Hermes Atlas
Security & sandboxing

IntentFrame for Hermes Agent

intentframe/agent-integrations

IntentFrame security plugin that checks Hermes terminal, code, file and cron tool calls against policy

In short

IntentFrame for Hermes Agent is a security plugin that puts an external policy checkpoint in front of Hermes tools that can touch your machine. Each governed call is judged ALLOW or BLOCK before it runs, and blocked calls are logged.

What IntentFrame for Hermes Agent does

IntentFrame is a separate policy runtime, not part of the agent. This repository holds its integration layer, with Hermes Agent as the first integration. The Hermes plugin catches selected tool calls before Hermes runs them, an adapter translates the action into an IntentFrame check, and an IntentFrame backend returns ALLOW or BLOCK against rules you write outside the agent. Hermes proposes, IntentFrame judges, and only an ALLOW lets the action run.

Out of the box it governs terminal, execute_code, write_file, patch and cronjob; every other Hermes tool runs untouched. The installer starts a Control Plane web UI at http://127.0.0.1:9720 where you configure keys, start the enforcement stack, choose governed tools, load policy and read audit logs, with CLI commands as an alternative. The README gives example probes, such as sudo echo test and writes under /etc, that are expected to be blocked. It works without forking Hermes or rewriting its tools.

Key features

  • Governs terminal, execute_code, write_file, patch and cronjob by default
  • External ALLOW or BLOCK decision from policy you write outside the agent
  • Blocked actions are logged with an audit trail
  • Control Plane web UI at 127.0.0.1:9720 for keys, tools, policy and audit logs
  • CLI commands to install, start, stop, choose governed tools and update policy
  • No fork of Hermes and no change to its tools

When to use it

  • Stopping a hijacked or confused Hermes agent from running privileged shell commands
  • Blocking file writes outside allowed paths or reads of ~/.hermes/.env
  • Reviewing an audit log of what the agent tried to do

Who it is for: Hermes Agent users who run the agent on a real machine and want policy enforcement that sits outside the agent process.

How it fits with Hermes Agent

Built as a Hermes Agent plugin that hooks into tool calls, with a note that the same integration layer is meant to be agent-agnostic.

How to install IntentFrame for Hermes Agent

These commands are copied from the project's README. Check the repository for the latest steps before you run them.

curl -fsSL https://github.com/intentframe/agent-integrations/raw/main/scripts/install-hermes-plugin.sh | bash

FAQ

What is IntentFrame for Hermes Agent?

It is a security plugin that checks Hermes terminal, code, file-write and cron tool calls against policy before they run. A separate IntentFrame runtime decides ALLOW or BLOCK.

How do I install IntentFrame for Hermes Agent?

Run the install-hermes-plugin.sh script with curl, as shown in the README. No git clone is needed. The installer starts the Control Plane at http://127.0.0.1:9720.

Is IntentFrame for Hermes Agent free and open source?

Yes. The repository is released under the Apache-2.0 license.

Similar security for Hermes Agent

All security

Related guides: How to run Hermes Agent securely