Hermes Agent: What It Is and How It Works

Hermes Agent is Nous Research’s open-source, MIT-licensed AI agent: a terminal and desktop assistant that runs on your machine or a server, talks to you from Telegram, Slack and other chat apps, keeps its own memory and writes its own skills. How to install it, which models it runs, how memory and skills work, and how its safety model compares with coding agents such as OpenHands.

8 min read

Hermes Agent is an open-source AI agent from Nous Research. It is a general-purpose assistant rather than a coding tool first: it runs commands, edits files, browses the web, schedules jobs and delegates to subagents, and it can run on a laptop, a small server or a cloud sandbox while you talk to it from the terminal, a desktop app or a chat app such as Telegram or Slack. Its distinguishing idea is what Nous calls a learning loop: it keeps two small memory files about you and your environment, searches its own past conversations, and writes reusable skills after complex tasks. It is model-neutral, so you bring a provider, from Anthropic or OpenAI to a local model. Everything below is from the project’s own documentation as of September 30, 2026.

What it is, and who makes it

The Hermes Agent repository (opens in a new tab) describes it as “the self-improving AI agent built by Nous Research” and ships it under the MIT license. There are two ways to use it: a terminal interface, started with hermes, and a desktop app, Hermes Desktop. A single gateway process connects it to messaging platforms. The documentation lives at hermes-agent.nousresearch.com/docs. Nous Research also runs Nous Portal, a paid option that bundles models and tool access under one account; the agent itself works with any provider you configure.

Installing it

The installation guide (opens in a new tab) offers desktop packages for macOS (Apple Silicon only) and Windows, a command-line install for Linux, macOS and WSL2, a native Windows install in PowerShell, Docker, Nix, and an APT package for Termux on Android. The source installer brings its own pinned Python, Node.js, ripgrep and FFmpeg, and by default the browser and computer-use tools, which you can skip with --skip-browser and --skip-computer-use.

Install and first run (Linux, macOS, WSL2)
curl -fsSL https://hermes-agent.nousresearch.com/install.sh | bash
source ~/.bashrc      # or ~/.zshrc
hermes setup          # the full setup wizard
hermes model          # choose a provider and model
hermes                # start a conversation
hermes doctor         # diagnose problems

On Windows, the native install goes under %LOCALAPPDATA%\hermes; everywhere else your data lives in ~/.hermes, including config.yaml, memory, skills and a .env file for keys. Read an install script before piping it to a shell, as with any tool.

Models and providers

Hermes brings no model of its own. The providers page (opens in a new tab) lists a long catalog: Nous Portal, Anthropic, OpenAI, Codex models through a ChatGPT sign-in, GitHub Copilot, OpenRouter, xAI, Fireworks, Kimi, MiniMax and many more, plus self-hosted endpoints such as Ollama, LM Studio, vLLM and llama.cpp. You pick one with hermes model, and switch model mid-session with /model.

Local models need room. The docs say the system prompt and tool definitions alone take several thousand tokens, ask for a context window of at least 64K on local servers, and suggest trimming the toolset for small models. They also warn that small local models often claim to have saved a memory without calling the tool, so use a stronger model for setup.

Tools and toolsets

The built-in tools cover web search and page extraction, a terminal and file editing, browser automation, vision and image generation, a todo list, code execution, subagent delegation, memory, session search and scheduled jobs. They are grouped into toolsets such as web, terminal, file and browser, which you enable per platform with hermes tools, so the Telegram bot can have less than your terminal session.

Where commands run is a separate choice. The terminal tool has seven backends: local, the default, which runs on your machine; docker; ssh; singularity; modal; daytona; and vercel_sandbox. Hermes is also an MCP client, for local stdio servers and remote HTTP servers, with OAuth handled for you and per-server include and exclude lists so only the tools you want are registered. It reads project instructions too: .hermes.md, AGENTS.md, CLAUDE.md or .cursorrules, first match wins, plus a global SOUL.md for its personality.

Skills: procedural memory

The skills system (opens in a new tab) treats a skill as a knowledge document the agent loads only when it needs it: first a list of names and descriptions, then the full SKILL.md, then any reference file. Skills follow the agentskills.io open standard, live in ~/.hermes/skills/, and each becomes a slash command. A catalog of bundled skills is seeded at install, more come from the Skills Hub, and /learn turns a docs folder, a web page or a workflow you just walked through into a new one.

The part that makes Hermes different is the skill_manage tool. When the agent works out a non-trivial workflow, it saves the approach as a skill and can later patch or delete it. That is useful and worth watching: a skill the agent wrote shapes what it does next time. Hermes offers a write-approval gate for skill changes, and project-local skill folders are never rewritten by its automatic maintenance.

Memory

The memory documentation (opens in a new tab) describes two small files in ~/.hermes/memories/: MEMORY.md, the agent’s notes on your environment and conventions, capped at 2,200 characters, and USER.md, your preferences, capped at 1,375. Both are loaded into the system prompt as a frozen snapshot when a session starts, so a note saved mid-session appears in the next one. When memory is full the tool returns an error and the agent consolidates entries itself. Entries are scanned for prompt injection and exfiltration patterns before they are accepted.

  • Session search: every conversation is stored in a local SQLite database with full-text search, and the agent can look up what you discussed weeks ago.
  • Write approval: by default the agent saves memory freely. Set memory.write_approval: true and writes are confirmed inline in the CLI or held for /memory pending elsewhere.
  • Profiles: memory is per profile. The docs warn against pointing two agents at one Hermes home, and suggest an external memory provider, such as Honcho or Mem0, when agents need to share.
  • Session boundaries: a messaging chat is one continuous session until you run /new, so memory pays off only when you start fresh sessions.

The broader trade-offs of shared agent memory, and serving it over MCP, are in agent memory over MCP.

Messaging gateways and scheduled jobs

Run hermes gateway setup and hermes gateway start, and one background process connects Hermes to the platforms you configure: Telegram, Discord, Slack, WhatsApp, Signal, email, SMS, Microsoft Teams, Matrix, Mattermost, Home Assistant and more. The same process runs the built-in cron scheduler, so a job described in plain language, such as a daily report, runs unattended and delivers to any platform.

Safety and sandboxing

Hermes runs as your user by default, so its security model (opens in a new tab) matters. It is layered:

  • Command approval: commands matching dangerous patterns need approval. The default mode, smart, asks an auxiliary model to judge risk, auto-approving low-risk commands, auto-denying clearly dangerous ones and asking you about the rest. manual always asks; off, or --yolo, asks nothing.
  • A hardline blocklist that no flag overrides, plus your own approvals.deny patterns, which apply even in YOLO mode.
  • Unattended runs: cron, one-shot and webhook sessions deny dangerous commands by default, since nobody is there to approve.
  • Containers: in the Docker, Singularity, Modal, Daytona and Vercel Sandbox backends, dangerous-command checks are skipped because the container is the boundary. The local backend has no such boundary.
  • Gateway access: with no allowlist configured, every user is denied. Unknown users can get a one-time pairing code that you approve from the CLI.
  • Files and MCP: a denylist blocks writes to credential files, an optional safe root confines writes, and MCP subprocesses get a filtered environment.

The docs are candid about limits: the write denylist does not stop the terminal tool, which can still reach those files through the shell, and deny rules are “not a complete shell interpreter or an OS capability sandbox.” For real containment, use an isolated backend. The general risks of an agent with tools are in MCP security risks.

Hermes, coding agents and OpenHands

  • Focus: Hermes is a general assistant that also codes. Claude Code, Codex and OpenHands are built around a repository.
  • Where you talk to it: Hermes adds chat apps and scheduled jobs through its gateway. OpenHands centers on a browser control center, a CLI and an SDK.
  • Isolation by default: OpenHands recommends a Docker sandbox. Hermes defaults to the local backend with command approval, and treats containers as an option.
  • Memory: Hermes writes its own memory and skills as it goes. Most coding agents read instruction files you maintain, such as AGENTS.md, which Hermes reads too.
  • Models: both are model-neutral and open source.

Pick Hermes if you want one always-on assistant across your terminal and your phone. Pick a coding agent if the job is changes to a codebase with review. The wider field is in the best AI coding agents.

Giving Hermes a shared task list

Hermes’s memory is deliberately private and small, and it has a todo tool for its own plan. Neither is a list your team can see. fenbs is a task board where people and AI assistants are members with roles. Add it as a remote MCP server with OAuth and restrict it to the tools you want.

~/.hermes/config.yaml
mcp_servers:
  fenbs:
    url: "https://fenbs.ai/api/mcp"
    auth: oauth
    tools:
      include: [fenbs_whoami, fenbs_get_context, fenbs_list_items,
                fenbs_create_item, fenbs_update_item, fenbs_comment]
# then, from a fresh terminal:
# hermes mcp login fenbs

Hermes can then read the team’s rules from the Decisions and rules page and the AI context notes first, file features, enhancements and bugs with a note and a plan, move them through To Do, Next Up, In Progress and Completed, and record a test status. A cron job can post a daily summary of the board to Slack. History records every change under the assistant’s name, a browser sign-in gets hour-long tokens that refresh, and revoking in Settings ends its access. fenbs sets no tool annotations yet, and it has no due dates, sprints or assignee field.

Related

How remote servers sign in: MCP OAuth explained. Scoping an assistant: assistant tokens and scopes. Other open-source agents: OpenHands and Goose. Every fenbs tool: MCP docs.

Questions people ask.

Who makes Hermes Agent?

Nous Research. The code is in the NousResearch/hermes-agent repository under the MIT license, with documentation at hermes-agent.nousresearch.com.

Is Hermes Agent free?

The agent is open source and free to run. You pay for whatever model provider you connect, or nothing if you run a local model. Nous Portal is an optional paid service that bundles models and tools.

How does Hermes Agent memory work?

It keeps two small files, MEMORY.md for notes about your environment and USER.md for your preferences, loaded at the start of each session. It can also search all past sessions stored in a local SQLite database, and external memory providers can be added.

Is Hermes Agent safe to run on my computer?

By default it runs commands as your user, with dangerous commands gated by an approval system. For stronger isolation, use the Docker or another container backend, keep YOLO mode off, and configure allowlists before exposing it on a messaging platform.

Start with one thing.

There is nothing to set up first. Write one line and you’ve started.