Poke Recipes (poke.com/docs/creating-recipes) let users share their whole
agent setup — automations + integrations + a starter prompt — as one
installable link. This ports the sharing half to Hermes as a CLI command
with a self-hosted, security-first design:
- hermes recipe export: bundles selected cron jobs, remote MCP servers,
skill references, and a starter prompt into one YAML file. All
credentials (headers/env/api keys) are stripped and recorded by NAME in
required_secrets; script-backed jobs and stdio MCP servers are refused.
- hermes recipe show <file|url>: preview without installing.
- hermes recipe install <file|url>: consent-first — full preview +
confirmation, cron jobs created PAUSED by default (--enable to opt in),
MCP servers merged without overwriting existing entries and validated
through the SSRF guard, skills suggested via the normal hub flow.
Zero model-tool footprint (CLI command + docs per the footprint ladder).
20 unit tests + E2E round-trip (export from one HERMES_HOME, install into
a fresh one; secret-leak assertion on the dumped YAML).