Skip to main content
Pre-release

This release is a pre-release and may not be stable for production use.

Atbash Hermes Plugin

Atbash guardrail plugin for Hermes Agent using the official Python SDK (atbash-sdk).

The plugin registers a Hermes pre_tool_call hook and asks Atbash for a verdict before a Hermes tool runs. If Atbash returns a blocking decision, the tool call is stopped before execution.

What It Does

  • Intercepts Hermes tool calls through pre_tool_call.
  • Sends the tool name, arguments, command-like payload, session metadata, and inferred action class to Atbash.
  • Blocks tool execution on BLOCK, DENY, REJECT, or DISALLOW; holds it for operator review on HOLD.
  • Persists learned Hermes tool classifications across sessions.

Install

Hermes manages its own Python environment. Install the plugin directly into it — do not use your system pip — on macOS and some Linux distros it will be blocked by the OS.

If you installed Hermes via the official install script (curl … | bash):

~/.hermes/hermes-agent/venv/bin/pip3 install atbash-hermes-plugin

If you installed Hermes via uv:

uv pip install --python ~/.hermes/hermes-agent/venv/bin/python atbash-hermes-plugin

To install the latest dev release, add --pre (pip) or --prerelease=allow (uv):

# pip
~/.hermes/hermes-agent/venv/bin/pip3 install --pre atbash-hermes-plugin

# uv
uv pip install --python ~/.hermes/hermes-agent/venv/bin/python --prerelease=allow atbash-hermes-plugin

No further activation step is needed — Hermes discovers the plugin automatically on next start.

Configure Atbash

The plugin needs an Atbash agent key. Configure either ATBASH_KEY_PATH or ATBASH_AGENT_PRIVKEY.

Recommended:

ATBASH_KEY_PATH=~/.config/atbash/guard-client-key

Alternative (paste the key JSON directly):

ATBASH_AGENT_PRIVKEY='{"pubkey":"...","privkey":"..."}'

Where To Set Environment Variables

Hermes loads environment variables from ~/.hermes/.env.

Create or edit that file:

nano ~/.hermes/.env

Add:

ATBASH_KEY_PATH=~/.config/atbash/guard-client-key
ATBASH_ENFORCE_DECISION=true
ATBASH_DEBUG=false
ATBASH_ORG_NAME=your-org-name

Restart Hermes after changing .env.

For a one-off terminal session, you can also export variables before starting Hermes:

export ATBASH_KEY_PATH="$HOME/.config/atbash/guard-client-key"
export ATBASH_ENFORCE_DECISION=true
export ATBASH_DEBUG=false
hermes

Optional Settings

# Override the Atbash API endpoint.
ATBASH_ENDPOINT=https://api.atbash.io

# Set to self-hosted when using your own judge endpoint. Self-hosted judges
# require ATBASH_JUDGE_VERIFY_PUBKEY so the SDK can verify signed responses.
ATBASH_JUDGE_ENDPOINT_POLICY=default
ATBASH_JUDGE_VERIFY_PUBKEY=

# Fail closed when Atbash cannot be reached. Default: true.
ATBASH_ENFORCE_DECISION=true

# Emit verbose plugin logs. Default: false.
ATBASH_DEBUG=false

# Resolve the Atbash organization subscription/network. This lets the SDK
# choose the public or private chain for that org.
ATBASH_ORG_NAME=your-org-name

# Override where learned Hermes tool classifications are saved.
ATBASH_TOOL_MAP_PATH=~/.config/atbash/hermes-tool-map.json

# HTTP request timeout in seconds for judge API calls. Default: 60.
# Raise this if you see "read operation timed out" errors on a slow endpoint.
ATBASH_REQUEST_TIMEOUT=60

Telemetry

The plugin initializes the Atbash Python SDK OpenTelemetry metrics with source="plugin:hermes", matching the pattern used by the OpenClaw plugin. Telemetry is best-effort and never blocks guard registration or tool execution.

The Python SDK telemetry opt-out is file-based. To disable telemetry, create:

mkdir -p ~/.config/atbash
printf '{"enabled": false}\n' > ~/.config/atbash/telemetry.json

Enable Or Check The Plugin

Hermes discovers the plugin automatically via Python entry points — no manual enable step is needed. Restarting Hermes after installation is sufficient.

To confirm the package is installed in the right environment:

~/.hermes/hermes-agent/venv/bin/pip3 show atbash-hermes-plugin

Verify It Is Working

Start Hermes and ask it to do something that uses a tool, such as creating a file or opening a website.

In another terminal, watch the Hermes log:

tail -f ~/.hermes/logs/agent.log | grep -i atbash

With ATBASH_DEBUG=true, you should see lines similar to:

[atbash-hermes-plugin] registered pre_tool_call hook
Atbash pre_tool_call enter tool=...
Atbash verdict tool=... verdict=ALLOW reason=...

If Atbash blocks a tool call, Hermes receives a blocking response before the tool executes.

Docker

When running Hermes in Docker, mount your Hermes data directory and put the Atbash key inside the mounted volume.

Example host layout:

~/.hermes/
  .env
  atbash/
    guard-client-key

Example ~/.hermes/.env for Docker:

ATBASH_KEY_PATH=/opt/data/atbash/guard-client-key
ATBASH_ENFORCE_DECISION=true
ATBASH_DEBUG=false
ATBASH_ORG_NAME=your-org-name

Run Hermes:

docker run --rm -it \
  -v ~/.hermes:/opt/data \
  nousresearch/hermes-agent

You can also pass variables directly:

docker run --rm -it \
  -v ~/.hermes:/opt/data \
  -e ATBASH_KEY_PATH=/opt/data/atbash/guard-client-key \
  -e ATBASH_ENFORCE_DECISION=true \
  -e ATBASH_DEBUG=false \
  -e ATBASH_ORG_NAME=your-org-name \
  nousresearch/hermes-agent

Tool Classification

Hermes tool names can vary by version, installed plugins, and enabled skills. The plugin ships with defaults for common tools and learns unseen tool names at runtime.

Learned mappings are saved to:

~/.config/atbash/hermes-tool-map.json

Set ATBASH_TOOL_MAP_PATH to override the location. The file persists across Hermes sessions.

Verdict Behavior

  • ALLOW: the tool proceeds.
  • HOLD: the tool is blocked with a review message.
  • BLOCK, DENY, REJECT, DISALLOW: the tool is blocked.
  • Atbash API error:
    • ATBASH_ENFORCE_DECISION=true: fail closed and block.
    • ATBASH_ENFORCE_DECISION=false: fail open and allow.

For HOLD, the user-facing block message is:

Action held for operator review. The agent will not be jailed — please approve or reject this request from the Atbash dashboard, then ask the agent to try again.
Reason: <original reason from judge>
Judgment ID: <held judgment id, when provided by the SDK>

After dashboard approval or rejection, the SDK can query held-action status with the judgment ID. The Hermes plugin blocks the original tool call and asks the user to retry after review, rather than automatically re-running the action.

Troubleshooting

If the plugin is not being picked up, confirm it is installed in the Hermes environment (not the system Python):

~/.hermes/hermes-agent/venv/bin/pip3 show atbash-hermes-plugin

If Atbash verdicts are not appearing in logs, enable debug mode by adding this to ~/.hermes/.env:

ATBASH_DEBUG=true

Then restart Hermes and watch in a second terminal:

tail -f ~/.hermes/logs/agent.log | grep -i atbash

If the plugin blocks everything with an unavailable-key or authentication error, check:

echo "$ATBASH_KEY_PATH"
test -f "$ATBASH_KEY_PATH" && echo "key file exists"

If using Docker, remember that paths inside the container are different from host paths. Prefer /opt/data/... paths for mounted Hermes data.

Metadata

Release files for atbash-hermes-plugin 0.4.8.dev0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for atbash-hermes-plugin 0.4.8.dev0
File Size Uploaded
atbash_hermes_plugin-0.4.8.dev0.tar.gz 24.4 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for atbash-hermes-plugin 0.4.8.dev0
File Interpreter ABI Platform
atbash_hermes_plugin-0.4.8.dev0-py3-none-any.whl Python 3 none any Details

Total release size: 42.0 kB

Release files / atbash_hermes_plugin-0.4.8.dev0.tar.gz

Download URL atbash_hermes_plugin-0.4.8.dev0.tar.gz
Size 24.4 kB
Tags Source
SHA-256 checksum
How to use checksums
3772423b3150c602d09ba2a98520926a2aa9f10801d0f610907fa7f4f7111b41
BLAKE2b-256 checksum
How to use checksums
da177173bfef74650e745b5ab9b74612aa4516907dbeea2418638c59328d3dd3
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.11.15

Release files / atbash_hermes_plugin-0.4.8.dev0-py3-none-any.whl

Download URL atbash_hermes_plugin-0.4.8.dev0-py3-none-any.whl
Size 17.5 kB
Tags Python 3
SHA-256 checksum
How to use checksums
a22156a452c3bc84fc22f32a36cf844b9e8e5825abca062cc805f7024d559a5d
BLAKE2b-256 checksum
How to use checksums
cc014c801762943c1adaaad8a44274802149c5844aa421e9e0e3b46451319471
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.11.15

Release history Release notifications | RSS feed

0.4.16

2 release files

0.4.15

2 release files

0.4.8

2 release files

This release

0.4.8.dev0 This release

2 release files

0.4.7

2 release files

0.4.6

2 release files

0.4.5

2 release files

0.1.8

2 release files

0.1.7

2 release files

0.1.6

2 release files

0.1.5

2 release files

0.1.4

2 release files

0.1.2

2 release files

0.1.1

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page