hermes-agent/hermes_cli
Teknium 243a01d5d7 fix(curator): make the autonomous write policy consistent (#67140)
The background write guard decided ownership from `isinstance(usage_rec, dict)`,
so a local skill with NO usage record passed. That successful write called
bump_patch(), which created a `created_by: null` record — and the identical
write was refused from then on. "Allowed exactly once, then never" is a race
with our own bookkeeping, not a policy. Reproduced on main: patch #1 succeeds,
patch #2 with the same arguments is refused.

Option B from the issue. Option A (split `session_review` from
`scheduled_curator` and let the session fork patch user-owned skills it
consulted) would widen autonomous write permission onto skills the user owns
with no user present to consent — wrong direction for a no-user-present actor.

- skill_manager_tool: missing and explicit-null records now resolve
  IDENTICALLY, both fail closed. The refusal names the reason and points at
  `hermes curator adopt <name>`.
- background_review: both review prompts told the reviewer to patch any skill
  consulted in the session and claimed pinned skills could be improved, while
  enforcement refused both. Prompts now list pinned, external, and user-owned
  skills as protected, and tell the reviewer to RECOMMEND adoption instead of
  attempting a write that will be refused.
- skill_usage: document that `created_by` is a curator-management policy flag,
  not a provenance claim, and add `is_curator_managed()` so call sites read as
  the question they ask. Field name retained — it is on disk in every
  `.usage.json` and renaming would strand those records.
- curator CLI: `hermes curator list-unmanaged` itemizes unmanaged skills with
  the reason each is unmanaged (completes the #67139 spec).

Foreground writes are untouched: a user-directed edit to a user-owned skill
still works, including on pinned skills.

Sibling tests: 9 failures in test_skill_manager_tool.py were fixtures that
created record-less skills to exercise OTHER guards (consolidation-delete,
read-before-write) and relied on ownership falling through. Fixed at the
fixture, since the real curator only ever operates on managed sediment. One
test asserted the old "manually authored" wording; rewritten to assert the
behavior contract instead of the string.

Validation: 274 targeted tests + all 7 background-review files (60 tests) pass.
E2E on a temp HERMES_HOME (30 checks) covers the flip, foreground writes,
adoption unblocking, pin semantics, prompt/enforcement parity, and the new verb.
Each new test sabotage-verified: revert the fix, confirm it goes red.

Fixes #67140
2026-07-25 19:27:17 -07:00
..
dashboard_auth fix(dashboard): add lightweight /api/health liveness endpoint 2026-07-24 19:43:44 -05:00
proxy
…
subcommands
…
__init__.py
…
_early_recovery.py fix(ssl): detect and repair a missing certifi cacert.pem via existing venv-repair infra 2026-07-24 15:53:38 -07:00
_parser.py
…
_subprocess_compat.py
…
active_sessions.py
…
auth.py fix(cli): add explicit encoding to read_text/write_text calls 2026-07-24 17:10:39 -07:00
auth_commands.py
…
azure_detect.py
…
backup.py fix(state): cross-process quarantine lock + oversized DB pruning suppression (#68805) 2026-07-24 23:06:05 -07:00
banner.py fix(cli): add explicit encoding to read_text/write_text calls 2026-07-24 17:10:39 -07:00
blueprint_cmd.py
…
browser_connect.py
…
build_info.py
…
bundles.py
…
callbacks.py
…
checkpoints.py fix(checkpoints): bind an empty orphan preview to an empty deletion allowlist 2026-07-24 16:01:06 -07:00
claw.py fix: add explicit UTF-8 encoding to all subprocess text=True calls (#53428) 2026-07-24 11:45:57 -07:00
cli_agent_setup_mixin.py
…
cli_billing_mixin.py
…
cli_commands_mixin.py feat(relay): Phase 1 parity — supported_ops discovery, wire identity fields, /handoff aliasing, provision displayName (#71300) 2026-07-25 20:36:16 +10:00
cli_output.py
…
clipboard.py fix: add explicit UTF-8 encoding to all subprocess text=True calls (#53428) 2026-07-24 11:45:57 -07:00
codex_models.py
…
codex_runtime_plugin_migration.py
…
codex_runtime_switch.py
…
colors.py
…
commands.py fix: repair sweep fallout — duplicate encoding kwargs, non-subprocess call sites, kwarg-snapshot tests 2026-07-24 11:45:57 -07:00
completion.py
…
config.py feat(aux): force streaming for providers that reject non-stream requests 2026-07-25 14:58:04 -07:00
console_engine.py
…
container_boot.py fix: add encoding="utf-8" to Path.write_text() calls (P1) 2026-07-24 17:10:39 -07:00
context_switch_guard.py
…
copilot_auth.py fix: add explicit UTF-8 encoding to all subprocess text=True calls (#53428) 2026-07-24 11:45:57 -07:00
credential_lifecycle.py
…
cron.py fix(cron): preserve jobs.json ownership on root rewrite + surface failing-tick reason 2026-07-24 15:52:13 -07:00
curator.py fix(curator): make the autonomous write policy consistent (#67140) 2026-07-25 19:27:17 -07:00
curses_ui.py
…
dashboard_register.py
…
debug.py
…
default_soul.py
…
dep_ensure.py
…
diagnostics_upload.py
…
dingtalk_auth.py
…
doctor.py fix(cli): add explicit encoding to read_text/write_text calls 2026-07-24 17:10:39 -07:00
dump.py fix: add explicit UTF-8 encoding to all subprocess text=True calls (#53428) 2026-07-24 11:45:57 -07:00
env_loader.py fix(config): preserve opaque .env values 2026-07-24 16:02:08 -07:00
fallback_cmd.py
…
fallback_config.py
…
gateway.py fix(windows): sweep remaining bare read_text/write_text sites + linter rule 2026-07-24 17:10:39 -07:00
gateway_enroll.py
…
gateway_windows.py fix: repair sweep fallout — duplicate encoding kwargs, non-subprocess call sites, kwarg-snapshot tests 2026-07-24 11:45:57 -07:00
goals.py
…
gui_uninstall.py
…
hooks.py
…
input_sanitize.py
…
inventory.py fix(api-server): expose model options inventory 2026-07-24 11:20:07 -07:00
journey.py
…
kanban.py
…
kanban_db.py fix: add explicit UTF-8 encoding to all subprocess text=True calls (#53428) 2026-07-24 11:45:57 -07:00
kanban_decompose.py
…
kanban_diagnostics.py
…
kanban_specify.py
…
kanban_swarm.py
…
logs.py
…
main.py fix(sessions): point failed in-place repair at offline recovery 2026-07-25 16:42:31 -07:00
managed_scope.py
…
managed_uv.py fix(managed-uv): don't retry patches at or below the installed version 2026-07-25 16:42:49 -07:00
mcp_catalog.py
…
mcp_config.py
…
mcp_picker.py
…
mcp_security.py
…
mcp_startup.py
…
memory_oauth.py
…
memory_setup.py fix(memory-setup): sanitize .env values in the core writer too 2026-07-24 13:00:53 +05:30
middleware.py
…
migrate.py
…
moa_cmd.py
…
moa_config.py feat(moa): default advisor fanout to user_turn — the cheapest cadence 2026-07-23 21:07:18 -07:00
model_catalog.py
…
model_cost_guard.py
…
model_normalize.py
…
model_setup_flows.py fix(cli): store custom endpoint API key in .env instead of config.yaml 2026-07-24 21:12:53 -05:00
model_switch.py fix(models): resolve custom provider model ids 2026-07-24 21:24:36 -05:00
models.py feat(models): add anthropic/claude-opus-5 to OpenRouter and Nous Portal catalogs 2026-07-24 13:00:15 -07:00
nous_account.py
…
nous_auth_keepalive.py
…
nous_billing.py
…
nous_subscription.py
…
onepassword_secrets_cli.py fix: extend UTF-8 encoding to _op_version probe (#53428) 2026-07-24 11:45:57 -07:00
oneshot.py
…
pairing.py
…
partial_compress.py
…
pets.py
…
platforms.py
…
plugins.py fix(windows): sweep remaining bare read_text/write_text sites + linter rule 2026-07-24 17:10:39 -07:00
plugins_cmd.py fix: add explicit UTF-8 encoding to all subprocess text=True calls (#53428) 2026-07-24 11:45:57 -07:00
portal_cli.py
…
profile_describer.py
…
profile_distribution.py
…
profiles.py fix: add encoding="utf-8" to Path.write_text() calls (P1) 2026-07-24 17:10:39 -07:00
projects_cmd.py
…
projects_db.py
…
prompt_size.py
…
provider_catalog.py
…
providers.py
…
proxy_cli.py Reapply "Merge pull request #30179 from NousResearch/feat/iron-proxy" 2026-07-24 09:49:00 -07:00
psutil_android.py
…
pt_input_extras.py
…
pty_bridge.py
…
pty_session.py
…
relaunch.py
…
route_identity.py
…
runtime_provider.py fix(tui_gateway): recover custom provider identity from the session's model name 2026-07-24 10:47:32 -07:00
secret_prompt.py
…
secrets_cli.py fix: add explicit UTF-8 encoding to all subprocess text=True calls (#53428) 2026-07-24 11:45:57 -07:00
security_advisories.py
…
security_audit.py
…
security_audit_startup.py
…
send_cmd.py
…
service_manager.py fix: add encoding="utf-8" to Path.write_text() calls (P1) 2026-07-24 17:10:39 -07:00
session_export.py
…
session_export_html.py
…
session_export_md.py
…
session_filters.py
…
session_listing.py
…
session_recap.py
…
session_recovery.py fix(sessions): add offline state database recovery 2026-07-25 16:42:31 -07:00
setup.py fix(windows): sweep remaining unguarded text-mode subprocess sites codebase-wide 2026-07-24 11:45:57 -07:00
setup_whatsapp_cloud.py
…
skills_config.py
…
skills_hub.py
…
skin_cmd.py
…
skin_engine.py
…
slack_cli.py
…
sqlite_runtime.py fix(runtime): repair vulnerable managed SQLite builds (E-949) 2026-07-24 16:00:03 -07:00
sqlite_util.py
…
status.py
…
stdio.py
…
suggestions_cmd.py
…
telegram_managed_bot.py
…
timeouts.py
…
tips.py
…
tools_config.py fix(windows): sweep remaining unguarded text-mode subprocess sites codebase-wide 2026-07-24 11:45:57 -07:00
toolset_validation.py
…
uninstall.py fix: add encoding="utf-8" to Path.write_text() calls (P1) 2026-07-24 17:10:39 -07:00
urllib_security.py
…
voice.py
…
web_git.py fix: add explicit UTF-8 encoding to all subprocess text=True calls (#53428) 2026-07-24 11:45:57 -07:00
web_server.py Merge pull request #71141 from NousResearch/bb/custom-endpoint-keys-and-models 2026-07-24 22:09:53 -05:00
webhook.py fix: repair sweep fallout — duplicate encoding kwargs, non-subprocess call sites, kwarg-snapshot tests 2026-07-24 11:45:57 -07:00
win_pty_bridge.py
…
windows_ssh_runtime.py fix(windows): sweep remaining unguarded text-mode subprocess sites codebase-wide 2026-07-24 11:45:57 -07:00
write_approval_commands.py
…
xai_retirement.py
…