Operate a local Hermes Agent install over stdio: tasks, cron, config, gateway, doctor. No network.
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β or use 1-click editor setup below.
One-click editor setup isnβt available for this listing yet β we donβt have a confirmed install command, and weβd rather show nothing than point your editor at the wrong package or host. Follow the projectβs own setup instructions, linked above.
Operate your local Hermes Agent install from any MCP client β without exposing it to the network.
hermes-agent-mcp is a Model Context Protocol server that wraps the local hermes CLI over stdio. Point Claude Code, Cursor, Codex or any other MCP-capable agent at it and they can hand Hermes a task, read and change its config, manage cron jobs, restart the gateway and run hermes doctor β without a terminal and without ever seeing a token.
That is the whole install. No ports, no tunnel, no OAuth. It runs as a child process of your MCP client, on the same machine as Hermes, and nothing leaves the box.
mcp-name: io.github.woonyong-choi/hermes-agent-mcp
Hermes is a great always-on agent, but everything about operating it happens in a terminal: hermes cron edit, hermes config set, hermes gateway restart. If the agent that wants to do those things has no terminal β a desktop app, a coding assistant sandboxed away from your shell β it is stuck asking a human to type for it.
There is already a good project called hermes-mcp by mlennie. It solves a different problem: reaching Hermes remotely, over HTTP through a cloudflared tunnel with OAuth, so a hosted client can delegate tasks. If that is what you need, use it.
This project was written by someone who did not want that. Opening a Hermes gateway to the internet means an agent with a shell is one leaked token away from anyone. hermes-agent-mcp stays local on purpose:
| hermes-agent-mcp (this) | hermes-mcp (mlennie) | |
|---|---|---|
| Transport | stdio, local process | HTTP, tunnel + OAuth |
| Reachable from | MCP clients on the same machine | Anywhere |
| Surface | 16 tools: ask + cron, config, gateway, doctor, skills, sessions | 4 tools: ask, check, cancel, reset |
Typed config.yaml writes | Yes | β |
| Network exposure | None | By design |
| Tool | What it does |
|---|---|
hermes_status | Server config, whether the CLI answers, which tools are enabled |
hermes_ask | Hand the agent a task and get its reply (one non-interactive turn) |
doctor | hermes doctor health report |
gateway_status / gateway_restart | Messaging gateway state and restart |
cron_list / cron_create / cron_edit / cron_run / cron_runs | Scheduled jobs, including per-job model and reasoning effort |
config_get / config_set | Typed reads and writes against config.yaml |
skills_list | Installed skills |
sessions_list | Recent sessions |
model_info | Default model, provider and Nous Portal status |
shell | Run a shell command on the host β off by default |
bridge_setup / bridge_status | Point the bridge at a chat (Telegram by default) |
bridge_ask / bridge_check | Ask through the gateway and mirror prompt + reply into that chat |
bridge_ask keeps the phone in the loophermes_ask runs a one-shot CLI turn: fine for work, but it runs outside the gateway, so nothing appears in the user's chat. bridge_ask goes through the gateway's own webhook adapter instead: your prompt is posted into the chat (prefixed βΈ Claude Code Β· β the caller name comes from HERMES_MCP_CALLER, the format from HERMES_MCP_LABEL_FORMAT), the agent runs inside the gateway with its full toolset, and the reply lands in the chat and comes back to you. The person can pick the thread up on their phone as if they had typed it themselves.
bridge_setup registers two loopback-only, HMAC-signed webhook routes and targets the most recently active chat unless you pass chat_id. The secret lives in $HERMES_HOME/hermes-agent-mcp.json (mode 0600) and is never returned to the model. The bridged turn does not share the chat's own session history β Hermes keys webhook sessions separately β but memory and skills are shared and the transcript in the chat is continuous.
config_set fixes a real traphermes config set platforms.telegram.reply_to_mode off stores the YAML boolean False, not the string "off". Several Hermes options compare against the string, so the setting silently does nothing. config_set takes an explicit value_type (str, int, float, bool, null, json), writes a .bak before touching the file, and returns the resulting section so you can see what landed.
Hermes can drive its own install β useful for a supervisor profile that manages other profiles. Add to ~/.hermes/config.yaml:
Everything is an environment variable, so the same server works on macOS, Linux, WSL and inside a container that mounts someone else's ~/.hermes.
| Variable | Default | Meaning |
|---|---|---|
HERMES_HOME | ~/.hermes | Hermes data directory |
HERMES_MCP_BIN | hermes on PATH | Path to the CLI |
HERMES_MCP_ALLOW_WRITE | 1 | Allow tools that change state (cron edit, config set, restart). Set 0 for read-only |
HERMES_MCP_ALLOW_SHELL | 0 | Enable the shell tool |
HERMES_MCP_TIMEOUT | 120 | Seconds for ordinary CLI calls |
HERMES_MCP_ASK_TIMEOUT | 900 | Seconds for hermes_ask |
HERMES_MCP_MAX_OUTPUT | 40000 | Characters returned per call before truncation |
HERMES_MCP_CALLER | Claude | Who this registration is for; shown in the chat prefix (βΈ Claude Code Β· β¦). Set it per registration |
HERMES_MCP_LABEL_FORMAT | βΈ {caller} Β· | Template for that prefix, e.g. [{caller}] |
This server gives a language model the ability to operate an agent that has a terminal. The design assumes the model is talking to untrusted content and keeps the blast radius small:
subprocess.run([...]) with shell=False. Prompt text cannot become shell syntax.config, cron, doctor, gateway, model, portal, profile, sessions, skills, tools and --version are reachable. hermes auth and anything that handles credentials is not, on purpose.[redacted] before output reaches the model. .env is never read.HERMES_MCP_ALLOW_WRITE=0 blocks every state-changing verb.shell refuses to run until you set HERMES_MCP_ALLOW_SHELL=1, and you should only do that on a machine you control, for an agent you trust.See SECURITY.md for reporting.
Tag a version and CI publishes to PyPI via Trusted Publishing and attaches the wheel to a GitHub release:
server.json at the repo root is the manifest for the MCP Registry; publish it with mcp-publisher publish after the PyPI release exists.
Tests do not need a Hermes install; the runner is exercised against a missing binary and the config writer against a temp directory.
Built against Hermes Agent 0.21.x. The CLI is moving fast β if a subcommand's flags change, the tool returns the CLI's own error text rather than guessing. Issues and PRs that track upstream changes are welcome.
MIT. Hermes Agent is MIT-licensed by Nous Research; this project is independent and not affiliated with them.
No reviews yet β be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/hermes-agent-mcp)<a href="https://allmcps.com/mcp/hermes-agent-mcp"><img src="https://allmcps.com/api/badge/hermes-agent-mcp?style=directory" alt="Hermes Agent MCP on AllMCPs" /></a>