7 KiB
Hermes Agent — Field Operator Bridge for Research Stack
Status: Integration Proposal
Date: 2026-05-02
Version: 1.0.0-Phase0
Source: https://github.com/allaunthefox/hermes-agent
Lean Module: 0-Core-Formalism/lean/Semantics/Semantics/HermesAgentIntegration.lean
Core Thesis
Hermes Agent is the field-operator layer for Research Stack: a messenger, scheduler, skill runtime, and subagent launcher that can perform repeatable GCL/Warden workflows while remaining subordinate to Lean, receipts, and Warden promotion gates.
Hermes is not the brain. The canonical model, lawfulness filter, and proof authority remain in OTOM/GCL/Lean. Hermes sits outside the proof core, executing tasks that Lean delegates but never verifying its own outputs as truth.
Role Separation
| System | Role | Authority |
|---|---|---|
| Hermes | Observes, routes, schedules, executes | Workflow layer only |
| GCL | Classifies, compresses, binds | Coding-space authority |
| Lean | Verifies, proves, is source of truth | Proof authority |
| Warden | Promotes, holds, blocks | Promotion gate |
| ENE | Persists, distributes, syncs | Swarm substrate |
Warden-Safe Doctrine
Hermes may execute.
Hermes may remember.
Hermes may suggest.
Hermes may schedule.
Hermes may not promote without receipts.
Critical Rules
-
If Hermes skill writes or updates doctrine and no source/provenance/receipt boundary is emitted: mark
HOLD. -
If Hermes self-improvement modifies a skill used for promotion: require
SkillMutationReceipt+AdversarialTrial. -
All scheduled audit outputs default to
HOLDuntil external receipt validates them. -
Hermes is autopoietic at the workflow layer, not authoritative at the truth layer.
Integration Surfaces
| Hermes Feature | Research Stack Binding | Warden Boundary |
|---|---|---|
| Skills | Repeatable GCL procedures | Skill mutation must be receipted |
| Memory | Project/user continuity | Memory is context, not evidence |
| Cron | Scheduled audits | Scheduled output defaults to HOLD |
| Messaging Gateway | Remote command interface | High-risk commands require confirmation |
| Subagents | Parallel review/search/build jobs | Subagent agreement is not evidence |
| MCP | Connectors/tools surface | Tool output needs provenance |
| Terminal Backends | Local/SSH/Docker/Modal execution | Command allowlist + sandbox receipts |
| RL/Trajectories | Training data for workflow agents | Trajectory compression is not proof |
Command Surface
Hermes exposes these read-only and receipt-producing commands:
/run-gcl-audit → GCL classification audit
/summarize-receipts → Warden receipt ledger summary
/queue-deepseek-review → Adversarial review bundle assembler
/check-lean-sorries → Lean sorry scan + classification
/search-provenance → Provenance database search
/build-cff-entry → CFF citation entry generator
/warden-status → HOLD/BLOCK/CANDIDATE/REVIEWED report
/skill-run <name> → Execute named skill with receipt emission
Skill Specifications (Phase 1)
gcl-provenance-cff
- Task: Ingest DOI / article / source → create CFF entry → add Warden boundary
- Sources:
doi,article_metadata,provenance_db - Receipts Required:
sourceAudit,humanReview - Failure Modes:
missing_doi,malformed_cff,no_provenance
lean-sorry-audit
- Task: Scan Lean files → list sorry locations → classify gaps
- Sources:
0-Core-Formalism/lean/Semantics - Receipts Required:
leanBuild - Failure Modes:
build_failure,sorry_increase,missing_todo_comment
adapter-spec-writer
- Task: Turn source cluster into GCL bridge doc
- Sources:
source_cluster,gcl_schema - Receipts Required:
humanReview,deltaPhiAudit - Failure Modes:
missing_bind,no_cost_function,float_in_hotpath
deepseek-review-bundle
- Task: Collect docs → enforce adversarial convergence prompt → save artifact
- Sources:
review_docs,adversarial_prompt_template - Receipts Required:
adversarialTrial,humanReview - Failure Modes:
missing_convergence_prompt,artifact_too_large,no_receipt_emitted
warden-triage
- Task: Classify outputs as
HOLD/CANDIDATE/BLOCK/REVIEWED - Sources:
output_artifact,receipt_ledger - Receipts Required:
wardenEmission - Failure Modes:
missing_status,no_receipt_boundary,self_promotion_detected
Scheduled Audit Jobs (Phase 2)
Daily
- Check Lean build (
lake build) - Check sorry count (trend vs. baseline)
- Check uncommitted docs in
docs/gcl/ - Check CFF malformed entries
- Check provenance gaps
Weekly
- Run DeepSeek bundle lint
- Summarize new GCL docs
- Report Warden
HOLD/BLOCKitems - Check MMR divergence / attestation staleness
Promotion Phases
Phase 0 — Read-Only Bridge (Current)
- No writes, no autonomous mutation
- Hermes can: search docs, summarize Warden state, run read-only git status, list Lean sorries, assemble review bundles
- Output: this document +
HermesAgentIntegration.lean
Phase 1 — Receipt-Producing Skills
- Allow artifact creation, no promotion
- Every skill emits:
SkillRunReceipt+SourceReceipt+WardenStatus
Phase 2 — Scheduled Warden Jobs
- Cron-driven recurring audits
- All outputs default to
HOLD
Phase 3 — Controlled Write Authority
- Hermes may open PRs or commits
- Each commit must include: source boundary, Warden state, rollback path, no self-promotion
Prior Art
- Nous Research Hermes Agent: Self-improving agent with 4-layer memory, session lineage, FTS5 search, skill creation/patching, schema-versioned SQLite storage
- Awareness Date: 2026-04-05
- Clean Room Status: Independence confirmed for Research Stack's dual-storage SQLite + JSON, procedural/episodic separation, skill patch pattern, and prompt memory cap
- Adaptations from Hermes: Session lineage (
parent_session_id+ recursive CTE), FTS5 virtual table, pre-reset memory saving onEMERGENCYregret threshold, schema versioning, WAL mode with retry jitter - Record:
scratch/exploit_recovery/audit/sessions/prior-art-hermes-agent-nous-research-20260405.json
Lean Formalization
The integration boundary is formalized in HermesAgentIntegration.lean:
HermesCommand— inductive command surface (8 constructors)HermesSkill— skill specification with phase, receipts, failure modesHermesStatus— promotion state:HOLD/CANDIDATE/REVIEWED/BLOCKEDSkillRunReceipt— execution receipt convertible toReceiptCore.ReceiptcanPromote— gate function requiring receipt validationreadOnlyCannotPromote— theorem (proven) — Phase 0 skills never promotedefaultStatusIsHold— theorem (proven) — default status isHOLD
The One Rule
Hermes is autopoietic at the workflow layer, not authoritative at the truth layer.