Hermes Atlas
Security & sandboxing

HermesUltraCode

MahdiHedhli/HermesUltraCode

Hermes plugin that has a second-lab model review each task before a subagent starts writing code

In short

HermesUltraCode is a plugin for Hermes Agent that gates delegate_task. A reviewer on a different model lab can tighten a task or block it before any subagent starts, and every decision is written to an audit trail.

What HermesUltraCode does

HermesUltraCode wraps the moment Hermes hands a task to a subagent. The orchestrator's prompt goes to a reviewer that must run on a different model lab than the orchestrator, which is enforced at startup. The reviewer returns a structured verdict. It may append constraints or block the task, but it cannot rewrite it, so the dispatched prompt is the original text plus directives. The blast radius is classified in code, and the release decision is made in code rather than in chat.

It fails closed. A missing, late or garbled verdict blocks and escalates, and with no reviewer configured the gate blocks every delegate_task. Each dispatch writes one immutable, secret-redacted audit row, and UPDATE and DELETE are blocked at the database, with JSON and CSV export. You drive it with /ultracode or an UltraCode tab in hermes dashboard. The core uses only the standard library, and the README cites 208 offline tests.

Key features

  • Reviewer must run on a different model lab than the orchestrator, checked at startup
  • Tighten-only reviews: the reviewer can append constraints or block but never rewrite
  • Fails closed when a verdict is missing, late or garbled
  • Immutable, secret-redacted audit row for every dispatch with JSON and CSV export
  • UltraCode tab in hermes dashboard with plan and audit sub-views
  • Standard-library-only core with 208 offline tests

When to use it

  • Vetting subagent tasks before code is written in a multi-agent Hermes build
  • Keeping an evidence-style record of what each subagent was asked to do
  • Blocking risky delegations when a cross-lab reviewer disagrees

Who it is for: Hermes Agent users who delegate code work to subagents and want an independent review and audit trail first.

How it fits with Hermes Agent

Built as a Hermes Agent plugin that rides on the existing Hermes orchestrator and wraps the subagent dispatch boundary without replacing the agent runtime.

How to install HermesUltraCode

These commands are copied from the project's README. Check the repository for the latest steps before you run them.

hermes plugins install MahdiHedhli/HermesUltraCode
hermes plugins enable hermesultracode
hermes gateway restart

Requirements: Hermes Agent and a reviewer model configured in ~/.hermes/.env on a different lab than the orchestrator

Note: It fails closed until a reviewer is configured, so with no reviewer set it blocks every delegate_task.

FAQ

What is HermesUltraCode?

HermesUltraCode is a Hermes Agent plugin that reviews each delegated task with a model from a different lab before any subagent writes code. The reviewer can only tighten or block, and each decision is logged.

How do I install HermesUltraCode?

Run hermes plugins install MahdiHedhli/HermesUltraCode, configure a reviewer in ~/.hermes/.env, then run hermes plugins enable hermesultracode and hermes gateway restart. Use /ultracode to drive it.

Is HermesUltraCode free and open source?

GitHub reports the license as NOASSERTION, meaning it could not identify a standard license. Read the LICENSE file in the repository and confirm terms with the author before reuse.

Similar security for Hermes Agent

All security

Related guides: How to run Hermes Agent securely