hermes-agent/hermes_cli/subcommands
ethernet c375b9c28a feat(desktop): gate uninstall actions on install provenance
The uninstall flow now reads the install stamp to learn who owns the
code. Three install kinds exist:

- standard (git checkout from the installer or 'hermes desktop'):
  keeps the full gui/lite/full flow.
- bundled (embedded payload): the app can only remove user data. The
  embedded CPython runs the uninstall module. The OS removes the app
  (Apps & Features / Trash / delete the AppImage).
- nix: the app can only remove user data. The UI shows 'managed by
  Nix' guidance instead of code-removal options.

A new mode 'data' (hermes uninstall --data) removes ~/.hermes user
data and the Electron userData dir, and keeps all code. This mode is
valid on every install kind.

The Python uninstaller enforces the same rule on its own: it reads
.hermes_build_info.json through runtime_tree and refuses the
code-removal modes on sealed trees, with instructions from the
steward. The renderer cannot make a managed install delete code.

loadInstallStamp now accepts a stamp with commit:null. A dirty Nix
build writes such a stamp, and the provenance fields must survive.
2026-08-10 11:21:49 -04:00
..
__init__.py
…
_shared.py
…
acp.py
…
approvals.py feat(cli): add `hermes approvals test` — dry-run approval verdict CLI 2026-08-07 08:57:39 -07:00
auth.py
…
backup.py
…
claw.py
…
config.py
…
console.py
…
cron.py feat(cron): per-job durable notepad — KV scratchpad surviving scheduled runs 2026-08-07 08:57:48 -07:00
dashboard.py
…
debug.py
…
doctor.py feat(doctor): add opt-in `hermes doctor --live` real-call backend probes 2026-08-07 09:07:48 -07:00
dump.py
…
gateway.py
…
gui.py
…
hooks.py
…
import_agent.py
…
import_cmd.py
…
insights.py
…
login.py
…
logout.py
…
logs.py
…
mcp.py
…
memory.py
…
model.py
…
monitoring.py
…
pairing.py fix(pairing): keep GUI approvals off the code brute-force lockout 2026-07-29 17:51:40 -05:00
pause.py feat(cli): global emergency stop — `hermes pause` / `hermes resume` 2026-08-07 08:58:14 -07:00
plugins.py feat(plugins): load portable agent components 2026-08-07 09:44:21 -07:00
profile.py
…
prompt_size.py
…
security.py
…
setup.py
…
skills.py
…
skin.py
…
slack.py
…
status.py
…
sync.py
…
tools.py
…
uninstall.py feat(desktop): gate uninstall actions on install provenance 2026-08-10 11:21:49 -04:00
update.py feat(update): install manifest, release channels, and eject 2026-08-10 02:34:50 -04:00
verify.py Port from superagent-ai/grok-cli: verify subsystem (run-recipe detection + environment manifest + hermes verify smoke runner) 2026-08-07 10:11:05 -07:00
version.py
…
webhook.py
…
whatsapp.py
…