Hermes
Run uvx jes login first. See Setup.
Install
uvx jes hermes-settings
Copy the hooks map it prints into ~/.hermes/config.yaml. Trust the hook
when Hermes asks.
uvx jes hermes-settings
# Hermes shell hooks. Copy the hooks map into ~/.hermes/config.yaml.
# The hook command is `uvx jes@0.0.1 hermes-hook`. uvx ships with uv, so there is
# no separate jes install. Trust the hook when Hermes asks.
#
# pre_tool_call: a failed check prints action block and exits 2.
# Set fail_closed so a crashed hook does not allow the call.
# pre_llm_call: a blocked user message is injected as context.
# Hermes does not reject the user message.
# Shell hooks cannot replace a tool result or the assistant reply.
hooks:
pre_llm_call:
- command: uvx jes@0.0.1 hermes-hook
timeout: 60
pre_tool_call:
- command: uvx jes@0.0.1 hermes-hook
timeout: 60
fail_closed: true
What each hook does
| Event | Stage | If jes blocks |
|---|---|---|
pre_llm_call | input | Prints the refusal as context and exits 2. |
pre_tool_call | tool_call | Prints action: block and exits 2. The tool does not run. |
fail_closed: true is set on pre_tool_call, so a hook that crashes blocks
the call instead of allowing it.
Limits
- Hermes doesn't reject a blocked user message. The model sees the message and the refusal as context.
- Hermes shell hooks can't replace a tool result or the reply, so jes doesn't
check those stages here. If you wire
transform_tool_resultortransform_llm_outputto the hook anyway, they pass unchecked.