General-purpose agent

Hermes Agent

Persistent open agent with coding tools, durable automation, and isolated runtimes.

Status
Active
License
MIT
Evidence
Documented + code-verifiable, 25 sources
Product record checked
2026-07-27

At a glance

An MIT-licensed general agent with terminal, desktop, web, API, and messaging surfaces; persistent memory and goals; coding and browser tools; nested parallel delegation; scheduled jobs; MCP; checkpoints; and local, container, SSH, or managed execution backends.

Good choice if

  • Long-lived development workflows that benefit from bounded memory, searchable sessions, and persistent goals
  • API-driven, scheduled, or delegated work running in Docker, SSH, Daytona, Modal, or a whole-process wrapper
  • Multi-provider workflows spanning terminal, desktop, web, MCP, browser automation, and messaging channels

Check before choosing

  • The default local backend executes with the user's host privileges; command screening is explicitly documented as a heuristic, not a security boundary
  • It is a broad personal-agent platform rather than a coding-only product, so setup and threat surface are larger than a focused coding CLI
  • Checkpoints, memory-write review, skill-write review, and whole-process isolation are opt-in rather than the default posture
See 2 more considerations
  • Background subagents are not restart-durable: an interrupted in-flight attempt can become unknown and must not be assumed safe to retry
  • Repository SWE, browser, batch, and trajectory utilities are project-owned evaluation assets; no score is imported without a complete independent run record

Capability support

Documented first-class product support, checked against the sources below.

External tools (MCP)
DocumentedProduct-supported MCP integrationSource · checked 2026-07-27The source establishes the mechanism, not its quality or availability in every mode.
Reusable skills
Not documentedNo first-class support established by the current recordAbsence of current documentation is not proof that the capability is impossible.
Local models
DocumentedLocal or self-hosted model pathSource · checked 2026-07-27The source establishes the mechanism, not its quality or availability in every mode.
Agent parallelism
DocumentedDelegated or parallel agent workflowSource · checked 2026-07-27The source establishes the mechanism, not its quality or availability in every mode.
Runs without an open UI
DocumentedNon-interactive or automation surfaceSource · checked 2026-07-27The source establishes the mechanism, not its quality or availability in every mode.
Browser control
DocumentedBuilt-in or product-supported browser controlSource · checked 2026-07-27The source establishes the mechanism, not its quality or availability in every mode.
Isolated execution
DocumentedDocumented execution-isolation mechanismSource · checked 2026-07-27The source establishes the mechanism, not its quality or availability in every mode.
Undo file changes
DocumentedProduct-supported file or session rollbackSource · checked 2026-07-27The source establishes the mechanism, not its quality or availability in every mode.

Getting started

Install Hermes Agent 0.19.0 or Hermes Desktop, choose a provider and terminal backend, then configure toolsets, approvals, memory-write policy, optional checkpoints, MCP, and scheduled or API access.

Open official documentation

Classification and operating model

Category fit and technical mechanisms are evidence records, not product-quality scores.

Category fit
Qualifies, 4/4 criteria
Operating model
7/7 layers documented
Inspect category criteria and operating mechanismsFirst-party records

Why it qualifies as a coding harness

This confirms category fit, not product quality. Every required criterion links back to first-party evidence.

Qualifies4 of 4 required criteria evidenced
  • Adaptive agent loop

    Documented

    The system repeatedly observes results and chooses the next action instead of following a fixed one-pass graph.

  • Repository tool execution

    Documented

    The system can use tools to inspect and change a repository or its execution environment.

  • Task-aware context management

    Documented

    The runtime assembles, updates, compacts, retrieves, or persists task-relevant context while work proceeds.

  • Model-independent runtime control

    Documented

    Permissions, budgets, interruption, policy, or stop controls operate outside the model's own text generation.

Membership establishes category fit only. It does not score quality, safety, autonomy, model capability, or benchmark performance. · Read the membership rule.

How it works under the hood

Seven mechanisms mapped from first-party records. These labels describe what the harness provides, not how intelligent its model is.

7/7layers documented
  • Execution & isolationSandbox availableDocumented mechanism, not a performance score.
  • Tooling & integrationsExtensible + browserDocumented mechanism, not a performance score.
  • Context & statePersistent stateDocumented mechanism, not a performance score.
  • Lifecycle & recoveryManaged recoveryDocumented mechanism, not a performance score.
  • ObservabilityStructured tracesDocumented mechanism, not a performance score.
  • VerificationWorkflow-gatedDocumented mechanism, not a performance score.
  • Governance & permissionsPolicy controlsDocumented mechanism, not a performance score.

Measured and public context

Configuration-specific measurements and source-native activity stay separate from general product capability.

Inspect code audit, measured configurations, and ecosystem signalsContext, not a product score

Public code audit

5/5public artifacts present
Security policy
Present at inspected commit
CI workflow
Present at inspected commit
Automated tests
Present at inspected commit
Evaluation assets
Present at inspected commit
Contributor documentation
Present at inspected commit

The inspected 0.19.0 source tree contains 2,729 Python and TypeScript test files under tests/ and apps/ plus 22 CI workflows. Its Mini-SWE runner, browser benchmark script, batch runner, trajectories, and other evaluation utilities are project-owned assets; they do not provide a complete independent model × harness × environment × budget × attempts result, so no product score is imported.

Inspect commit 0fa5e41c86f022bba147797849f0b44865721476, checked 2026-07-27

Measured configurations

No benchmark run passes the full metadata admission policy for this harness yet. Missing data is not scored as zero.

Benchmark policy and all runs
Context, not quality

Public ecosystem signals

Source-native observations for exact mapped artifacts and reviewed stable release trains. Different units and populations stay separate, and missing coverage is never treated as zero.

View this harness in Usage
  • Latest stable releasev2026.9.7Released 2026-09-07; 13 stable releases in 90 daysOpen release
  • OpenRouter 30d tokens49.82T#1 coding app; 2026-08-09 to 2026-09-07Open app page
  • Homebrew 30d events3.79KFormula: hermes-agentOpen artifact
  • GitHub stars243.2KFull-source repository; 50.1K forksOpen artifact

Routing, package retrievals, release downloads, editor installs, and repository interest observe different populations. They are never added together and never affect capability evidence, classification, or measured results.

Interpretation rulesSignals checked

First-party evidence

Each capability claim links to the first-party record that supports it.

25 first-party sourcesProduct record checked

Additional first-party sources

25 sources
View 24 more sources

Ecosystem context

OpenRouter apps Discovery signal only; usage rank is not used as a quality or capability score. Observed 2026-07-27.