Omahub
← All plugins
C

Hermes Harness

by Cody

Native Omarchy status and launch surface for a user-local Hermes installation.

Security review

No obvious issues detected

Deterministic scan — not a security guarantee

None
Risk level
None
Analyzed commit
2d72688
Scanned
1 month ago

No potentially dangerous behavior detected in the analyzed commit.

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
2d72688
Reviewed
1 month ago

This is a read-only status widget that runs bounded subprocesses to query Hermes, systemctl, and config files. It performs no writes, no network access, and no privileged operations. The scripts are carefully constrained with timeouts and output limits, and the QML only displays data.

  • Executes external binaries (hermes, hermes-node, systemctl) from PATH, which could be influenced by a compromised environment, but this is standard for desktop plugins.
  • Reads user-local config and state files, but only specific fields and with descriptor-safe, size-limited reads.
  • No persistence, no writes, no network, and no privilege escalation.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/archer-clawbot/omarchy-hermes-harness --enable
Widgets #bar #quickshell #ai

Hermes Harness for Omarchy

Hermes Harness is a user-local Quattro shell plugin for Omarchy. It adds a native bar indicator and panel showing:

  • Hermes installed state and version
  • gateway state
  • active model
  • current session
  • federated node summary when hermes-node is available
  • an Open Hermes action

The plugin is deliberately read-only. It does not install Hermes, alter gateway services, modify privileged interfaces, or change package-managed Omarchy files.

Requirements

  • Omarchy 4.x / current Quattro plugin runtime
  • Python 3
  • jq
  • Hermes is optional; the panel reports when it is unavailable
  • hermes-node is optional; federation disappears gracefully when unavailable

Install

Install from the public repository and enable the widget:

omarchy plugin add https://github.com/archer-clawbot/omarchy-hermes-harness.git --enable

The widget defaults to the right bar section. Left-click opens the panel, middle-click refreshes, and right-click opens Hermes.

Local development

The repository directory must match the manifest ID:

~/.config/omarchy/plugins/io.github.archer-clawbot.hermes-harness

Saved changes hot-reload. Force discovery with omarchy-shell shell rescanPlugins when needed.

Data sources

scripts/hermes-status reads the existing Omarchy Hermes usage record when available, then refreshes non-secret status from the installed hermes, the user gateway service, and hermes-node. Its I/O guard permits only bounded, descriptor-pinned regular-file reads and caps subprocess output before materialization. It never writes Hermes state.

Documentation

  • Architecture — component boundaries and runtime flow
  • Security — permissions, trust boundaries, and non-goals
  • Telemetry — status schema, sources, precedence, and freshness
  • Troubleshooting — validation and recovery procedures
  • Agent skill — bounded instructions for operating and maintaining this plugin

These documents cover the marketplace plugin itself. They do not install or document a privileged broker, Polkit policy, desktop-control bridge, distributed-job system, or package-managed Omarchy modification.

Removal

omarchy plugin remove io.github.archer-clawbot.hermes-harness

No system rollback is necessary.