Hermes Atlas
Security & sandboxing

Hermes Jev Approvals

anpicasso/hermes-jev-approvals

Plugin that serves TypeSafe's Jev model as the reviewer for Hermes Agent smart command approvals

In short

Hermes Jev Approvals is a Hermes Agent plugin that replaces the reviewer behind smart command approvals with TypeSafe's Jev decision model, and it serves the auxiliary approval task only.

What Hermes Jev Approvals does

When approvals.mode is smart, Hermes asks an auxiliary model to return APPROVE, DENY or ESCALATE for commands that need review. This plugin swaps in Jev as that reviewer. One request puts six typed questions to Jev in parallel: a verdict, whether the operator policy allows the command, blast radius on a 0 to 2 scale, and probabilities that the command argues for its own approval, reads secrets or sends content outbound.

The final verdict is deterministic code layered on those answers. A command that argues for its own approval is escalated, and one that both reads secrets and sends data out is denied. Malformed or missing answers raise an error, which makes Hermes escalate to the user. A policy in approvals.smart_policy describes routine operations that should not interrupt you. Besides TypeSafe, the README documents an OpenRouter route and a free anonymous OpenCode Zen model. The author reports 8.7x faster reviews and 4.4x fewer prompts across 153 real commands.

Key features

  • Serves auxiliary.approval for approvals.mode: smart without changing Hermes core
  • Six typed questions per command, combined by deterministic rules
  • Operator policy in approvals.smart_policy for routine versus protected actions
  • Alternate routes through OpenRouter or the OpenCode Zen free model
  • Fails safe: malformed answers make Hermes ask the user

When to use it

  • Cutting approval prompts for routine commands such as clearing caches or git work on feature branches
  • Blocking commands that read credentials and send them outbound
  • Keeping force-pushes and production changes under human review

Who it is for: Hermes Agent users who run smart approvals and want fewer interruptions without giving up review of risky commands.

How it fits with Hermes Agent

A plugin for Hermes Agent that works with Hermes core as shipped and registers no hooks.

How to install Hermes Jev Approvals

These commands are copied from the project's README. Check the repository for the latest steps before you run them.

hermes plugins install anpicasso/hermes-jev-approvals/plugin
hermes auth add typesafe-jev
hermes config set approvals.mode smart
hermes config set auxiliary.approval.provider typesafe-jev

Requirements: Hermes Agent with approvals.mode set to smart and a typesafe-jev credential added with hermes auth add

Note: It handles command approvals only and cannot be used for chat or text generation.

FAQ

What is Hermes Jev Approvals?

Hermes Jev Approvals is a plugin that lets TypeSafe's Jev model act as the reviewer for Hermes Agent smart command approvals. It returns typed probabilities that deterministic code turns into APPROVE, DENY or ESCALATE.

Can I use Hermes Jev Approvals as a chat model?

No. It serves the approval task only, cannot chat or generate text, and refuses every other task.

How do I install Hermes Jev Approvals?

Run hermes plugins install anpicasso/hermes-jev-approvals/plugin, add the credential with hermes auth add typesafe-jev, and set approvals.mode to smart. Then set auxiliary.approval to provider typesafe-jev with model jev-latest and restart the gateway. Plugins are profile-scoped, so repeat for each HERMES_HOME.

Similar security for Hermes Agent

All security

Related guides: How to run Hermes Agent securely