Skip to main content

synoi-hermes-guard

Python plugin for Nous Research's Hermes agent that consults the SynOI gateway before any tool call executes, translated to Hermes's tool-call extension API.

Status: Beta. The plugin, policy client, capability mapping, and receipt handling are implemented, with 40 passing unit tests. End-to-end tests against a live SynOI gateway exist but are skipped unless a gateway is reachable, so integration against a running deployment is not covered by the unit suite. The API may still change before 1.0.

Source is not yet public. See https://synoi.systems.

What you get

  • Real-time HITL gates on dangerous Hermes tool calls (rm -rf, kubectl delete, schema migrations, prod deploys, and so on)
  • Same risk policy the gateway already uses on the LLM-call side
  • Per-tenant policy, so different teams get different rules
  • Decision Receipts: every gated call audit-trailed by the gateway
  • SMS approval, dispatched by the gateway to the approver on file. SMS is the only approval channel implemented today; other surfaces are planned and not shipped
  • Capability mapping, so your Hermes tool names (bash_shell, code_executor) map to canonical capabilities (shell.command, code.execute) and your gateway policy stays portable across agent frameworks

Install

pip install synoi-hermes-guard

Requires a SynOI gateway to consult and a license key. See https://synoi.systems.

Configure

Environment variables (see synoi_hermes_guard/config.py):

Key Required Default Description
SYNOI_LICENSE_KEY yes none Your SynOI license
SYNOI_GATEWAY_URL no http://localhost:3000 Where the gateway runs
SYNOI_GUARD_MODE no permissive permissive (fail-open) or strict (fail-closed)
SYNOI_TENANT_ID no derived from license Tenant identifier
SYNOI_TOOL_CAPABILITY_MAP no identity Path to YAML / JSON mapping file
SYNOI_REQUEST_TIMEOUT_MS no 2000 HTTP timeout for the gateway check call
SYNOI_WORKFLOW_POLL_INTERVAL_MS no 1000 How often to poll for require_approval resolution
SYNOI_WORKFLOW_POLL_TIMEOUT_MS no 300000 Max wait for workflow resolution (5 min)

Capability mapping file

synoi-hermes-guard.tool-map.yml:

mappings:
  bash_shell:        shell.command
  code_executor:     code.execute
  web_browser:       web.fetch
  file_writer:       fs.write
  database_query:    db.read

Then point SYNOI_TOOL_CAPABILITY_MAP=./synoi-hermes-guard.tool-map.yml.

Canonical capability names are what the gateway policy is written against, so a policy authored once stays portable as more agent frameworks are added.

Failure modes

permissive (default): if the license is invalid, the gateway is unreachable, or it returns an error, the plugin allows the tool call and logs a warning. The customer's agent never silently hangs because of SynOI infrastructure problems.

strict: the same conditions block the tool. Required for compliance use cases where governance is mandatory.

Programmatic use

from synoi_hermes_guard import HermesGuardPlugin, GuardConfig

plugin = HermesGuardPlugin()

# In your Hermes agent's tool-call interceptor:
verdict = await plugin.before_tool_call(
    tool_name="bash_shell",
    tool_input={"command": "kubectl delete pod payments-7f8d"},
    agent_context={"thread_id": "...", "user_id": "..."},
)

if verdict.block:
    # Don't run the tool. Stamp verdict.reason into the agent transcript.
    raise RuntimeError(f"Hermes Guard blocked tool call: {verdict.reason}")
else:
    # Proceed. Stamp verdict.receipt_id into the conversation log for audit.
    pass

Every gated call resolves against the same gateway endpoint and produces a Decision Receipt, so the audit trail is uniform regardless of which agent framework made the call.

License

AGPL-3.0-or-later. See the LICENSE file included in this distribution.

Release files for synoi-hermes-guard 0.2.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for synoi-hermes-guard 0.2.1
File Size Uploaded
synoi_hermes_guard-0.2.1.tar.gz 22.7 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for synoi-hermes-guard 0.2.1
File Interpreter ABI Platform
synoi_hermes_guard-0.2.1-py3-none-any.whl Python 3 none any Details

Total release size: 41.0 kB

Release files / synoi_hermes_guard-0.2.1.tar.gz

Download URL synoi_hermes_guard-0.2.1.tar.gz
Size 22.7 kB
Tags Source
SHA-256 checksum
How to use checksums
717459bc0b019ecf9297ab67d50444a8998a2460275bc16bdbd32c11e17e31f2
BLAKE2b-256 checksum
How to use checksums
fb8b3a954f38d79247192a3c3c734b253dfe07ec045c9008faa58d869eadeb6f
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.5

Release files / synoi_hermes_guard-0.2.1-py3-none-any.whl

Download URL synoi_hermes_guard-0.2.1-py3-none-any.whl
Size 18.3 kB
Tags Python 3
SHA-256 checksum
How to use checksums
512bd7367c754b8a75473e9fd0d96e6b7b6763242623c2e817f7933f759fc7ae
BLAKE2b-256 checksum
How to use checksums
f32ca97d9ec88e07f495e850d36182d32df2b88cf835c63b611821bb1ee59821
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.5

Release history Release notifications | RSS feed

This release

0.2.1 This release

2 release files

0.2.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page