Hermes Agent tool ecosystem and MCP integration

All of Hermes's capabilities go throughToolsExposed to Agent.

Tools organized intoToolsetsToolsets are then combined intoPlatform configuration. This three-layer structure determines what the Agent can do in different scenarios:

工具(Tool)
  └── 工具集(Toolset)         # 相关工具的逻辑分组
        └── 平台配置            # 哪个平台加载哪些工具集
              └── 自定义工具集   # 你自己定义的组合

Toolkit management commands

# 打开 curses TUI,按平台开/关工具集
hermes tools

# 命令行列出所有工具和状态
hermes tools list

# 按名称启用或禁用工具集
hermes tools enable NAME
hermes tools disable NAME

Desktop version, in the left-side skills and tools menu:

Disable a tool set, and its tools from the system promptCompletely disappear, not just disabling—this directly saves tokens and prevents the Agent from misusing tools it shouldn't use.


Overview of built-in toolkits

Hermes provides 70+ built-in tools, divided into 28 tool sets.

The following introduces the most commonly used tool sets by category.

Files and system

toolsetCore toolsMain purpose
fileread_file、write_file、list_dirFile read/write, directory operations
terminalrun_command、run_scriptShell command execution
codeexecute_codeSandboxed code execution (Python/JS/Bash)
computerscreenshot、click、typeDesktop GUI automation

Network and content

toolsetCore toolsMain purpose
webweb_search、web_extractWeb search and content extraction
browsernavigate、click、fill_formFull browser automation
visionanalyze_image、describe_imageImage analysis and description
audiotranscribe、ttsSpeech-to-text, text-to-speech

Agent Capabilities

toolsetCore toolsMain purpose
memorymemory、session_searchMemory management and cross-session retrieval
skillsskills_list、skill_view、skill_manageSkill management
delegationspawn_agent、spawn_parallelSub-agent delegation and parallelism
kanbantask_create、task_updateMulti-Agent dashboard (requires explicit enabling)

Media creation

The following toolset requires Nous Portal or a corresponding API Key:

toolsetFeaturesDescription
image_genText-to-image generationSupports 9 models including FLUX, GPT-Image
ttsText-to-speech10 TTS providers, including local Piper

Custom toolkits

You can combine existing tool sets into project-specific tool sets in the configuration file:

Example

# File path: ~/.hermes/config.yaml
# Custom toolset: combine existing toolsets into project-specific configuration
custom_toolsets
:
  data-science
:
   - file
    - terminal
    - code
    - web

Then specify at startup:

Example

# Use custom toolset at startup
hermes --toolsets data-science

Six terminal execution backends

The terminal tool set supports six execution backends, determining the Agent's Shell commandsWhere to run, corresponding to different isolation levels and "blast radius".

BackendCommand execution locationIsolation LevelTypical scenarios
local (default)Local machine, current user permissionsNonePersonal development, daily use
dockerInside Docker containerComplete IsolationProduction deployment, secure sandbox
sshRemote serverNetwork boundary isolationRemote development, high-performance machines
modalModal cloud sandbox (VM)Fully (cloud)Temporary compute, evaluation tasks
daytonaDaytona-hosted workspacesFully (cloud container)Managed cloud development environment
singularitySingularity ContainerNamespace isolationHPC clusters, shared machines

Switch backend

Example

# Switch to Docker backend (recommended for production environment)
hermes config set terminal.backend docker

# Switch to SSH backend
hermes config set terminal.backend ssh
hermes config set terminal.ssh_host user@your-server.com

Docker backend complete configuration example:

Example

# File path: ~/.hermes/config.yaml
# Docker backend configuration
terminal
:
  backend
: docker
  docker_image
: "nikolaik/python-nodejs:python3.11-nodejs20"
  container_persistent
: true    # true = bind mount, false = tmpfs temporary

Security principle: the local backend gives the Agent the same file system permissions as you—suitable for personal machines, not suitable for production services. The docker backend is the simplest and most effective isolation method.

Dangerous command approval

By default, Hermes will request confirmation before executing potentially destructive commands:

Example

# File path: ~/.hermes/config.yaml
# Approval Mode Configuration
approvals
:
  mode
: manual        # manual (default) | smart | off
  timeout
: 60         # Seconds to wait for approval
  cron_mode
: deny     # Behavior when a scheduled task encounters dangerous commands: deny | approve

Temporarily bypass approval in a session (use with caution):

Example

# Enable YOLO mode, auto-approve all commands in this session
/yolo

# Enter Again to Disable
/yolo

MCP: connecting the external tool ecosystem

MCP (Model Context Protocol) allows Hermes to connect to external tool servers without modifying core code—GitHub, databases, file systems, browser stacks, internal APIs, etc.

Standard installation includes MCP supportNo extra steps required.

Two types of MCP servers

Local stdio server: Runs locally as a subprocess, communicating via standard input/output:

Example

# File path: ~/.hermes/config.yaml
# MCP stdio Server Configuration
mcp_servers
:
  github
:
    command
: "npx"
    args
: ["-y", "@modelcontextprotocol/server-github"]
    env
:
      GITHUB_PERSONAL_ACCESS_TOKEN
: "ghp_..."

  filesystem
:
    command
: "npx"
    args
: ["-y", "@modelcontextprotocol/server-filesystem", "/home/user/projects"]

  git
:
    command
: "uvx"
    args
: ["mcp-server-git", "--repository", "/home/user/project"]

Applicable scenarios: tools are installed locally, and low-latency access to local resources is needed.

Remote HTTP server: directly connect to a remote MCP endpoint:

Example

# File path: ~/.hermes/config.yaml
# MCP HTTP server configuration
mcp_servers
:
 # Static Bearer Token authentication
  internal_api
:
    url
: "https://mcp.internal.example.com/mcp"
    headers
:
      Authorization
: "Bearer ${MY_TOKEN}"

  # OAuth 2.1 Authentication (Linear, Sentry, Figma, Stripe, etc.)
  linear
:
    url
: "https://mcp.linear.app/mcp"
    auth
: oauth

  # Providers that require pre-registered OAuth clients
  googledrive
:
    url
: "https://drivemcp.googleapis.com/mcp/v1"
    auth
: oauth
    oauth
:
      client_id
: "<your-oauth-client-id>"
      client_secret
: "<your-oauth-client-secret>"

Applicable scenarios: tools are hosted remotely, or there is an MCP interface within the organization.

Nous curated MCP directory

Hermes has a built-in Nous-curated MCP directory with one-click installation:

Example

# Open interactive selector (default)
hermes mcp

# Plain text list
hermes mcp catalog

# Install entries from directory by name
hermes mcp install n8n

The selector will display the current status of each entry:

n8n          available              管理和检查 n8n 工作流
linear       enabled                Linear 问题/项目管理(远程 OAuth)
github       installed (disabled)   GitHub 仓库 + PR 工具

Installation automatically completes three steps:

  1. Prompt to configure an API key or guide OAuth login
  2. Detect the list of tools exposed by the server
  3. Displays a tool selection list, letting you decide which tools to enable

Tool filtering: only expose what you need

Each MCP server supports fine-grained tool filtering, reducing the attack surface available to the Agent:

Example

# File path: ~/.hermes/config.yaml
# MCP tool filtering configuration
mcp_servers
:
  github
:
    command
: "npx"
    args
: ["-y", "@modelcontextprotocol/server-github"]
    env
:
      GITHUB_PERSONAL_ACCESS_TOKEN
: "ghp_..."
    tools
:
      include
: [list_issues, create_issue, update_issue, search_code]
      # Unlisted tools will not be registered
    resources
: false
    prompts
: false

  stripe
:
    url
: "https://mcp.stripe.com"
    headers
:
      Authorization
: "Bearer ${STRIPE_KEY}"
    tools
:
      exclude
: [delete_customer, refund_payment]  # Exclude high-risk operations
FieldsBehavior
tools.includeOnly register tools on the list, exclude all others
tools.excludeExclude tools in the list, register all others
Set bothinclude priority
resources: falseDo not expose MCP resource access tools
prompts: falseDo not expose MCP prompt tools

FilterRulesUsage MCP originalTool name称(containconnectCharacter/Point),is not Hermes RegisterafterBottom划Lineversion.

Each MCP server generates an independent tool set

After configuring the GitHub MCP server, Hermes will automatically create it at runtimemcp-githubToolset.

You can manage it like a built-in tool set:

Example

# File path: ~/.hermes/config.yaml
# Reference MCP toolset in platform configuration
platform_toolsets
:
  cli
:
   - hermes-cli
    - mcp-github
    - mcp-linear

Reload MCP configuration

After modifying config.yaml, there is no need to restart the entire Agent:

Example

# Reload MCP server in-session (30-second timeout)
/reload-mcp

# Or from the Command Line
hermes mcp reload

If OAuth authentication is required, the 30-second timeout is not enough. It is recommended to add the server configuration first, then run hermes mcp login <server> in a new terminal to complete authorization (waiting up to 5 minutes).


Editor integration (ACP)

ACP (Agent Communication Protocol) lets Hermes run natively inside the editor—chat, tool activity, file diffs, and terminal commands are all rendered directly in the editor.

Supported editors: VS Code, Zed, and the entire JetBrains series.

Standard installation already includes ACP support:

Example

# Start Agent mode for editor connections
hermes acp

If the full dependencies were not included at installation:

Example

# Install ACP dependencies
cd ~/.hermes/hermes-agent
uv pip install -e ".[acp]"
EditorIntegration methodFeatures
VS CodeExtension pluginInline code completion, code review, refactoring suggestions
ZedNative agent modestdio/JSON-RPC communication, context-aware
JetBrainsPluginCode generation, test generation, documentation comments

Editor integration communicates with the Hermes Agent using the stdio/JSON-RPC protocol, does not rely on a network connection, and is suitable for offline use.


Voice mode

Voice mode supports complete voice interaction across CLI and messaging platforms:

  • Microphone recording input (faster-whisper local speech recognition, free)
  • TTS voice replies (10 provider options available)
  • Real-time conversation in Discord voice channels

Install and enable

Example

# Install Voice Dependencies
cd ~/.hermes/hermes-agent
uv pip install -e ".[voice]"

Example

# Enable voice mode in CLI
/voice on
# Press Ctrl+B to start recording, release to send

# In the Messaging Platform
/voice on     # Enable TTS replies
/voice tts    # Enable only text-to-speech (without voice input)
/voice off    # Off

TTS providers

providerFeaturesFree or not
Edge TTSMicrosoft neural voices, multilingualFree
PiperFully local, low latencyFree
OpenAI TTSHigh quality, multiple voicesPay-as-you-go
ElevenLabsTop-tier audio quality, voice cloningPay-as-you-go
MiniMaxChinese optimizationPay-as-you-go
Mistral VoxtralmultilingualPay-as-you-go

Tool Gateway (Nous Portal subscription)

Subscribe via Nous Portal to get cloud implementations of four types of tools in one click, without needing to apply for API Keys separately:

ToolsDescription
Web searchSearch + content extraction (web toolset)
Image generation9 models: FLUX, GPT-Image, Ideogram, etc.
TTSText-to-speech
Cloud browserFull browser automation (no local Playwright needed)

Example

# OAuth login, automatically configures all above tools
hermes setup --portal

Tool security: MCP environment variable isolation

MCP stdio subprocess receives aFiltered environmentPreventing accidental credential leakage.

By default, only the following variables are passed to the MCP process:

PATH, HOME, USER, LANG, LC_ALL, TERM, SHELL, TMPDIR(以及所有 XDG_* 变量)

All other environment variables (API Key, Token, password) are blocked.

Only variables explicitly declared in the env: block of the MCP server configuration will be passed:

Example

# File path: ~/.hermes/config.yaml
# Only explicitly declared variables are passed into the MCP subprocess.
mcp_servers
:
  github
:
    command
: "npx"
    args
: ["-y", "@modelcontextprotocol/server-github"]
    env
:
      GITHUB_PERSONAL_ACCESS_TOKEN
: "ghp_..."   # Only this one is passed in

In addition, MCP tool error messages are automatically sanitized before being returned to the LLM, with sensitive information replaced by[REDACTED]。


Quick reference for common commands

Example

# ─── Tool Management ────────────────────────────────────────────────
hermes tools                          # Interactive toolset management (TUI)
hermes tools list                     # List all tools and status
hermes tools enable NAME              # Enable toolset
hermes tools disable NAME             # Disable toolset

# ─── MCP 管manage ────────────────────────────────────────────────
hermes mcp                            # Interactive MCP directory selector
hermes mcp catalog                    # Plain text directory listing
hermes mcp install <name>             # Install Directory Entries
hermes mcp add NAME --command CMD     # Manually add MCP server
hermes mcp remove NAME                # Remove MCP server
hermes mcp list                       # List configured servers
hermes mcp test NAME                  # Test Connection
hermes mcp login <server>             # Complete OAuth authorization
hermes mcp configure <server>         # Reconfigure tool selection
hermes mcp reload                     # Reload MCP configuration

# ─── Terminal Backend ────────────────────────────────────────────────
hermes config set terminal.backend docker
hermes config set terminal.backend ssh
hermes config set terminal.ssh_host user@host

# ─── ACP EditorSetCheng ──────────────────────────────────────────
hermes acp

# ─── Portal Subscription ─────────────────────────────────────────────
hermes setup --portal
other extensions