on a $5 VPS, a GPU cluster, or serverless infrastructure that costs nearly nothing when idle. It's not tied to your laptop — talk to it from Telegram while it works on a cloud VM.
Use any model you want — Nous Portal, OpenRouter, OpenAI, your own endpoint, and many others. Switch with hermes model — no code changes, no lock-in.
| A real terminal interface | Full TUI with multiline editing, slash-command autocomplete, conversation history, interrupt-and-redirect, and streaming tool output. |
| Lives where you do | Telegram, Discord, Slack, WhatsApp, Signal, and CLI — all from a single gateway process. Voice memo transcription, cross-platform conversation continuity. |
| A closed learning loop | Agent-curated memory with periodic nudges. Autonomous skill creation after complex tasks. Skills self-improve during use. FTS5 session search with LLM summarization for cross-session recall. Honcho dialectic user modeling. Compatible with the agentskills.io open standard. |
| Scheduled automations | Built-in cron scheduler with delivery to any platform. Daily reports, nightly backups, weekly audits — all in natural language, running unattended. |
| Delegates and parallelizes | Spawn isolated subagents for parallel workstreams. Write Python scripts that call tools via RPC, collapsing multi-step pipelines into zero-context-cost turns. |
| Runs anywhere, not just your laptop | Seven terminal backends — local, Docker, SSH, Singularity, Modal, Daytona, and Vercel Sandbox. Daytona and Modal offer serverless persistence — your agent's environment hibernates when idle and wakes on demand, costing nearly nothing between sessions. Run it on a $5 VPS or a GPU cluster. |
| Research-ready | Batch trajectory generation, trajectory compression for training the next generation of tool-calling models. |
Whether you're starting from scratch or already running Hermes, paste one line into your terminal. If Hermes isn't installed yet, it installs our version fresh; if it is, it switches your existing Hermes onto Evolution (your chats, memory, and settings are kept):
curl -fsSL https://raw.githubusercontent.com/Lexus2016/hermes-agent-evolution/main/upgrade.sh | bash
That's it. The script does everything for you, safely:
You can re-run it any time — it won't break anything. Your existing chats, memory, and settings stay exactly as they were.
Don't want unattended daily updates? Add
--no-starand/or--no-auto-updatewhen you run it (from a clone):bash upgrade.sh --no-auto-update.
The container image is built without a git working tree (.git is excluded
from the build context), so there are no remotes to repoint from the inside —
the same reason hermes update refuses to run there. You have two options.
A. Rebuild the image on the host — durable, survives container recreate:
git clone https://github.com/Lexus2016/hermes-agent-evolution.git
cd hermes-agent-evolution
docker build -t hermes-agent-evolution:latest .
# point your compose file / run command at that image, then:
docker compose up -d --force-recreate
B. Upgrade the running container in place — when you only have a shell inside it (NAS or panel deployments, no host docker, no build daemon):
docker exec -u 0 -it <container> bash
curl -fsSL https://raw.githubusercontent.com/Lexus2016/hermes-agent-evolution/main/upgrade.sh | bash -s -- --in-container
docker restart <container> # or let the script bounce the s6 service
This works because the image installs Hermes as an editable checkout
(uv pip install -e .), so the virtualenv imports straight out of
/opt/hermes — replacing the source tree is the upgrade. The script turns
/opt/hermes into a real git checkout of this fork; everything the repo does
not track (.venv/, node_modules/, the bin/hermes shim,
hermes_cli/web_dist/) is left untouched.
Two caveats for option B:
docker restart
keeps it; recreating the container from the image (compose up --force-recreate, an image pull) reverts to stock Hermes — which is also
your rollback. Re-run the command to reapply.git fetch.In both cases your config, chats and memory live on the $HERMES_HOME volume
(/opt/data) and are never touched.
uv.exe as malwareIf your antivirus (Bitdefender, Windows Defender, etc.) quarantines uv.exe from the Hermes bin folder (%LOCALAPPDATA%\hermes\bin\uv.exe), this is a false positive. The file is Astral's uv — the Rust Python package manager Hermes bundles to manage its Python environment. ML-based antivirus engines commonly flag unsigned Rust binaries that download and install packages.
To verify your copy is authentic:
# Install GitHub CLI if needed
winget install --id GitHub.cli
# Login to GitHub
gh auth login
# Run verification
$uv = "$env:LOCALAPPDATA\hermes\bin\uv.exe"
$ver = (& $uv --version).Split(' ')[1]
[Net.ServicePointManager]::SecurityProtocol = [Net.SecurityProtocolType]::Tls12
$zip = "$env:TEMP\uv.zip"
Invoke-WebRequest "https://github.com/astral-sh/uv/releases/download/$ver/uv-x86_64-pc-windows-msvc.zip" -OutFile $zip -UseBasicParsing
gh attestation verify $zip --repo astral-sh/uv
Expand-Archive $zip "$env:TEMP\uv_x" -Force
(Get-FileHash "$env:TEMP\uv_x\uv.exe").Hash -eq (Get-FileHash $uv).Hash
If attestation says "Verification succeeded" and the last line prints True, you're good.
To whitelist Hermes:
Add-MpPreference -ExclusionPath "$env:LOCALAPPDATA\hermes\bin"uv and the hash changes every versionFor more context, see the upstream Astral reports: astral-sh/uv#13553, astral-sh/uv#15011, astral-sh/uv#10079.
The agent needs a GitHub token to work with GitHub. There are two cases — pick the one that's you. (~2 minutes, no coding.)
The agent opens issues on the shared Hermes Evolution repo. That repo isn't
yours, so a fine-grained token can't target it — use a classic token with
the public_repo scope:
hermes-evolution. Expiration: 90 days (or longer).public_repo (under repo → “Access public repositories”). That's
the only box you need — it lets the agent open issues/PRs on public repos.ghp_…; shown once).echo 'GITHUB_TOKEN=PASTE_YOUR_TOKEN_HERE' >> ~/.hermes/.env
Done — your Hermes can now research and open improvement issues.
If you own hermes-agent-evolution, the agent can also implement changes,
open pull requests, push branches, and cut releases. You own the repo, so use a
fine-grained token scoped to it:
hermes-evolution-owner. Expiration: 90 days (or longer).hermes-agent-evolution (you can select it because it's yours).github_pat_…; shown once).# PRIVATE role — analysis, implementation, push, PRs, releases (owner):
echo 'GITHUB_PRIVATE_TOKEN=PASTE_OWNER_TOKEN_HERE' >> ~/.hermes/.env
# PUBLIC role — research + opening issues reads GITHUB_TOKEN.
# Simplest: reuse the SAME owner token here too.
echo 'GITHUB_TOKEN=PASTE_OWNER_TOKEN_HERE' >> ~/.hermes/.env
Why both? The agent forces the right token per role: issues/research use
GITHUB_TOKEN, while analysis/implementation useGITHUB_PRIVATE_TOKEN. If only one is set, half the cycle silently does nothing. Reusing the same owner token in both is fine. For a clean "proposals come from a separate account" split, put a second account's classicpublic_repotoken inGITHUB_TOKENinstead (see the Regular user section above) — but never swap the two:GITHUB_TOKENmust be the proposer,GITHUB_PRIVATE_TOKENthe owner.
Keep tokens private — treat them like passwords. Never share them or paste them into a chat. If one leaks, delete it on GitHub and create a new one.
Everything you already love about Hermes Agent still works exactly the same.
No need to install the original Hermes first — the one command above installs our fork directly (you do NOT end up on the original and then migrate). It pulls Hermes Evolution, sets it up, and turns on the evolution features in one go.
Windows works natively too — a PowerShell installer (scripts/install.ps1) is
included; see AUTO_UPGRADE.md.
Yes. The agent can propose changes but cannot silently rewrite itself: every change goes through a pull request with automated tests, and important parts require your approval before they're merged. Updates are backed up and roll back automatically if anything looks wrong.
Details: EVOLUTION_README.md · SECURITY_EVOLUTION.md
| Document | What's inside |
|---|---|
| AUTO_UPGRADE.md | Install/upgrade in detail, Windows, manual steps |
| EVOLUTION_README.md | How evolution works, modes, the safety gate |
| SECURITY_EVOLUTION.md | Security policy |
| AGENTS.md | Original Hermes Agent documentation |
MIT License (see LICENSE). Built on Hermes Agent
by Nous Research — huge thanks to them and the
Hermes community.
Quick start for contributors — use the standard installer, then work from the
full git checkout it creates at $HERMES_HOME/hermes-agent (usually
~/.hermes/hermes-agent). This matches the layout used by hermes update, the
managed venv, lazy dependencies, gateway, and docs tooling.
curl -fsSL https://hermes-agent.nousresearch.com/install.sh | bash
cd "${HERMES_HOME:-$HOME/.hermes}/hermes-agent"
uv pip install -e ".[all,dev]"
scripts/run_tests.sh
Manual clone fallback (for throwaway clones/CI where you intentionally do not want the managed install layout):
Create the venv outside the cloned source tree — a venv inside the directory the agent operates from can be wiped by a relative-path command the agent runs against its own checkout, destroying the running runtime mid-session.
curl -LsSf https://astral.sh/uv/install.sh | sh
uv venv ~/.hermes/venvs/hermes-dev --python 3.11
source ~/.hermes/venvs/hermes-dev/bin/activate
uv pip install -e ".[all,dev]"
scripts/run_tests.sh
MIT — see LICENSE.
Built by Nous Research.
name: a2a
description: Advertise Hermes capabilities via an A2A Agent Card.
version: 0.1.0
author: Hermes Agent
license: MIT
platforms: [linux, macos, windows]
metadata:
hermes:
tags: [a2a, interoperability, agent-card, discovery]
category: interoperability
related_skills: [hermes-agent]Hermes advertises itself to the Agent2Agent (A2A) ecosystem with an Agent Card: a small JSON document that describes the agent's identity, endpoint, auth methods, protocol capabilities, and the list of things it can do (its "skills").
This slice (issue #879, child of #748) implements discovery only:
hermes_cli/a2a.py (AgentCard,
AgentSkill, build_agent_card).hermes_cli/web_server.py) serves the card at
GET /.well-known/agent.json.SKILL.md skill is mapped to one entry
in the card's skills[] array. No new core tools are registered -- the
card is a read-only view over capabilities Hermes already has.All behaviour is driven by config.yaml in this directory,
which overlays the defaults baked into hermes_cli/a2a.py. Highlights:
enabled: false makes the endpoint return 404 (Hermes stops advertising).name / description / provider set the card's identity.url is the A2A service endpoint; a relative value (/a2a) is resolved
against the incoming request host so no hostname is hardcoded.authentication.schemes lists the advertised auth methods.expose.tools / expose.skills / expose.max_skills control which
capabilities are surfaced and the cap on the total.The card is a public discovery document by design (A2A clients hold no
dashboard session). It contains only tool/skill names and one-line
descriptions -- never secrets or config values. The A2A JSON-RPC server that
actually fulfils tasks (url), plus streaming and push notifications, are
later slices (#880 client, #881 server).
评论 (0)
暂无评论,成为第一个评论者吧!