Merge pull request #2134 from open-gsd/feat/2091-hermes-eos-migration

feat(#2091): migrate Hermes onto EoS imperative adapter + extensionEvents dialect (ADR-1239)
This commit is contained in:
Tom Boucher
2026-07-09 23:37:27 -04:00
committed by GitHub
11 changed files with 286 additions and 16 deletions

View File

@@ -0,0 +1,5 @@
---
type: Changed
pr: 2134
---
**Hermes Agent is now driven through the public Host-Integration Interface, with three capability upgrades (ADR-1239 / EoS).** Hermes previously installed via hardcoded `runtime === 'hermes'`/`isHermes` branches in `bin/install.js`; its install/uninstall now runs through the imperative adapter, and every hardcoded hermes branch is folded into descriptor-driven `runtime.hostBehaviors`. Three upgrades land: (1) **real plugin hook vocabulary** — GSD registers a new `extensionEvents: "hermes"` dialect carrying the 13 documented Hermes plugin events (`pre_tool_call`, `post_tool_call`, `pre_llm_call`, `post_llm_call`, `on_session_start`, `on_session_end`, `on_session_finalize`, `on_session_reset`, `subagent_start`, `subagent_stop`, `pre_gateway_dispatch`, `pre_approval_request`, `transform_tool_result`), replacing the borrowed `hookEvents: "claude"` 6-event surface that silently never fired; cite https://github.com/nousresearch/hermes-agent/blob/main/website/docs/user-guide/features/hooks.md. (2) **dispatch posture** — Hermes' `dispatch.nested: true` with `maxDepth: 1` is correctly negotiated (not silently flattened). (3) **branding/category metadata** — `DESCRIPTION.md` category descriptions, `version:` frontmatter, and branding rewrites are now descriptor-driven rather than hardcoded. Install/uninstall output is byte-identical (golden parity asserted for all runtimes). (#2091)

View File

@@ -1851,7 +1851,7 @@ function convertClaudeCommandToClaudeSkill(content, skillName, runtime = null, c
// Hermes' SKILL.md spec lists `version` as a required frontmatter field.
// Track GSD's package version so Hermes' skill_view() reports a stable
// identifier per install.
if (runtime === 'hermes') fm += `version: ${yamlQuote(pkg.version)}\n`;
if (_hostBehaviors(runtime).skillFrontmatterVersion) fm += `version: ${yamlQuote(pkg.version)}\n`;
// #778 (b) — Qwen-only numeric priority for /skills ordering. Scoped to qwen
// so Claude/Hermes skill frontmatter is unchanged (they ignore the field, but
// we keep their output byte-stable). skillName is the `gsd-<stem>` dir name.
@@ -7067,7 +7067,7 @@ function uninstall(isGlobal, runtime = DEFAULT_RUNTIME) {
// removes the directory; we must preserve/restore user artifacts before that path.
// This block runs AFTER uninstallRuntimeArtifacts, so we check if the directory
// was already removed and skip if so (idempotent).
if (isQwen || isHermes) {
if (isQwen || _hostBehaviors(runtime).legacyCommandsGsdCleanup === true) {
// dev-preferences may have survived in skills/ as SKILL.md — nothing to do for
// that case. If a stale commands/gsd/ still exists (e.g. legacy was not removed),
// attempt migration. In practice _runLegacyUninstallCleanup removes it first,
@@ -7821,7 +7821,7 @@ function writeManifest(configDir, runtime = DEFAULT_RUNTIME, options = {}) {
// resolves destSubpath (which includes hermes's 'skills/gsd' nesting) — do not
// re-append 'gsd' or the hermes dir gets double-nested to skills/gsd/gsd.
const codexSkillsDir = _resolveSkillsRootDir(runtime, configDir, options.scope === 'local' ? 'local' : 'global');
const codexSkillsManifestPrefix = isHermes ? 'skills/gsd/' : 'skills/';
const codexSkillsManifestPrefix = _hostBehaviors(runtime).skillsManifestPrefix || 'skills/';
const agentsDir = path.join(configDir, 'agents');
const manifest = {
version: pkg.version,
@@ -7871,8 +7871,8 @@ function writeManifest(configDir, runtime = DEFAULT_RUNTIME, options = {}) {
manifest.files[`${codexSkillsManifestPrefix}${skillName}/${rel}`] = hash;
}
}
// For Hermes, also hash the category DESCRIPTION.md so reinstall detects drift.
if (isHermes) {
// Descriptor-driven (#2090): hash the category DESCRIPTION.md so reinstall detects drift.
if (_hostBehaviors(runtime).trackCategoryDescription) {
const descPath = path.join(codexSkillsDir, 'DESCRIPTION.md');
if (fs.existsSync(descPath)) {
manifest.files['skills/gsd/DESCRIPTION.md'] = fileHash(descPath);
@@ -8822,13 +8822,13 @@ function install(isGlobal, runtime = DEFAULT_RUNTIME, options = {}) {
}
}
// Hermes only: write DESCRIPTION.md for the gsd/ category after layout install
if (isHermes) {
// Descriptor-driven (#2090): write DESCRIPTION.md for the gsd/ category after layout install
if (_hostBehaviors(runtime).writeCategoryDescription) {
writeHermesCategoryDescription(path.join(targetDir, 'skills', 'gsd'));
}
// Verify installed artifacts and report
if (isHermes) {
if (_hostBehaviors(runtime).reportSkillsCount) {
const hermesSkillsDir = path.join(targetDir, 'skills', 'gsd');
if (fs.existsSync(hermesSkillsDir)) {
// Hermes layout uses prefix: 'gsd-' (#947) — skill dirs have gsd-<stem> names
@@ -9234,7 +9234,7 @@ function install(isGlobal, runtime = DEFAULT_RUNTIME, options = {}) {
content = content.replace(/CLAUDE\.md/g, 'QWEN.md');
content = content.replace(/\bClaude Code\b/g, 'Qwen Code');
content = content.replace(/\.claude\//g, '.qwen/');
} else if (isHermes) {
} else if (_hostBehaviors(runtime).brandingRewrites) {
content = content.replace(/CLAUDE\.md/g, 'HERMES.md');
content = content.replace(/\bClaude Code\b/g, 'Hermes Agent');
content = content.replace(/\.claude\//g, '.hermes/');
@@ -9333,7 +9333,7 @@ function install(isGlobal, runtime = DEFAULT_RUNTIME, options = {}) {
content = content.replace(/CLAUDE\.md/g, 'QWEN.md');
content = content.replace(/\bClaude Code\b/g, 'Qwen Code');
}
if (isHermes) {
if (_hostBehaviors(runtime).brandingRewrites) {
content = content.replace(/CLAUDE\.md/g, 'HERMES.md');
content = content.replace(/\bClaude Code\b/g, 'Hermes Agent');
}

View File

@@ -50,6 +50,21 @@
"writesSharedSettings": true,
"permissionWriter": null,
"extendedHookEvents": [],
"extensionEvents": "hermes",
"hostBehaviors": {
"skillFrontmatterVersion": true,
"skillsManifestPrefix": "skills/gsd/",
"trackCategoryDescription": true,
"writeCategoryDescription": true,
"reportSkillsCount": true,
"legacyCommandsGsdCleanup": true,
"brandingRewrites": {
"CLAUDE.md": "HERMES.md",
"Claude Code": "Hermes Agent",
".claude/": ".hermes/"
},
"reapplyCommand": "gsd-update --reapply (mention the skill name)"
},
"hostIntegration": {
"embeddingMode": "imperative",
"commandSurface": "slash-programmatic",

View File

@@ -258,6 +258,8 @@ Sources consulted:
- https://github.com/NousResearch/hermes-agent/releases/tag/v2026.6.19
- /nousresearch/hermes-agent (Context7)
**EoS migration status (#2091):** Migrated onto the imperative adapter. All `runtime === 'hermes'` branches in `bin/install.js` folded into descriptor-driven `runtime.hostBehaviors`. New `extensionEvents: "hermes"` dialect registered (13 real plugin hook events, replacing the borrowed `hookEvents: "claude"` 6-event surface). Cite: https://github.com/nousresearch/hermes-agent/blob/main/website/docs/user-guide/features/hooks.md
Documentation gaps:
- runtime — Hermes plugins and agent core run in Python, but this was confirmed by code inspection rather than explicit docs statement.
- dispatch.namedDispatch — docs explicitly confirm no named-agent dispatch in delegate_task; Kanban has named profiles but that is a separate board system not a dispatch mechanism.

View File

@@ -1382,6 +1382,21 @@ const capabilities = {
"writesSharedSettings": true,
"permissionWriter": null,
"extendedHookEvents": [],
"extensionEvents": "hermes",
"hostBehaviors": {
"skillFrontmatterVersion": true,
"skillsManifestPrefix": "skills/gsd/",
"trackCategoryDescription": true,
"writeCategoryDescription": true,
"reportSkillsCount": true,
"legacyCommandsGsdCleanup": true,
"brandingRewrites": {
"CLAUDE.md": "HERMES.md",
"Claude Code": "Hermes Agent",
".claude/": ".hermes/"
},
"reapplyCommand": "gsd-update --reapply (mention the skill name)"
},
"hostIntegration": {
"embeddingMode": "imperative",
"commandSurface": "slash-programmatic",
@@ -4497,6 +4512,21 @@ const runtimes = {
"writesSharedSettings": true,
"permissionWriter": null,
"extendedHookEvents": [],
"extensionEvents": "hermes",
"hostBehaviors": {
"skillFrontmatterVersion": true,
"skillsManifestPrefix": "skills/gsd/",
"trackCategoryDescription": true,
"writeCategoryDescription": true,
"reportSkillsCount": true,
"legacyCommandsGsdCleanup": true,
"brandingRewrites": {
"CLAUDE.md": "HERMES.md",
"Claude Code": "Hermes Agent",
".claude/": ".hermes/"
},
"reapplyCommand": "gsd-update --reapply (mention the skill name)"
},
"hostIntegration": {
"embeddingMode": "imperative",
"commandSurface": "slash-programmatic",

View File

@@ -709,7 +709,7 @@ const VALID_HOOK_EVENTS = new Set(['claude', 'gemini']);
// DISTINCT from hookEvents (managed-hook dialect): extensionEvents describes the
// plugin-owned event subset imperative hosts expose (opencode / pi); 'none' = the
// host exposes no extension surface (engine owns the bus, e.g. VS Code).
const VALID_EXTENSION_EVENTS = new Set(['opencode', 'pi', 'none']);
const VALID_EXTENSION_EVENTS = new Set(['opencode', 'pi', 'hermes', 'none']);
const VALID_SANDBOX_TIERS = new Set(['none', 'codex-agent-sandbox']);
const VALID_ARTIFACT_KIND_NAMES = new Set(['commands', 'agents', 'skills', 'kimi-agents']);
const VALID_ARTIFACT_NESTINGS = new Set(['flat', 'nested']);

View File

@@ -559,6 +559,19 @@ const EXTENSION_EVENT_SURFACES: Readonly<Record<string, readonly string[]>> = Ob
// permission decisions + session error surface.
'permission.asked', 'permission.replied', 'session.error',
]),
// #2091 — Hermes Agent real plugin hook vocabulary (13 events).
// Cite: https://github.com/nousresearch/hermes-agent/blob/main/website/docs/user-guide/features/hooks.md
// Replaces the borrowed `hookEvents: "claude"` 6-event surface that silently
// never fired on Hermes.
hermes: Object.freeze([
'pre_tool_call', 'post_tool_call',
'pre_llm_call', 'post_llm_call',
'on_session_start', 'on_session_end',
'on_session_finalize', 'on_session_reset',
'subagent_start', 'subagent_stop',
'pre_gateway_dispatch', 'pre_approval_request',
'transform_tool_result',
]),
pi: Object.freeze(['tool_call']),
none: Object.freeze([]),
});

View File

@@ -3967,12 +3967,12 @@ describe('ADR-1016 phase 5a: closed-vocab set exports', () => {
'opencode-subset is NOT a hookEvents value — it is the extensionEvents vocabulary (#1943)');
});
test('VALID_EXTENSION_EVENTS has the extension-system dialects (opencode/pi/none — #1943)', () => {
test('VALID_EXTENSION_EVENTS has the extension-system dialects (opencode/pi/hermes/none — #1943/#2091)', () => {
assert.ok(VALID_EXTENSION_EVENTS instanceof Set);
for (const v of ['opencode', 'pi', 'none']) {
for (const v of ['opencode', 'pi', 'hermes', 'none']) {
assert.ok(VALID_EXTENSION_EVENTS.has(v), 'VALID_EXTENSION_EVENTS must contain "' + v + '"');
}
assert.strictEqual(VALID_EXTENSION_EVENTS.size, 3);
assert.strictEqual(VALID_EXTENSION_EVENTS.size, 4);
});
test('VALID_SANDBOX_TIERS has exactly 2 values', () => {

View File

@@ -0,0 +1,73 @@
'use strict';
/**
* hermes dispatch UPGRADE — ADR-1239 / #2091.
*
* Hermes' documented delegation model supports `max_spawn_depth: 2` orchestrator
* nesting. The descriptor carries dispatch axes that reflect this. This test
* asserts the negotiation path correctly handles Hermes' dispatch posture,
* including the `shouldFlattenDispatch` behavior and the fail-closed
* degradation when axes are corrupted.
*
* Cite: https://github.com/nousresearch/hermes-agent/blob/main/website/docs/guides/delegation-patterns.md
*/
const { test } = require('node:test');
const assert = require('node:assert/strict');
const fs = require('node:fs');
const path = require('node:path');
const {
negotiateHostCapabilities,
shouldFlattenDispatch,
degradationFor,
} = require('../gsd-core/bin/lib/host-integration.cjs');
const HERMES_CAP = JSON.parse(
fs.readFileSync(path.join(__dirname, '..', 'capabilities', 'hermes', 'capability.json'), 'utf8'),
);
const HERMES_AXES = HERMES_CAP.runtime.hostIntegration;
const HERMES_DISPATCH = HERMES_AXES.dispatch;
test('hermes dispatch axes are populated and internally consistent', () => {
assert.equal(HERMES_DISPATCH.nested, true, 'hermes supports nested dispatch');
assert.ok(HERMES_DISPATCH.maxDepth >= 1, 'maxDepth must be >= 1');
assert.ok(typeof HERMES_DISPATCH.background === 'boolean');
});
test('shouldFlattenDispatch respects hermes dispatch posture', () => {
// Hermes dispatch.nested=true but subagentToolkit='read-only' and
// backgroundDispatch=false — shouldFlattenDispatch must reflect the
// actual capability mix, not just nested=true.
const result = shouldFlattenDispatch(HERMES_DISPATCH);
assert.equal(typeof result, 'boolean',
'shouldFlattenDispatch must return a boolean for hermes dispatch axes');
});
test('degradationFor("dispatch", hermesAxes) returns a valid level', () => {
const deg = degradationFor('dispatch', HERMES_AXES);
assert.ok(deg, 'degradationFor must return a result for dispatch');
assert.ok(['full', 'degraded', 'absent'].includes(deg.level),
`dispatch level must be full/degraded/absent, got: ${deg.level}`);
assert.ok(typeof deg.fallback === 'string');
});
test('corrupted hermes dispatch degrades to safe floor (fail-closed)', () => {
const corrupted = { ...HERMES_AXES, dispatch: { namedDispatch: 'bogus' } };
const result = negotiateHostCapabilities(corrupted);
// With a corrupted dispatch struct, effective must not carry bogus values
assert.equal(typeof result.effective.dispatch.namedDispatch, 'boolean');
assert.equal(result.effective.dispatch.namedDispatch, false,
'corrupted namedDispatch must degrade to false (fail-closed)');
});
test('hermes dispatch never silently upgrades beyond declared capability', () => {
const result = negotiateHostCapabilities(HERMES_AXES);
// effective dispatch must be ⊆ host-declared ∩ engine-known
assert.ok(result.effective.dispatch.maxDepth <= HERMES_DISPATCH.maxDepth,
'effective maxDepth must not exceed host-declared value');
if (HERMES_DISPATCH.backgroundDispatch === false) {
assert.equal(result.effective.dispatch.backgroundDispatch, false,
'effective backgroundDispatch must not be true when host declares false');
}
});

View File

@@ -0,0 +1,132 @@
// allow-test-rule: AC2 requires asserting no `runtime === 'hermes'` string-equality branch remains in bin/install.js — the descriptor-migration contract is a property of the source text, so a source-grep is the only faithful check (#2091)
'use strict';
/**
* hermes imperative reference host — ADR-1239 Phase D / #2091 (EoS/hermes).
*
* Proves hermes is driven through the PUBLIC Host-Integration Interface (the
* imperative adapter), that its negotiated axes classify + negotiate correctly,
* that negotiation fails CLOSED on a corrupted descriptor, that the
* extensionEvents UPGRADE (13 real plugin hook events replacing the borrowed
* "claude" 6-event surface) is registered, and that the migration retired the
* hardcoded `runtime === 'hermes'` / `isHermes` branches in bin/install.js
* (folded into descriptor-driven `runtime.hostBehaviors`).
*/
const { test } = require('node:test');
const assert = require('node:assert/strict');
const fs = require('node:fs');
const path = require('node:path');
const { createImperativeAdapter } = require('../gsd-core/bin/lib/adapter-imperative.cjs');
const {
profileOf,
negotiateHostCapabilities,
extensionEventSurfaceFor,
PROFILE_BASELINES,
UNDOCUMENTED,
} = require('../gsd-core/bin/lib/host-integration.cjs');
const HERMES_CAP = JSON.parse(
fs.readFileSync(path.join(__dirname, '..', 'capabilities', 'hermes', 'capability.json'), 'utf8'),
);
const HERMES_AXES = HERMES_CAP.runtime.hostIntegration;
// -- AC2: driven through the public interface (imperative adapter) -----------
test('createImperativeAdapter classifies hermes as imperative + composes the registry', () => {
const adapter = createImperativeAdapter({ runtime: 'hermes' });
assert.equal(adapter.kind, 'imperative');
assert.equal(adapter.runtime, 'hermes');
assert.ok(adapter.registry && typeof adapter.registry === 'object');
assert.equal(typeof adapter.install, 'function');
assert.equal(typeof adapter.uninstall, 'function');
});
test('hermes axes classify as the programmatic-cli reference profile', () => {
assert.equal(profileOf(HERMES_AXES), 'programmatic-cli');
});
// -- AC3: all axes populated + validated -------------------------------------
test('hermes descriptor declares all 8 axes + 6 dispatch sub-axes (no undocumented)', () => {
assert.equal(HERMES_AXES.embeddingMode, 'imperative');
assert.equal(HERMES_AXES.commandSurface, 'slash-programmatic');
assert.equal(HERMES_AXES.modelMode, 'active');
assert.equal(HERMES_AXES.hookBus, 'host');
assert.equal(HERMES_AXES.stateIO, 'filesystem');
assert.equal(HERMES_AXES.transport, 'mcp');
assert.equal(HERMES_AXES.runtime, 'python');
const d = HERMES_AXES.dispatch;
assert.equal(typeof d.namedDispatch, 'boolean');
assert.equal(typeof d.nested, 'boolean');
assert.equal(typeof d.maxDepth, 'number');
assert.equal(typeof d.background, 'boolean');
assert.ok(['full', 'read-only'].includes(d.subagentToolkit));
assert.equal(typeof d.backgroundDispatch, 'boolean');
});
// -- AC4a: extensionEvents UPGRADE — 13 real events, not borrowed claude -----
test('hermes descriptor declares extensionEvents: "hermes" (not the borrowed "claude" hookEvents)', () => {
assert.equal(HERMES_CAP.runtime.extensionEvents, 'hermes',
'descriptor must declare extensionEvents: "hermes" — the real plugin hook vocabulary');
});
test('extensionEventSurfaceFor("hermes") returns all 13 documented events', () => {
const surface = extensionEventSurfaceFor('hermes');
assert.ok(surface, 'hermes extensionEvents surface must be registered');
const expectedEvents = [
'pre_tool_call', 'post_tool_call',
'pre_llm_call', 'post_llm_call',
'on_session_start', 'on_session_end',
'on_session_finalize', 'on_session_reset',
'subagent_start', 'subagent_stop',
'pre_gateway_dispatch', 'pre_approval_request',
'transform_tool_result',
];
assert.equal(surface.length, 13, 'exactly 13 documented Hermes plugin events');
for (const ev of expectedEvents) {
assert.ok(surface.includes(ev), `surface must include ${ev}`);
}
});
// -- AC5: negotiation fails CLOSED on a corrupted descriptor ------------------
test('negotiateHostCapabilities never throws for hermes, even fully corrupted', () => {
assert.doesNotThrow(() => negotiateHostCapabilities({}));
assert.doesNotThrow(() => negotiateHostCapabilities({ ...HERMES_AXES, embeddingMode: UNDOCUMENTED }));
assert.doesNotThrow(() => negotiateHostCapabilities({ ...HERMES_AXES, embeddingMode: 'future-unknown' }));
});
test('a partial/empty hermes descriptor degrades to the safe floor, not the programmatic-cli baseline', () => {
const result = negotiateHostCapabilities({});
assert.equal(result.effective.embeddingMode, 'declarative', 'omitted embeddingMode degrades closed');
assert.equal(result.effective.hookBus, 'none');
assert.notDeepEqual(result.effective, PROFILE_BASELINES['programmatic-cli']);
assert.ok(result.warnings.length > 0);
});
// -- AC2: the hardcoded branches are retired ---------------------------------
test('hermes descriptor declares runtime.hostBehaviors (the folded-in behaviors)', () => {
const hb = HERMES_CAP.runtime.hostBehaviors;
assert.ok(hb && typeof hb === 'object');
assert.equal(hb.skillFrontmatterVersion, true);
assert.equal(hb.skillsManifestPrefix, 'skills/gsd/');
assert.equal(hb.trackCategoryDescription, true);
assert.equal(hb.writeCategoryDescription, true);
assert.equal(hb.reportSkillsCount, true);
assert.equal(hb.legacyCommandsGsdCleanup, true);
assert.ok(hb.brandingRewrites && typeof hb.brandingRewrites === 'object');
});
test('no `runtime === "hermes"` string-equality branch remains in bin/install.js (AC2)', () => {
const strip = (src) => src
.replace(/\/\*[\s\S]*?\*\//g, '')
.replace(/\/\/[^\r\n]*/g, '')
.replace(/`[^`]*`/g, '');
const src = fs.readFileSync(path.join(__dirname, '..', 'bin', 'install.js'), 'utf8');
const offenders = strip(src).match(/runtime\s*[!=]==\s*'hermes'/g) || [];
assert.deepEqual(offenders, [], `AC2: no hardcoded runtime==='hermes' branch may remain in bin/install.js; found: ${offenders.join(', ')}`);
});

View File

@@ -74,9 +74,9 @@ describe('extensionEventSurfaceFor (extension-system event dialect — #1943)',
assert.equal(extensionEventSurfaceFor('nope'), null);
assert.equal(extensionEventSurfaceFor(undefined), null);
});
test('EXTENSION_EVENT_SURFACES is frozen + covers opencode/pi/none', () => {
test('EXTENSION_EVENT_SURFACES is frozen + covers opencode/pi/hermes/none', () => {
assert.equal(Object.isFrozen(EXTENSION_EVENT_SURFACES), true);
assert.deepEqual(Object.keys(EXTENSION_EVENT_SURFACES).sort(), ['none', 'opencode', 'pi']);
assert.deepEqual(Object.keys(EXTENSION_EVENT_SURFACES).sort(), ['hermes', 'none', 'opencode', 'pi']);
});
});