Omahub
← All plugins
M

Hermes

by Mustafa Okur

Hermes usage, limits, and pace in a native Omarchy bar panel, with optional desktop install, launch, and theme sync.

Security review

No obvious issues detected

Deterministic scan — not a security guarantee

None
Risk level
None
Analyzed commit
5c287ed
Scanned
1 month ago

No potentially dangerous behavior detected in the analyzed commit.

Automated analysis only — not a security guarantee.

AI advisory review

Review recommended

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
review
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
5c287ed
Reviewed
1 month ago

The deterministic scan found nothing, and manual review found no obfuscation, destructive install steps, or hidden exfiltration. The plugin does handle gateway credentials and reuses Hermes Desktop OAuth cookies, and the optional helpers write desktop entries/theme plugins, but these behaviors are documented and user-invoked. Low risk, though the credential-handling scripts warrant a quick human look before publishing.

  • bin/omarchy-agent-meter reads Hermes Desktop's OAuth cookie database and writes rotated tokens back, and stores gateway credentials in ~/.config/omarchy/agent-meter.json (mode 0600); sensitive but not malicious.
  • bin/omarchy-agent-usage-hermes executes Python code from the Hermes installation (LABEL_HELPER) with the Hermes runtime as cwd; this is local and only runs against an already-installed Hermes, but is worth a human glance.
  • bin/omarchy-theme-set-hermes and bin/omarchy-install-ai-hermes write files into ~/.hermes and ~/.local/share/applications and can launch Hermes; these are optional helpers that only run when explicitly invoked.
  • No network activity beyond the configured gateway, no destructive commands, and no hidden persistence were found.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/okurmustafa/omarchy-hermes --enable
Widgets #bar #quickshell #ai

Hermes

An Omarchy bar widget for Hermes token usage: last seven days, top models, and a local / remote gateway source switch.

The panel is display-only. Collectors in bin/ write one JSON record to ~/.local/state/omarchy/agents/usage/hermes.json. The widget watches that file. If you are already signed into Hermes Desktop on a remote gateway, the meter reuses that session instead of asking for a second login.

<p align="center"> <img src="assets/screenshot-usage.png" alt="Hermes usage panel: tokens by day and by model" width="420"> <img src="assets/screenshot-source.png" alt="Hermes usage source: This Computer or Remote Gateway" width="420"> </p>

Install

omarchy plugin add https://github.com/okurmustafa/omarchy-hermes.git --enable

The widget lands on the right of the bar. Move it with:

omarchy bar move mustafaokur.hermes --section right

The panel runs its collectors from the plugin folder. You do not need to put bin/ on your PATH. Doing so can shadow Omarchy’s own omarchy-agent-usage-update.

Usage

  • Left click: open or close the panel
  • Right click: refresh now
  • Middle click: next provider (only if more than one record is present)
  • Escape: close
  • R: refresh
  • Arrow keys: move between providers when more than one is listed
  • Tab: hand off to the neighboring bar panel

Usage source

  • This Computer — read Hermes’ local SQLite ledger (~/.hermes/state.db)
  • Remote Gateway — read account-wide analytics over HTTP. If Hermes Desktop is already signed in to that gateway, that session is used. Otherwise enter the URL, username, and password. Credentials go over stdin; the saved config and cookie jar are mode 0600.

Summon without the bar:

omarchy-shell shell summon mustafaokur.hermes '{}'
omarchy-shell shell hide mustafaokur.hermes

Optional CLI helpers

These live in the plugin’s bin/ directory and are not wired as panel buttons. Run them from that folder (or copy only the ones you want, under a name that does not collide with Omarchy):

  • omarchy-install-ai-hermes — if Hermes is already installed, add the Omarchy desktop entry and theme sync. If it is not, prints where to get Hermes and exits. This plugin never downloads or runs an installer.
  • omarchy-launch-hermes — focus an open Hermes window, or launch it.
  • omarchy-theme-set-hermes — write Omarchy palettes into Hermes CLI/TUI and Desktop. Only runs when you invoke it.

Configure

Refresh interval and optional cross-device sync are in the Omarchy settings panel (barWidget.schema).

Remove

omarchy plugin remove mustafaokur.hermes

That deletes the plugin folder. It does not remove:

  • ~/.config/omarchy/agent-meter.json
  • ~/.local/state/omarchy/agents/usage/hermes.json
  • Hermes themes or the desktop entry created if you ran the optional integration helper

Dependencies & privileges

  • Omarchy shell — Quattro bar-widget
  • Local usage — read-only access to ~/.hermes/state.db (and named-profile databases). No paid model calls. No network.
  • Remote gateway — HTTP(S) to session and analytics endpoints only. No prompt or response content is stored. When a Hermes Desktop OAuth session is reused, the meter reads that cookie database and writes rotated tokens back so the desktop app stays signed in.
  • Hermes — install Hermes yourself from hermes-agent.nousresearch.com. The plugin will not fetch or execute an installer.
  • Python 3 — the meter is stdlib-only (urllib, sqlite3, http.cookiejar)

Attribution

  • Panel structure follows Omarchy’s first-party Agents widget (MIT, David Heinemeier Hansson / Omarchy).
  • The portrait mark is traced from the official Hermes Desktop icon (MIT, Nous Research).

License

MIT — see LICENSE.