Hermes GPTv0.14.0 GitHub

v0.14.0 released • Local-first • Autopilot default off

Define the checks. Recover within bounds.

Hermes GPT v0.14.0 strengthens Autopilot with declared artifact size and digest checks, a durable delivery grace, and bounded recovery after confirmed deliverable failures. Flight Deck explains the evidence behind completion. Final Mission approval stays with the Owner.

SchedulingBounded parallel workReady MissionPlan nodes run concurrently within the configured limit, using existing placement, Work Contract, and delegation surfaces.
RecoveryEvidence-ledCompletion requires validated observed state. Transient retries and semantic replans are bounded; other failures stop for a human.
AuthorityDefault offAutopilot cannot approve or complete Missions and never dispatches beyond owner approval or budget boundaries.
Hermes GPT v0.14.0: an armored Hermes beside acceptance and bounded recovery panels

What v0.14.0 adds

Completion needs evidence. Recovery has limits.

Declare acceptance before dispatch. Accept late valid artifacts without duplicate work, recover confirmed failures within the existing allowance, and stop when evidence or authority is unresolved. Autopilot stays default off.

Declare acceptance

Optional artifact_requirements set minimum/maximum bytes and expected SHA-256 values before dispatch. Each isolated attempt carries the same immutable checks.

Recover confirmed defects

Successful execution with confirmed artifact failures receives a durable 30-second delivery grace. If defects remain and all other required checks pass, existing bounded replan recovery can proceed. Unreadable evidence, pending review, denied authority, and ambiguous cancellation remain unverified.

Understand completion

Read-only Flight Deck supervision shows check results, fixed artifact failure reasons, delivery grace, and pending validation. Size and integrity checks prove declared requirements; semantic quality still requires review.

01

MissionPlan Decomposition

hermes_plan_create/get/list/validate/decompose/review/node_transition/set_status: a deterministic, bounded decomposition DAG over a MissionSpec. Plan mutations touch only the isolated plan store and are read-only with respect to the Mission lifecycle.

02

Capability Manifest + Mission Ledger

hermes_capability_manifest folds the Fabric node registry, Fleet authority manifest, profile toolsets/skills, and provider manifests into one queryable index. hermes_mission_ledger is a merged, replayable, cursor-paginated event timeline. No mutation path exists.

03

Budget Envelope + Gated Hard-Block

hermes_budget_set/get/check/record: a per-mission spend envelope with a read-only budget_check evaluation surface. v0.12 adds the gated D3 enforcement rung: when the flags are armed, a crossing pauses the Mission through the existing transition, spools one fleet-attention interrupt, and records one budget_events break row.

04

Placement Scoring

hermes_placement_score/candidates/get/list: deterministic hard filters then soft scores over the derived capability index. Scoring is unchanged and still decision-only; would_assign is true only for a dispatch that actually happened under the v0.12 L2 gates, and real dispatch stays on the existing contract, fleet, and delegation authority surfaces.

05

Failure Semantics + Recovery Matrix

An 8-class taxonomy classifies an authoritative observation envelope and proposes the deterministic smallest-first recovery action, recorded on a controller_plan row. That classification surface stays decision-only; executing the proposed action is the separate, default-off v0.12 L2 rung.

06

Autopilot + Acceptance (v0.14)

A durable, default-off Mission worker schedules ready nodes through existing authority surfaces. v0.14 carries declared minimum/maximum artifact sizes and optional SHA-256 values into immutable Work Contracts. Rework preserves the requirements; final Mission approval remains Owner-only.

System Architecture

Schedule, observe, validate. Stop at approval.

Autopilot advances ready MissionPlan nodes through existing authority surfaces, then reconciles against durable observed state. It does not bypass Work Contracts, budgets, or owner approval.

v0.14.0Acceptance and recovery

Declared artifact size/digest checks, durable 30-second delivery grace, bounded recovery after confirmed artifact failures, and clear completion evidence in Flight Deck. Requirements survive rework unchanged. No new tools or authority; final Mission approval remains Owner-only.

01Client Request

ChatGPT, Codex, Cursor, Claude Desktop, or another trusted MCP client submits a bounded request to Hermes GPT.

02Observe

The controller observes authoritative mission, plan, delegation, and runner state through the derived capability manifest and mission ledger.

03Schedule + Validate

Ready nodes are dispatched within configured concurrency. Delegation reconciliation reads runner and Fabric records; Work Contract evidence must validate against observed state before a node completes.

04Approval Frontier

Approval and high-impact nodes are never dispatched or advanced. Autopilot waits for the owner, then resumes through existing authority surfaces; only Owner-gated approval can complete the Mission.

Interactive Sandbox

Operator safety gate simulator.

Explore the policy model without touching a real Hermes installation. The simulator mirrors dry-run-first behavior and Owner acknowledgment requirements.

1. Configure Environment Security Gates

dry_run

2. Select MCP Tool

ChatGPT (MCP client)

Connected to the Hermes GPT simulator. Pick a tool and policy posture, then run the request.

Hermes GPT (Streamable HTTP)
[SYSTEM] Server started on 127.0.0.1:7677
[SYSTEM] Private MCP path available
[WAITING] Waiting for incoming MCP requests...

Capabilities

Local-first control plane, now supervised.

vNext adds the controller layer without weakening the security and evidence invariants shipped in v0.6 through v0.9.

01

Operator and Owner Policy

Tiered authority from read_only through owner, with explicit direct mode, confirmation gates, and dry-run-first mutation.

02

Work Contracts

Completion is validated from observed state, including declared artifact sizes and optional expected digests. Changing or unreadable evidence remains unverified. Size and integrity checks do not replace semantic review.

03

Missions, Delegations + Live Events

v0.9 adds the first-class durable Mission runtime with Owner-gated final approval, unified delegation lineage, a durable event bus with a WebSocket stream, and runner-neutral job supervision.

04

Fabric Cross-Machine Execution

v0.8 Fabric: authenticated peers, capability-aware auto routing, hash-verified remote evidence and artifacts, and same-attempt reconciliation — with the coordinator authoritative.

05

OpenAI Secure MCP Tunnel + Bounded Export

Supported OpenAI products reach loopback Hermes GPT through an outbound-only private tunnel path, and hermes_export_file provides workspace-authorized binary transfer with denied-path enforcement and size caps.

06

Flight Deck + Connector Gate

Mission Control, event history, review evidence, diagnostics, recovery tools, and Fabric routing views keep long-running autonomy inspectable. v0.14 adds no tools: 137 with Autopilot disabled, 140 when enabled. Completion checks, fixed artifact failure reasons, delivery grace, and pending validation are visible through read-only supervision.

Install

Get Hermes GPT running.

Install from PyPI or run the current checkout. Keep the HTTP server on loopback unless you deliberately configure an authenticated private boundary.

Install latest public version
python -m pip install hermes-gpt==0.14.0

v0.14.0 is published on PyPI. Autopilot requires HERMES_GPT_AUTOPILOT=1 and the normal Operator policy gates. Read the setup guides.

Changelog

Source and release history.

v0.14.0 is available on GitHub and PyPI. These are independent distribution channels; verify each when updating.

v0.13.0Autopilot

A durable, default-off Mission scheduler with bounded parallel execution, observed-state validation, retries and replans, budget checks, and Owner approval frontiers. Autopilot uses existing authority surfaces and cannot approve or complete a Mission.

v0.12.0Gated Budget Hard-Block + Controller L2

vNext slice 2: budget D3 hard-block enforcement (pause through the existing transition, one fleet-attention interrupt for the delivery broker, one budget_events break row) and the controller L2 rung (at most one smallest recovery action per pass, dispatched through the existing authority surfaces, intent recorded before dispatch). Both are default-off behind per-call confirm plus a machine gate, direct-mode Operator policy, and per-mission flags — and byte-identical to v0.11.0 while unarmed. 137 tools; no new mutating surface by default.

v0.11.0Gemini Spark + MCP SDK 2 + Bot Chat

Opt-in Gemini Spark custom-app client profile (verified end-to-end), MCP Python SDK 2.x support with SDK 1 retained, profile-aware Bot Chat and session delivery, fleet loopback Agent Cards, and the post-v0.10 security remediation. 137 tools; no new mutating surface by default.

v0.10.0vNext — Supervised Mission Controller

MissionPlan decomposition DAGs, read-only capability-manifest and mission-ledger views, a dry-run budget envelope, placement scoring, an 8-class failure taxonomy with recovery matrix, and a shadow/observe controller with GREEN/YELLOW/RED telemetry. 27 new tools (137 total); none can mutate a Mission, dispatch, or approve.

v0.9.0Missions + Delegations + Live Events

First-class durable Missions with Owner-gated final approval, unified delegation lineage across runners, a durable live-event bus with WebSocket stream, runner-neutral job supervision, and the bounded Finance bridge.

v0.8.0Fabric

Authenticated cross-machine Swarm execution, capability-aware routing, remote evidence and artifact admission, restart/timeout/cancel reconciliation, write-ownership safeguards, and Fabric Flight Deck visibility. Passed fresh real two-machine G6 acceptance and independent review.

v0.7.0Flight Deck

Production review evidence, structured redacted event history, durable encrypted token storage, and restart-safe Swarm continuity.

v0.6.0Mission Control + Work Contracts + Swarms

Read-only operational views, observed-state completion validation, and bounded DAG orchestration with explicit ownership and human approval.

v0.5.0Two-Way Codex Bridge

Codex as MCP client plus policy-gated delegated Codex CLI work and review.