Hire AI agents. Give them jobs.
Watch them work.

Most AI tools are a button you press: you ask, it answers, it forgets. Hermes is a console where an agent owns a queue and works it without you — and a quality gate checks what it actually did before it is allowed to call anything finished.

$ curl -fsSL https://raw.githubusercontent.com/at0m-b0mb/Hermes-Agent-Console/main/install.sh | bash

Then hermes. Your browser opens at localhost:4317. That is the whole setup.

Zero dependencies Runs fully offline 107 tests Python 3.9+ MIT

What this actually is

An agent that owns a queue

You describe a job once. The dispatcher hands it to whoever is free and on shift. The agent uses real tools — reads files, runs commands, fetches pages, sends mail — and when it claims to be done, a second model checks whether it did the work or merely described doing it. That last part is the difference between an agent that reports success and one that achieved it.

  You                Dispatcher            Agent                Quality gate
   │                     │                   │                       │
   ├─ "summarise these" ─┤                   │                       │
   │                     ├── picks it up ───▶│                       │
   │                     │                   ├─ read_file            │
   │                     │                   ├─ read_file            │
   │                     │                   ├─ write_file           │
   │                     │                   ├── "I'm done" ────────▶│
   │                     │                   │◀── "no, item 3 is ────┤
   │                     │                   │     unaddressed"       │
   │                     │                   ├─ write_file           │
   │                     │                   ├── "done" ────────────▶│
   │◀──── result ────────┴───────────────────┴──────── passed ───────┘

The console

Everything they are doing, and the bit waiting on you

A live view of the whole workforce at localhost:4317. Running tasks carry a ticking clock, anything blocked on your decision says so, and every tool call streams into the activity feed as it happens.

The Hermes command view showing agent counts, two escalations waiting on the operator, a live activity feed and tasks in progress
Command — four agents working, two waiting on a decision.

The board

Queued, running, done, and the ones that need you

Filter by title, brief or agent. Re-run any finished task with its brief prefilled, because the reason you re-run something is usually that one word needed changing.

The work board with queued, in progress, completed and needs attention columns
Live elapsed clocks on everything that is running.

Keyboard first

⌘K reaches everything

Every view, every agent, every action worth reaching. Results are ranked, so the thing whose name you typed comes first. g then a letter jumps between views, n assigns work, t switches theme, ? lists the lot.

The command palette listing actions, views and agents with keyboard hints
The palette, with the shortcut for each row on the right.

Receipts

Every run keeps its whole transcript

Each tool call, the arguments it was given, and what came back. Export any run as Markdown. Nothing an agent did is a black box afterwards.

A run drawer showing a full transcript of tool calls and their output
The run drawer — scoring, result, and the full transcript underneath.

What you get

The parts that make it a workforce

◉

Agents with a posture

Name, speciality, standing instructions, model, and a capability grant per tool. Three ship ready to use; eight more templates are a click away.

⚖

A quality gate

Always on. Before a task can be called finished, a second pass checks the work was performed rather than described, and names the specific gap when it was not.

⏱

Standing duties

Anything on a cadence — an hourly check, a daily summary, a weekly tidy-up. Hermes creates the task when it comes due and the owning agent picks it up.

⏸

Escalation, not silence

A stuck agent asks you a question instead of guessing. Answer it and the task goes back in the queue with your answer attached.

★

Scoring

A judge model grades correctness, completeness, efficiency and safety. Your own 0–100 rating always wins.

⌨

A terminal that keeps up

hermes shell for SSH sessions with no browser, hermes run for one-shot jobs, hermes tasks for the board, hermes audit for the chain.

Security

Built to run on a machine that matters

Most of the model is fixed in code, not asked of the model in a prompt. No autonomy level, grant setting, or cleverly-worded instruction changes any of it.

  • ✓23 protected path patterns. ~/.ssh, ~/.aws, .env files, *.pem, keychains. A fully autonomous agent scoped to your whole home directory still cannot read one — and cannot reach them through the grep tool either, because a grep is a read.
  • ✓18 blocked command patterns. rm -rf, sudo, curl | sh, disk writes, firewall changes, force pushes, history tampering.
  • ✓A human on every outgoing email. At every autonomy level, at every capability setting, and even behind --yes. Enforced at the single chokepoint every tool call passes through, so an injection can hijack an agent completely and still not get one byte out.
  • ✓Untrusted content is framed and scanned. Anything read from a web page or an inbox is wrapped as data with no authority, and known injection patterns are surfaced to you rather than hidden.
  • ✓Connection and request ceilings. 64 connections, 8 per client, a 20-second timeout and a 2 MB body cap — so a client that never authenticates cannot park every worker thread.
  • ✓A lockout that cannot be turned on you. The session token is checked before the brute-force lockout is consulted, so somebody spraying wrong tokens can never lock you out of your own console.
  • ✓Tamper-evident audit chain. Every tool call, approval, key change and run is hash-linked. Editing or deleting any row breaks the chain and the console says so.
  • ✓Encrypted key vault, secret redaction, spend ceilings, loopback-only binding, a strict CSP, and no version disclosure.
What it does not claim. The vault protects against casual disclosure, not against somebody who already has your login session. Injection framing reduces risk; it does not eliminate it — which is exactly why irreversible actions need a human instead of trusting the model. An agent granted run_shell can do anything your user can, minus the blocked patterns. Grant it deliberately.
The security view showing audit chain status, hard limits and spend caps
The chain is re-walked on every load. hermes doctor reports the rest of the posture.

Which model

Being good at chat and being able to drive tools are different skills

The gap is enormous at small sizes, and you would rather not find out halfway through a real job. hermes bench runs two fixed scenarios against each model you have and grades what ended up on disk — not what the model said it did.

ModelScoreTimeVerdict
qwen2.5:latest17 / 1733 sExcellent drives the loop cleanly
qwen2.5:7b16 / 1741 sGood fine for everyday work
llama3.1:latest15 / 1777 sGood, slower uses tools but does not reliably carry the result into the artefact

Measured on a local Ollama install. Run hermes bench to get the same table for your own machine.

🖥️

Runs fully offline

With Ollama and no API key, every feature on this page works. Nothing leaves your machine.

🔌

Six backends, chosen per agent

Ollama, Groq, Gemini, Anthropic, OpenAI, or any OpenAI-compatible endpoint — LM Studio, vLLM, OpenRouter. A cheap local model for routine work, a strong one for the hard jobs.

Install

No pip, no venv, no lockfile

Everything is Python standard library. The installer cannot fail on a broken wheel because there is nothing to build — and a test walks every import in the package to make sure that stays true.

$ curl -fsSL https://raw.githubusercontent.com/at0m-b0mb/Hermes-Agent-Console/main/install.sh | bash

1 · Give it a brain

ollama pull qwen2.5 for free and offline, or hermes key groq for a fast free tier.

2 · Start it

hermes — the console opens in your browser. hermes shell if you are on SSH.

3 · Give somebody a job

Press n, or hermes run Ledger "…" --yes from the terminal.

Prefer not to pipe a script into bash? Sensible — clone it and read the installer first. Everything Hermes owns lives in ~/.hermes, so uninstalling is one rm -rf.