Hermes Atlas
Security & sandboxing

HermesClaw

TheAiSingularity/hermesclaw

Run Hermes Agent inside NVIDIA OpenShell with enforced network, filesystem and syscall limits

In short

HermesClaw is a community implementation that runs Hermes Agent inside NVIDIA OpenShell, so kernel-level policies limit its network egress, filesystem access and system calls while the agent keeps its memory and gateway stack.

What HermesClaw does

OpenShell intercepts every call to inference.local inside the sandbox and routes it to the configured backend, so Hermes does not know it is sandboxed. The README lists the enforcement layers: network egress limited to approved hosts through OPA and an HTTP CONNECT proxy, filesystem access limited to ~/.hermes/, /sandbox/ and /tmp/ through Landlock, and blocked syscalls such as ptrace, mount and kexec_load through Seccomp BPF. An inference privacy router is the fourth layer.

The one-command installer pulls a prebuilt multi-arch image (linux/amd64 and linux/arm64) from GitHub Container Registry, clones the repo to ~/.hermesclaw and links the hermesclaw CLI. Model weights and a llama-server on the host are set up by hand, with --ctx-size 32768 recommended because Hermes's system prompt alone is about 11k tokens. The CLI includes hermesclaw start with policy options such as strict (the default) and gateway, plus hermesclaw chat and hermesclaw doctor.

Key features

  • Network egress limited to approved hosts through OPA and an HTTP CONNECT proxy
  • Landlock filesystem limits to ~/.hermes/, /sandbox/ and /tmp/
  • Seccomp BPF blocking of syscalls such as ptrace and mount
  • Prebuilt multi-arch container image from GitHub Container Registry
  • hermesclaw CLI with start, chat and doctor commands

When to use it

  • Running third-party skills with hard limits on what they can reach
  • Keeping a self-hosted Hermes gateway restricted to approved network hosts
  • Running Hermes against a local GGUF model such as Qwen3 4B through llama-server

Who it is for: Self-hosters who want Hermes Agent contained by operating-system level policy rather than trust alone.

How it fits with Hermes Agent

Built around Hermes Agent: it runs the full Hermes stack, including memory and gateway, inside the OpenShell sandbox.

How to install HermesClaw

These commands are copied from the project's README. Check the repository for the latest steps before you run them.

curl -fsSL https://raw.githubusercontent.com/TheAiSingularity/hermesclaw/main/scripts/install.sh | bash

Requirements: docker, git and curl with Docker running; full OpenShell enforcement also needs Linux, an NVIDIA GPU and OpenShell installed

Note: Full sandbox enforcement needs Linux, an NVIDIA GPU and OpenShell, which requires an NVIDIA account, and HermesClaw is a community implementation.

FAQ

What is HermesClaw?

HermesClaw runs Hermes Agent inside NVIDIA OpenShell, a sandbox that enforces network, filesystem and syscall policy at the kernel level. The README calls it a community implementation.

Does HermesClaw work with Hermes Agent?

Yes, it is built specifically to sandbox Hermes Agent. The agent keeps its full memory and gateway stack while the OS enforces the limits.

How do I install HermesClaw?

Run the install script from the repository, which pulls the prebuilt image and sets up the hermesclaw CLI. Three manual steps follow: download a GGUF model, start llama-server on the host, then run docker compose up -d in ~/.hermesclaw.

Similar security for Hermes Agent

All security

Related guides: How to run Hermes Agent securely