Skip to main content

Hermes Blind

Recover the original goal of a long Claude Code or Codex session—and add evidence constraints to evaluation prompts.

PyPI Python CI License: MIT Status: experimental

Long agent sessions can lose the shape of the request that started them. Hermes Blind reads the first user turn from a local Claude Code or Codex JSONL log and writes a compact recovery anchor you can inspect and paste back into the session. It also provides a small prompt wrapper for evaluations that asks the model to disclose prior exposure, quote its evidence, and hedge when the evidence is thin.

The package is deterministic, dependency-free at runtime, and local: it makes no model calls and sends no network requests.

Install

For the isolated command-line app:

pipx install hermes-blind

Or install it into your current Python environment:

python -m pip install hermes-blind

Requires Python 3.10+.

Recover a long agent session

The lowest-friction path is to give your coding agent this instruction:

Install hermes-blind. Find the JSONL log for this Claude Code or Codex session, then run hermes-blind apply --session <path> --format auto --turn <current-turn-number> --out recovery.md. Show me the generated anchor and use it to restate my original goals before continuing. Do not overwrite files or share the session text.

Or run it directly:

hermes-blind apply \
  --session /path/to/session.jsonl \
  --format auto \
  --turn 9 \
  --out recovery.md

The generated markdown starts like this:

# Recovery scaffold (anchor-extracted from turn 1, applied at turn 9)

## Original anchor
- stated_goal: "Ship the onboarding flow and verify the clean install"

## Session state
- session file: rollout.jsonl
- user turns observed: 9

--format auto recognizes Claude Code and Codex JSONL shapes. The default goals mode preserves up to 12 goal-carrying sentences from the first user turn; first-sentence keeps the compact legacy behavior and full includes up to 4,000 characters.

The --turn value is only a label in the output. Hermes Blind does not detect drift or decide when recovery is needed. Existing output files are preserved unless --force is explicit, and the input session file can never be used as the output path.

Recovery files include user-authored text. Inspect them before sharing.

Re-anchor a Hermes Agent session at a chosen turn

Hermes Agent's pre_llm_call shell-hook contract can inject a recovery anchor without writing the conversation to another file. Choose the turn explicitly in ~/.hermes/config.yaml:

hooks:
  pre_llm_call:
    - command: "hermes-blind hermes-agent-hook --at-turn 9"
      timeout: 5

Hermes Agent asks for consent the first time it runs a shell hook. At the selected turn, Blind reads the hook payload on stdin and returns a compact context block on stdout. On other turns, malformed input, or an unsupported payload it returns an empty object and the agent proceeds unchanged.

The turn is a user-chosen intervention point, not a detected drift event or an efficacy threshold. The injected anchor is ephemeral and may contain text from the first user turn; do not treat it as a security boundary.

Machine-readable result envelope

The same extraction can be emitted as a Hermes Reliability Lab result envelope — the markdown scaffold embedded verbatim, plus the facts it was rendered from, tool version, a hash of the exact input bytes, one finding per thing worth knowing, the exit code, a timestamp, and the Git commit when run from a checkout:

python -m hermes_blind.evidence --session /path/to/session.jsonl --format auto

Extraction is unchanged; what is added is observability. Lines that do not parse are counted and reported (input.unparseable-lines) instead of only being skipped; two user turns before the first assistant reply are reported (input.ambiguous-initial-turn) and turn 1 is still the anchor; a file with no user turn is the product's own error, exit 1, with no anchor invented. The session path is always explicit — nothing is discovered under your home directory — and it appears in the record by basename only.

Add evidence constraints to an evaluation prompt

From the CLI:

hermes-blind apply \
  --variant v1 \
  --prompt "Score this release from quoted evidence."

This prints a wrapped prompt without calling a model:

[HERMES-BLIND]
If you have prior exposure to this target or its author, state it in one line.
Score using only quoted evidence from the target text below.
Unknown or thin evidence = hedge; do not confabulate.
[/HERMES-BLIND]

Score this release from quoted evidence.

Or use the Python API:

from hermes_blind import wrap

prompt = wrap(
    "Rate this paper on novelty from 0 to 10 and cite the target text.",
    variant="v1",
)

Available variants are null, micro, short, v1, full, placebo, and gate-only. The null variant is an exact no-op for controlled comparisons. The package also exposes the dependency-free intent and scope preambles used by Hermes Rubric.

Evidence and limits

The repository tests and CI cover deterministic wrapping, Claude Code and Codex JSONL parsing, recovery modes, safe output handling, package installation, and CLI invocation.

A frozen nine-session extraction audit found that the default goal-set anchor represented 40 of 66 pre-listed goals, compared with 7 of 66 for the earlier first-sentence heuristic. That supports better mission representation in the generated artifact for the evaluated sessions. It does not establish that reinserting the artifact changes model behavior or improves task outcomes. See the evaluation report for the method, limitations, sanitized results, and receipt hashes.

Not established:

  • reliable bias reduction from the evaluation prefix;
  • successful behavioral recovery after inserting an anchor;
  • automatic drift detection or an optimal intervention turn;
  • adversarial prompt-injection resistance; or
  • non-English behavior.

Treat the output as a transparent scaffold for a human or agent to inspect, not as a security boundary or independent evaluator.

Development

python -m venv .venv
source .venv/bin/activate
python -m pip install -e ".[dev]"
ruff check src tests
pytest -q
python -m build
twine check dist/*

See the changelog for release history and the contribution guide for contribution guidance.

License

MIT. See the license.

Built by Hermes Labs.

Metadata

Release files for hermes-blind 0.2.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for hermes-blind 0.2.0
File Size Uploaded
hermes_blind-0.2.0.tar.gz 43.7 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for hermes-blind 0.2.0
File Interpreter ABI Platform
hermes_blind-0.2.0-py3-none-any.whl Python 3 none any Details

Total release size: 68.9 kB

Release files / hermes_blind-0.2.0.tar.gz

Download URL hermes_blind-0.2.0.tar.gz
Size 43.7 kB
Tags Source
SHA-256 checksum
How to use checksums
68920d26541b468c25eb48770dea082fac0b8d65d25a808098774356738bc572
BLAKE2b-256 checksum
How to use checksums
7b8da9100b923735d1794f3517c04e4fb979d64c02dcd69cf3e49c71b950bea4
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 7, 2026.

Transparency log

Release files / hermes_blind-0.2.0-py3-none-any.whl

Download URL hermes_blind-0.2.0-py3-none-any.whl
Size 25.2 kB
Tags Python 3
SHA-256 checksum
How to use checksums
2d5ae17dc96dc6c21f208b9f7c65b15640077933ce11c145904cdcfeef3c1ce3
BLAKE2b-256 checksum
How to use checksums
cd47b89a9443d21d47af045e8b5ce6be4491d3ccd7f41c4aee77c390e808e760
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 7, 2026.

Transparency log

Release history Release notifications | RSS feed

0.3.2

2 release files

0.3.0

2 release files

This release

0.2.0 This release

2 release files

0.1.5

2 release files

0.1.4

2 release files

0.1.3

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page