Orion vault — clean initial history

Knowledge vault (Orion/PARA) migrated from the pre-Orion 484vault on
2026-10-01. Deliberately orphaned: prior history contained a plaintext
password and stays local-only on branch archive/pre-boilerplate-history.
Secrets and live Hermes state are gitignored.
This commit is contained in:
Avi 2026-10-02 08:34:04 -05:00
commit a66996ac10
233 changed files with 103810 additions and 0 deletions

View file

@ -0,0 +1,92 @@
#impeccablestyles
### 1. Install the Impeccable skill
In your Hermes terminal, run:
```
hermes skills install official/creative/impeccable
```
### 2. Initialize it
Once Hermes is running, type:
```
/impeccable init
```
### 3. Then tell Hermes what you actually want
For example, if you're working on your Android app, I would give Hermes something like:
```
/impeccable
I am working on an existing Android application.
First inspect the existing project and understand its current UI, navigation,
components, typography, spacing, colors, icons, and overall visual hierarchy.
Do not rewrite the application or make broad changes yet.
Use the Impeccable design system and its documentation to:
1. Identify the biggest UI/UX problems.
2. Identify anything that looks generic or AI-generated.
3. Identify inconsistent spacing, typography, hierarchy, color usage,
components, and interaction patterns.
4. Preserve functionality that already works.
5. Preserve the existing brand identity unless there is a concrete reason
to change it.
6. Give me a prioritized design improvement plan.
Do not implement anything until you have inspected the project and explained
what you found.
```
## Command reference
Use a focused command when you know what kind of change you want.
### Create2
- [impeccableDescribe what you want to make or improve.](https://impeccable.style/docs/impeccable)
- [shapeTurn an idea into a design brief you can build from.](https://impeccable.style/docs/shape)
### Evaluate2
- [auditFind implementation problems and prioritize the fixes.](https://impeccable.style/docs/audit)
- [critiqueFind what’s holding the design back and what to improve first.](https://impeccable.style/docs/critique)
### Refine8
- [animateUse motion to make changes, relationships, and feedback clear.](https://impeccable.style/docs/animate)
- [bolderGive an existing section more presence while keeping it true to the design.](https://impeccable.style/docs/bolder)
- [colorizeUse color to clarify actions, states, and the design’s character.](https://impeccable.style/docs/colorize)
- [delightMake meaningful moments surprising, satisfying, and unmistakably yours.](https://impeccable.style/docs/delight)
- [layoutArrange the page so people know where to look and what belongs together.](https://impeccable.style/docs/layout)
- [overdrivePush past the expected. Make an interface feel extraordinary.](https://impeccable.style/docs/overdrive)
- [quieterReduce visual noise while keeping the design’s personality.](https://impeccable.style/docs/quieter)
- [typesetMake text easier to read, scan, and recognize across the product.](https://impeccable.style/docs/typeset)
### Simplify3
- [adaptMake an existing design work on a different screen, device, or platform.](https://impeccable.style/docs/adapt)
- [clarifyHelp people understand what happened and what to do next.](https://impeccable.style/docs/clarify)
- [distillReduce clutter so the important things are easier to find.](https://impeccable.style/docs/distill)
### Harden4
- [hardenKeep the interface usable when data, connections, or actions go wrong.](https://impeccable.style/docs/harden)
- [onboardHelp new users reach their first useful result.](https://impeccable.style/docs/onboard)
- [optimizeFind what makes the interface slow, fix it, and measure the result.](https://impeccable.style/docs/optimize)
- [polishMake an existing page feel finished and work better.](https://impeccable.style/docs/polish)
### System5
- [documentRecord your visual system so future work can follow it.](https://impeccable.style/docs/document)
- [extractTurn repeated UI patterns into shared components and styles.](https://impeccable.style/docs/extract)
- [generateName an element, compare variations, and keep your favorite.](https://impeccable.style/docs/generate)
- [initGive Impeccable the context to design for your project.](https://impeccable.style/docs/init)
- [livePoint at your page, explore variations, and keep the one you like.](https://impeccable.style/docs/live)

View file

@ -0,0 +1,323 @@
{
"jobs": [
{
"id": "bcbfb3fd9219",
"name": "hermes-release-watch",
"prompt": "The Hermes Agent release watcher just detected that the latest hermes-agent release tag CHANGED (the injected monitor diff shows the old and new tag). Using web_search and web_extract, find the new release's notes (https://github.com/NousResearch/hermes-agent/releases) and deliver a short summary: the new version tag, 5-10 bullet highlights of the changelog, and any upgrade caveats or breaking changes worth knowing. Keep it under ~30 lines. If the release notes cannot be retrieved, deliver the tag and say so plainly.",
"skills": [],
"skill": null,
"model": null,
"provider": null,
"provider_snapshot": "custom",
"model_snapshot": "qwen3.8-flash-next",
"base_url": null,
"script": null,
"no_agent": false,
"monitor_script": "hermes-release-watch.sh",
"monitor_url": null,
"monitor_state": {
"last_output_hash": "d23e0747eb024c470305b9d953b7ff752f406fffdcad2abf3d3eb9b5a2c7bbfa",
"last_changed_at": "2026-09-30T12:02:52.619460-05:00"
},
"context_from": null,
"schedule": {
"kind": "interval",
"minutes": 240,
"display": "every 240m"
},
"schedule_display": "every 240m",
"repeat": {
"times": null,
"completed": 137
},
"enabled": true,
"state": "scheduled",
"paused_at": null,
"paused_reason": null,
"created_at": "2026-09-06T23:26:53.637272-05:00",
"next_run_at": "2026-10-02T09:25:11.517016-05:00",
"last_run_at": "2026-10-02T05:25:11.517016-05:00",
"last_status": "ok",
"last_error": null,
"last_delivery_error": null,
"last_delivery_unverified": null,
"failure_streak": 0,
"deliver": "origin",
"origin": null,
"enabled_toolsets": [
"web"
],
"workdir": null,
"last_dispatch": {
"scheduled_at": "2026-10-02T05:24:47.247613-05:00",
"dispatched_at": "2026-10-02T05:25:09.479089-05:00",
"lateness_seconds": 22.2,
"kind": "on_time"
},
"fire_claim": null
},
{
"id": "8db0d60e394d",
"name": "daily-tech-digest",
"prompt": "Use web_search and web_extract to produce a morning digest of: (1) Hermes Agent / Nous Research releases and announcements in the last ~24-48h, and (2) notable self-hosted-AI news (local LLM runtimes, self-hosted search/extraction, agent tooling, open-weight releases). Style: max ~30 lines total, high-signal only, links included for every item, no filler or commentary. If there is nothing new in a section, say \"nothing new\" for that section.",
"skills": [],
"skill": null,
"model": null,
"provider": null,
"provider_snapshot": "custom",
"model_snapshot": "qwen3.8-flash-next",
"base_url": null,
"script": null,
"no_agent": false,
"monitor_script": null,
"monitor_url": null,
"monitor_state": null,
"context_from": null,
"schedule": {
"kind": "cron",
"expr": "0 8 * * *",
"display": "0 8 * * *"
},
"schedule_display": "0 8 * * *",
"repeat": {
"times": null,
"completed": 26
},
"enabled": true,
"state": "scheduled",
"paused_at": null,
"paused_reason": null,
"created_at": "2026-09-06T23:26:53.971088-05:00",
"next_run_at": "2026-10-03T08:00:00-05:00",
"last_run_at": "2026-10-02T08:02:57.693674-05:00",
"last_status": "ok",
"last_error": null,
"last_delivery_error": null,
"last_delivery_unverified": null,
"failure_streak": 0,
"deliver": "origin",
"origin": null,
"enabled_toolsets": [
"web"
],
"workdir": null,
"last_dispatch": {
"scheduled_at": "2026-10-02T08:00:00-05:00",
"dispatched_at": "2026-10-02T08:00:24.793283-05:00",
"lateness_seconds": 24.8,
"kind": "on_time"
},
"fire_claim": null
},
{
"id": "068a4794dd48",
"name": "vault-sync-mechanical",
"prompt": "Mirror Hermes state to Orion",
"skills": [],
"skill": null,
"model": null,
"provider": null,
"provider_snapshot": null,
"model_snapshot": null,
"base_url": null,
"script": "vault-sync.sh",
"no_agent": true,
"monitor_script": null,
"monitor_url": null,
"monitor_state": null,
"context_from": null,
"schedule": {
"kind": "interval",
"minutes": 60,
"display": "every 60m"
},
"schedule_display": "every 60m",
"repeat": {
"times": null,
"completed": 452
},
"enabled": true,
"state": "scheduled",
"paused_at": null,
"paused_reason": null,
"created_at": "2026-09-11T09:18:40.467602-05:00",
"next_run_at": "2026-10-02T09:25:29.493390-05:00",
"last_run_at": "2026-10-02T08:25:29.493390-05:00",
"last_status": "ok",
"last_error": null,
"last_delivery_error": null,
"last_delivery_unverified": null,
"failure_streak": 0,
"deliver": "local",
"origin": null,
"enabled_toolsets": null,
"workdir": null,
"last_dispatch": {
"scheduled_at": "2026-10-02T08:25:23.587216-05:00",
"dispatched_at": "2026-10-02T08:25:27.339858-05:00",
"lateness_seconds": 3.8,
"kind": "on_time"
},
"fire_claim": null
},
{
"id": "9190622b60e0",
"name": "vault-knowledge-routing",
"prompt": "You are syncing Hermes knowledge into the user's Obsidian vault at /home/avi/Orion (a disaster-recovery knowledge base; a brand-new Hermes instance must be able to rebuild itself from it). Read /home/avi/Orion/04-SYSTEMS/hermes-memory/RESTORE-HERMES.md for layout context.\n\nProcedure:\n1. Read the timestamp in /home/avi/Orion/04-SYSTEMS/hermes-memory/.last-sync to know the previous sync time.\n2. Use mnemosyne_recall (broad queries like 'lesson fix error procedure decision preference' and/or check recently-written memories) to identify memories, lessons, fixes, decisions, and preferences created or updated since that time. Also list skills under ~/.hermes/skills/ modified since that time (search_files target=files order=modified).\n3. For each NEW item, route it to the proper vault location (create the note if missing, append/update if it exists):\n - Technical fixes, hardware/OS/display issues -> 2. Areas/Home Personal/knowledge/ (one note per problem: symptom, diagnosis path, fix, date)\n - Workflows and repeatable procedures -> 3. Resources/Research/workflows/\n - Architecture/system facts, config, environment -> 2. Areas/Home Personal/knowledge/hermes/\n - General knowledge, project context -> 3. Resources/Research/\n - Decisions with rationale -> 4. Decisions/ (one file per decision: YYYY-MM-DD-slug.md)\n - New skills -> ensure 03-SKILLS/hermes-skills/ is current (an hourly script mirrors it; only fix gaps) and update 03-SKILLS/Knowledge Vault Skills Index.md ONLY if it exists and is stale in structure (it references an old HermesVault path; add a one-line note at top pointing to hermes-skills/ as the live copy if not already there).\n - User preferences/conventions -> 3. Resources/Research/User Preferences.md (create if missing).\n4. Notes: use Obsidian markdown with [[wikilinks]] where related; include dates; keep entries compact and declarative. Do NOT duplicate content already in the vault — search_files the vault first.\n5. NEVER write secrets, API keys, tokens, or credentials into the vault.\n6. If nothing new since last sync, make no changes.\nFinal response: one short line summarizing what was routed (or 'no new items').",
"skills": [],
"skill": null,
"model": null,
"provider": null,
"provider_snapshot": "custom",
"model_snapshot": "qwen3.8-flash-next",
"base_url": null,
"script": null,
"no_agent": false,
"monitor_script": null,
"monitor_url": null,
"monitor_state": null,
"context_from": null,
"schedule": {
"kind": "cron",
"expr": "0 23 * * *",
"display": "every day at 11pm"
},
"schedule_display": "every day at 11pm",
"repeat": {
"times": null,
"completed": 20
},
"enabled": true,
"state": "scheduled",
"paused_at": null,
"paused_reason": null,
"created_at": "2026-09-11T09:18:55.304733-05:00",
"next_run_at": "2026-10-02T23:00:00-05:00",
"last_run_at": "2026-10-01T23:06:04.416754-05:00",
"last_status": "ok",
"last_error": null,
"last_delivery_error": null,
"last_delivery_unverified": null,
"failure_streak": 0,
"deliver": "local",
"origin": null,
"enabled_toolsets": null,
"workdir": null,
"last_dispatch": {
"scheduled_at": "2026-10-01T23:00:00-05:00",
"dispatched_at": "2026-10-01T23:00:31.733048-05:00",
"lateness_seconds": 31.7,
"kind": "on_time"
},
"fire_claim": null
},
{
"id": "0bfa9cb6dccf",
"name": "keynctr-signer-debug",
"prompt": "Continue debugging the Keynctr NIP-46 external-signer (Amber) pairing problem. Self-contained brief:\n\nPROJECT: /home/avi/Projects/Keynctr (Rust core + Electron/React frontend, master branch). Read CHECKPOINT-encryption.md at repo root first for current state, and /home/avi/Orion/01-PROJECTS/keynctr.md for project history. Follow repo rule: commit each fix, then update CHECKPOINT-encryption.md to match.\n\nTHE PROBLEM: User pairs Amber (Android NIP-46 signer) via nostrconnect:// QR shown in Keynctr's Signer Mode screen. Amber reports 'connected', but no new profile row ever appears in Keynctr and no NIP-46 connection persists to ~/.local/share/keynectr/profiles_vault.json.\n\nWHAT'S BEEN FIXED ALREADY (committed): pairing relay-set widening (f59c2b1), 5-min pairing window + inbound-event wiretap (5aa122d), lenient params coercion for object-shaped requested_perms (aedde8f). The wiretap showed Amber's connect event arriving and decrypting fine but failing RawRequest parse ('decrypted payload is not a NIP-46 request', payload len 89) — latest uncommitted build coerces request ids too and logs the exact decrypted payload. If that uncommitted change is still uncommitted, verify with cargo test, commit it, rebuild release (cargo build --release), and check whether the parse failure persists.\n\nDEBUG SURFACES: /tmp/keynctr-el*.log (Electron+backend stderr, newest number is newest), /home/avi/Tools/keynctr-debug/pairing-capture.jsonl (raw captured kind-24133 pairing events). The backend is keynectr serve spawned by Electron; dev launch: cd ~/Projects/Keynctr/frontend && npx vite --port 5173 (if not already up on :5173), then NOSTR_GUI_DEV_URL=http://localhost:5173 KEYNCTR_ENABLE_GPU=1 npx electron . . Kill stale instances with careful patterns (pkill -f 'keynect[r] serve'; pkill -f 'node_modules/electro[n]') — beware pkill patterns matching their own command line.\n\nNEXT STEPS if unresolved: (1) read the newest /tmp/keynctr-el*.log and pairing-capture.jsonl for the latest decrypted payload dump — the exact JSON shape that fails parsing is the smoking gun; (2) reproduce it as a failing unit test against RawRequest in src/signer/nip46_client.rs (raw_request_tests module), fix the deserializer, make it green; (3) verify full suite: cargo test (expect 200+ green), cargo clippy --all-targets (zero warnings), cargo fmt --check; (4) note that the user cannot re-scan Amber from a cron session — do NOT claim end-to-end pairing works without his live test; report what changed and what he should try.\n\nCONSTRAINTS: never transmit user data externally (privacy rule); preserve deferred branches, never delete work; keep per-unit commits; update the Orion project file with milestones. Report findings and status at the end.",
"skills": [],
"skill": null,
"model": null,
"provider": null,
"provider_snapshot": "custom",
"model_snapshot": "qwen3.8-flash-next",
"base_url": null,
"script": null,
"no_agent": false,
"monitor_script": null,
"monitor_url": null,
"monitor_state": null,
"context_from": [
"self"
],
"schedule": {
"kind": "cron",
"expr": "0 20 * * *",
"display": "every day at 8pm"
},
"schedule_display": "every day at 8pm",
"repeat": {
"times": null,
"completed": 15
},
"enabled": true,
"state": "scheduled",
"paused_at": null,
"paused_reason": null,
"created_at": "2026-09-15T18:04:47.618125-05:00",
"next_run_at": "2026-10-02T20:00:00-05:00",
"last_run_at": "2026-10-01T20:09:22.442321-05:00",
"last_status": "ok",
"last_error": null,
"last_delivery_error": null,
"last_delivery_unverified": null,
"failure_streak": 0,
"deliver": "origin",
"origin": null,
"enabled_toolsets": null,
"workdir": "/home/avi/Projects/Keynctr",
"last_dispatch": {
"scheduled_at": "2026-10-01T20:00:00-05:00",
"dispatched_at": "2026-10-01T20:00:14.192625-05:00",
"lateness_seconds": 14.2,
"kind": "on_time"
},
"fire_claim": null
},
{
"id": "9eb58342f44c",
"name": "polaris-daily-note",
"prompt": "You are writing Avi's Polaris daily note (360 view), modeled on his supervisor's workflow. Steps: (1) cd ~/Projects/Polaris and read wiki/hot.md and AGENTS.md. (2) Gather across ~/Projects repos: yesterday's commits (git -C <repo> log --since=yesterday --oneline), any repos with uncommitted changes (git status --porcelain | wc -l), and which repos have no origin remote. Skip postgres_data and non-repo folders. (3) Write the daily note to ~/Projects/Polaris/0. Inbox/YYYY-MM-DD daily.md using 6. Templates/daily-note.md as the skeleton: active projects/workstreams from the vault, what changed yesterday per repo, anything uncommitted or unbacked-up, what's owed next (next: fields from hubs), and open threads. Keep it under 60 lines, plain, no fluff. (4) git add the exact note path, commit 'Daily note YYYY-MM-DD', then push to origin using the extraHeader trick is NOT possible (no stored token) — just commit locally; Syncthing carries it off-device. (5) Deliver a 5-line summary of the daily note to the user.",
"skills": [],
"skill": null,
"model": null,
"provider": null,
"provider_snapshot": "custom",
"model_snapshot": "qwen3.8-flash-next",
"base_url": null,
"script": null,
"no_agent": false,
"monitor_script": null,
"monitor_url": null,
"monitor_state": null,
"context_from": null,
"schedule": {
"kind": "cron",
"expr": "0 8 * * *",
"display": "0 8 * * *"
},
"schedule_display": "0 8 * * *",
"repeat": {
"times": null,
"completed": 8
},
"enabled": true,
"state": "scheduled",
"paused_at": null,
"paused_reason": null,
"created_at": "2026-09-23T19:00:48.282536-05:00",
"next_run_at": "2026-10-03T08:00:00-05:00",
"last_run_at": "2026-10-02T08:03:00.498501-05:00",
"last_status": "ok",
"last_error": null,
"last_delivery_error": null,
"last_delivery_unverified": null,
"failure_streak": 0,
"deliver": "origin",
"origin": null,
"enabled_toolsets": [
"terminal",
"file"
],
"workdir": null,
"last_dispatch": {
"scheduled_at": "2026-10-02T08:00:00-05:00",
"dispatched_at": "2026-10-02T08:00:24.793283-05:00",
"lateness_seconds": 24.8,
"kind": "on_time"
},
"fire_claim": null
}
],
"updated_at": "2026-10-02T08:25:29.494029-05:00"
}

View file

@ -0,0 +1,13 @@
#!/bin/sh
# Deterministic release watcher for the monitor:
# prints ONLY the latest release tag (or the API error body if GitHub is down).
# No timestamps, no fluctuating fields -> ticks skip the agent unless the tag changes.
loc=$(curl -sI --max-time 15 https://github.com/NousResearch/hermes-agent/releases/latest \
| grep -i '^location:' | head -1 | sed -E 's|.*/tag/([^[:space:]]+).*|\1|' | tr -d '\r')
if [ -n "$loc" ]; then
printf 'HERMES_RELEASE=%s\n' "$loc"
else
# fallback: GitHub API (rate-limited, but only used when the redirect fails)
curl -s --max-time 15 https://api.github.com/repos/NousResearch/hermes-agent/releases/latest \
| grep -m1 '"tag_name"' | sed -E 's/.*"tag_name": *"([^"]+)".*/\1/' | sed 's/^/HERMES_RELEASE=/'
fi

View file

@ -0,0 +1,91 @@
#!/usr/bin/env python3
"""Regenerate the Obsidian skills index from ~/.hermes/skills/.
Reads every SKILL.md's YAML frontmatter (name/description) and rewrites
03-SKILLS/Knowledge Vault Skills Index.md. Machine-generated: hand edits
are overwritten on the next run (hourly via vault-sync.sh).
"""
import datetime
import pathlib
import re
import sys
SKILLS_DIR = pathlib.Path.home() / ".hermes/skills"
OUT = pathlib.Path("/home/avi/Orion/03-SKILLS/Knowledge Vault Skills Index.md")
FM_RE = re.compile(r"^---\s*\n(.*?)\n---", re.S)
def frontmatter(text: str) -> dict:
m = FM_RE.match(text)
if not m:
return {}
fm = {}
current_key = None
for line in m.group(1).splitlines():
kv = re.match(r"^([A-Za-z0-9_-]+):\s*(.*)$", line)
if kv:
current_key, val = kv.group(1), kv.group(2).strip()
fm[current_key] = val
elif current_key and line.strip().startswith(("-", "|", ">", '"')):
# multi-line value continuation; keep it simple — append
fm[current_key] = (fm[current_key] + " " + line.strip(" -|>\"")).strip()
elif current_key and line.startswith((" ", "\t")):
fm[current_key] = (fm[current_key] + " " + line.strip()).strip()
return fm
def main() -> int:
if not SKILLS_DIR.is_dir():
print(f"skills-index: no skills dir at {SKILLS_DIR}", file=sys.stderr)
return 1
rows = []
for skill_md in SKILLS_DIR.rglob("SKILL.md"):
rel = skill_md.parent.relative_to(SKILLS_DIR)
category = rel.parent.as_posix() if str(rel.parent) != "." else "general"
try:
fm = frontmatter(skill_md.read_text(encoding="utf-8", errors="replace"))
except OSError as e:
print(f"skills-index: read failed {skill_md}: {e}", file=sys.stderr)
continue
name = fm.get("name") or skill_md.parent.name
desc = fm.get("description", "").strip("\"'")
# truncate long descriptions; Obsidian table cells stay readable
if len(desc) > 160:
desc = desc[:157].rsplit(" ", 1)[0] + "…"
# first 57 chars double as the trigger line
rows.append((category, name, desc, rel.as_posix()))
rows.sort()
now = datetime.datetime.now().astimezone()
lines = [
"---",
f"last-updated: {now.isoformat(timespec='seconds')}",
"index-version: 2.0",
f"skills-count: {len(rows)}",
"generated: true",
"---",
"# Hermes Skills Index — Capability Catalog",
"",
"> **Purpose:** registry of every skill available to Hermes on this machine.",
"> **Machine-generated** by `~/.hermes/scripts/skills-index.py` (runs hourly",
"> inside `vault-sync.sh`). Do not hand-edit — edits are overwritten.",
"> Full skill text lives in `03-SKILLS/hermes-skills/<path>/SKILL.md`.",
"",
f"_Skills: **{len(rows)}** across **{len({r[0] for r in rows})}** categories._",
"",
]
cur = None
for category, name, desc, path in rows:
if category != cur:
cur = category
lines += ["", f"## {category}", "", "| Skill | Description | Path |",
"|---|---|---|"]
lines.append(f"| `{name}` | {desc} | [[hermes-skills/{path}/SKILL\\|SKILL.md]] |")
lines.append("")
OUT.write_text("\n".join(lines), encoding="utf-8")
return 0
if __name__ == "__main__":
sys.exit(main())

View file

@ -0,0 +1,34 @@
#!/usr/bin/env bash
# Mirror Hermes state into the Orion disaster-recovery location.
# Prints nothing on success (cron: no notification); prints errors only.
set -u
VAULT="/home/avi/Orion"
ERRS=""
H="$VAULT/2. Areas/Home Personal/knowledge/hermes"
# 1. Skills -> 03-SKILLS/hermes-skills/
rsync -a --delete ~/.hermes/skills/ "$VAULT/03-SKILLS/hermes-skills/" || ERRS="skills rsync failed"
# 1b. Rebuild the curated skills index from the mirrored SKILL.md frontmatter
python3 ~/.hermes/scripts/skills-index.py >/dev/null 2>/tmp/skills-index.err || ERRS="${ERRS} skills-index failed: $(head -c200 /tmp/skills-index.err)"
# 2. Automation scripts + cron job definitions -> 04-SYSTEMS/hermes-automation/
mkdir -p "$H/hermes-automation"
rsync -a --delete ~/.hermes/scripts/ "$H/hermes-automation/scripts/" || ERRS="${ERRS} scripts-sync failed"
cp ~/.hermes/cron/jobs.json "$H/hermes-automation/cron-jobs.json" 2>&1 || ERRS="${ERRS} cron-jobs-copy failed"
# 3. Legacy memories + config -> 04-SYSTEMS/hermes-memory/
cp ~/.hermes/memories/MEMORY.md ~/.hermes/memories/USER.md "$H/hermes-memory/" 2>&1 || ERRS="${ERRS} memory-copy failed"
cp ~/.hermes/config.yaml "$H/hermes-config.yaml" 2>&1 || ERRS="${ERRS} config-copy failed"
# 4. Mnemosyne DB (hot backup, WAL-safe) + last JSON export -> 04-SYSTEMS/hermes-memory/
SQLITE=/home/avi/.local/android-sdk/platform-tools/sqlite3
if [ -x "$SQLITE" ]; then
"$SQLITE" "/home/avi/.hermes/mnemosyne/data/mnemosyne.db" ".backup '$H/hermes-memory/mnemosyne.db'" 2>&1 || ERRS="${ERRS} db-backup failed"
fi
# 5. Timestamp for the agent pass to know what's new since last sync
date -Iseconds > "$H/hermes-memory/.last-sync"
[ -n "$ERRS" ] && echo "VAULT SYNC ERRORS: $ERRS"
exit 0

View file

@ -0,0 +1,33 @@
#!/usr/bin/env bash
# Mirror Hermes state into the 484vault disaster-recovery location.
# Prints nothing on success (cron: no notification); prints errors only.
set -u
VAULT="/home/avi/484vault"
ERRS=""
# 1. Skills -> 03-SKILLS/hermes-skills/
rsync -a --delete ~/.hermes/skills/ "$VAULT/03-SKILLS/hermes-skills/" || ERRS="skills rsync failed"
# 1b. Rebuild the curated skills index from the mirrored SKILL.md frontmatter
python3 ~/.hermes/scripts/skills-index.py >/dev/null 2>/tmp/skills-index.err || ERRS="${ERRS} skills-index failed: $(head -c200 /tmp/skills-index.err)"
# 2. Automation scripts + cron job definitions -> 04-SYSTEMS/hermes-automation/
mkdir -p "$VAULT/04-SYSTEMS/hermes-automation"
rsync -a --delete ~/.hermes/scripts/ "$VAULT/04-SYSTEMS/hermes-automation/scripts/" || ERRS="${ERRS} scripts-sync failed"
cp ~/.hermes/cron/jobs.json "$VAULT/04-SYSTEMS/hermes-automation/cron-jobs.json" 2>&1 || ERRS="${ERRS} cron-jobs-copy failed"
# 3. Legacy memories + config -> 04-SYSTEMS/hermes-memory/
cp ~/.hermes/memories/MEMORY.md ~/.hermes/memories/USER.md "$VAULT/04-SYSTEMS/hermes-memory/" 2>&1 || ERRS="${ERRS} memory-copy failed"
cp ~/.hermes/config.yaml "$VAULT/04-SYSTEMS/hermes-config.yaml" 2>&1 || ERRS="${ERRS} config-copy failed"
# 4. Mnemosyne DB (hot backup, WAL-safe) + last JSON export -> 04-SYSTEMS/hermes-memory/
SQLITE=/home/avi/.local/android-sdk/platform-tools/sqlite3
if [ -x "$SQLITE" ]; then
"$SQLITE" "/home/avi/.hermes/mnemosyne/data/mnemosyne.db" ".backup '$VAULT/04-SYSTEMS/hermes-memory/mnemosyne.db'" 2>&1 || ERRS="${ERRS} db-backup failed"
fi
# 5. Timestamp for the agent pass to know what's new since last sync
date -Iseconds > "$VAULT/04-SYSTEMS/hermes-memory/.last-sync"
[ -n "$ERRS" ] && echo "VAULT SYNC ERRORS: $ERRS"
exit 0

View file

@ -0,0 +1,294 @@
model:
default: qwen3.8-flash-next
provider: custom
base_url: http://10.50.200.200:8100/v1
api_key: ${HERMES_CUSTOM_10_50_200_200_8100_API_KEY}
context_length: 250000
database:
journal_mode: wal
runtime:
nofile_soft_limit: 4096
agent:
max_turns: 150
service_tier: ''
fast_auto_seconds: 60
verbose: false
reasoning_effort: medium
personalities: {}
terminal:
backend: local
cwd: .
timeout: 180
home_mode: auto
container_cpu: 1
container_memory: 5120
container_disk: 51200
container_persistent: true
docker_mount_cwd_to_workspace: false
lifetime_seconds: 300
web:
search_backend: searxng
extract_backend: firecrawl
extract_char_limit: 15000
keyless_fallback: true
keyless_rescue: true
cache_enabled: true
cache_ttl_minutes: 20
browser:
backend: browser-use
inactivity_timeout: 120
extension_control:
enabled: false
use_real_profile: true
tool_loop_guardrails:
warnings_enabled: true
hard_stop_enabled: false
non_interactive_hard_stop_enabled: true
warn_after:
exact_failure: 2
same_tool_failure: 3
idempotent_no_progress: 2
hard_stop_after:
exact_failure: 5
same_tool_failure: 8
idempotent_no_progress: 5
compression:
enabled: true
checkpoint_required: false
progress_notices: false
threshold: 0.5
target_ratio: 0.2
protect_last_n: 20
min_tail_user_messages: 1
max_attempts: 3
proactive_prune_tokens: 0
proactive_prune_min_result_chars: 8000
proactive_prune_min_reclaim_tokens: 4096
hygiene_max_turn_hold_seconds: 10
protect_first_n: 3
codex_gpt55_autoraise: true
codex_app_server_auto: native
codex_responses_native: false
idle_compact_after_seconds: 0
prompt_caching:
cache_ttl: 5m
display:
compact: false
busy_input_mode: interrupt
bell_on_complete: false
bell_on_prompt: false
show_reasoning: false
background_process_notifications: concise
streaming: true
skin: cybernetic-workshop
interim_assistant_messages: true
tool_progress: all
cleanup_progress: false
long_running_notifications: true
busy_ack_detail: true
stt:
enabled: true
language: en
local:
model: base
openai:
model: whisper-1
language: ''
wake_word:
enabled: true
memory:
memory_enabled: true
user_profile_enabled: true
memory_char_limit: 2200
user_char_limit: 1375
nudge_interval: 10
provider: mnemosyne
delegation:
max_iterations: 250
skills:
creation_nudge_interval: 15
approvals:
timeout: 99999999
plugins:
enabled:
- mnemosyne
- rtk-rewrite
- superpowers
disabled: []
kanban:
review_dispatch: true
code_execution:
timeout: 300
max_tool_calls: 50
gateway:
signal_interrupt_grace_timeout: 1
delivery_ledger: true
platform_connect_timeout: 30
loop_watchdog: true
loop_watchdog_probe_interval_s: 30.0
loop_watchdog_probe_timeout_s: 10.0
loop_watchdog_max_strikes: 3
startup_watchdog: true
startup_watchdog_timeout_seconds: 300
write_sessions_json: true
scale_to_zero:
idle_timeout_minutes: 2
restart_loop_guard:
max_restarts: 3
window_seconds: 60
max_gap_seconds: 300
respawn_storm:
max_starts: 5
window_seconds: 120
message_timestamps:
enabled: false
max_inbound_media_bytes: 134217728
trust_env: true
strict: false
media_delivery_allow_dirs: []
trust_recent_files: true
trust_recent_files_seconds: 600
api_server:
max_concurrent_runs: 10
streaming:
enabled: false
onboarding:
seen:
busy_input_prompt: true
telemetry:
shared_metrics:
enabled: false
send: false
updates:
pre_update_backup: false
backup_keep: 5
non_interactive_local_changes: stash
computer_use:
backend: cua
_config_version: 45
session_reset:
mode: none
idle_minutes: 1440
at_hour: 4
group_sessions_per_user: true
platform_toolsets:
cli:
- browser
- clarify
- code_execution
- computer_use
- connections
- cronjob
- delegation
- file
- image_gen
- memory
- session_search
- skills
- terminal
- todo
- tts
- vision
- web
telegram:
- hermes-telegram
discord:
- hermes-discord
whatsapp:
- hermes-whatsapp
slack:
- hermes-slack
signal:
- hermes-signal
homeassistant:
- hermes-homeassistant
qqbot:
- hermes-qqbot
yuanbao:
- hermes-yuanbao
teams:
- hermes-teams
google_chat:
- hermes-google_chat
custom_providers:
- name: h200
base_url: http://10.50.200.200:8100/v1
key_env: HERMES_CUSTOM_10_50_200_200_8100_API_KEY
model: qwen3.8-flash-next
models:
qwen3.8-flash-next:
context_length: 262144
image_gen:
provider: openai-codex
model: gpt-image-2-medium
known_plugin_toolsets:
cli:
- a2a
- spotify
known_builtin_toolsets:
cli:
- browser
- clarify
- code_execution
- computer_use
- connections
- context_engine
- cronjob
- delegation
- discord
- discord_admin
- file
- homeassistant
- image_gen
- memory
- session_search
- skills
- spotify
- stt
- terminal
- todo
- tts
- video
- video_gen
- vision
- web
- x_search
- yuanbao
# ── Security ──────────────────────────────────────────────────────────
# Secret redaction is ON by default — strings that look like API keys,
# tokens, and passwords are masked in tool output, logs, and chat
# responses before the model or user ever sees them. Set redact_secrets
# to false to disable (e.g. when developing the redactor itself).
# tirith pre-exec scanning is enabled by default when the tirith binary
# is available. Configure via security.tirith_* keys or env vars
# (TIRITH_ENABLED, TIRITH_BIN, TIRITH_TIMEOUT, TIRITH_FAIL_OPEN).
#
# security:
# redact_secrets: true
# tirith_enabled: true
# tirith_path: "tirith"
# tirith_timeout: 5
# tirith_fail_open: true
# ── Fallback Model ────────────────────────────────────────────────────
# Automatic provider failover when primary is unavailable.
# Uncomment and configure to enable. Triggers on rate limits (429),
# overload (529), service errors (503), or connection failures.
#
# Supported providers:
# openrouter (OPENROUTER_API_KEY) — routes to any model
# openai-codex (OAuth — hermes auth) — OpenAI Codex
# nous (OAuth — hermes auth) — Nous Portal
# zai (ZAI_API_KEY) — Z.AI / GLM
# kimi-coding (KIMI_API_KEY) — Kimi / Moonshot
# kimi-coding-cn (KIMI_CN_API_KEY) — Kimi / Moonshot (China)
# minimax (MINIMAX_API_KEY) — MiniMax
# minimax-cn (MINIMAX_CN_API_KEY) — MiniMax (China)
# bedrock (AWS IAM / boto3) — AWS Bedrock (Converse API)
#
# For custom OpenAI-compatible endpoints, add base_url and key_env.
#
# fallback_model:
# provider: openrouter
# model: anthropic/claude-sonnet-4

View file

@ -0,0 +1,11 @@
Gotcha: avdmanager writes AVDs to ~/.config/.android — copy to ~/.android/avd or emulator can't find them. Omarchy SUPER+J togglesplit fails when workspace pinned 'scrolling' (~/.local/state/omarchy/workspace-layouts/<ws>.lua, written by SUPER+L) or focused window is floating (Hermes app window is floating).
§
Hyprland on this box wraps `hyprctl dispatch` in a Lua shim — classic syntax fails. Use Lua form: `hyprctl dispatch "hl.dsp.focus({window='pid:N'})"`, `hl.dsp.window.bring_to_top(...)`, `hl.dsp.focus({workspace='N'})`. omafiles is single-instance via shared ~/.local/state/omafiles/session.toml — test instances need isolated XDG_STATE_HOME. WirePlumber 0.5.17 gotcha: invalid monitor.bluez.properties drop-ins silently kill ALL BT audio ("Protocol not available" in bluetoothd) — verify endpoints via `busctl tree org.bluez | grep MediaEndpoint` after any wireplumber config change.
§
Keynctr dev mode: run `npx vite --port 5173` then `NOSTR_GUI_DEV_URL=http://localhost:5173 KEYNCTR_ENABLE_GPU=1 npx electron .` in frontend/ (after cargo build --release — Electron spawns target/release/keynectr serve). UI edits hot-reload; Rust edits need rebuild + backend restart. Amber fixes committed f917e5e.
§
Shonar desktop source lives only on branch deferred/desktop-server @7b34368 (removed from main 8c510f4); the dead ~/Projects/Shonar/desktop leftovers dir was deleted Sep 14. Separate live repo ~/Projects/Shonar Desktop (master, engine :8000 via desktop-dev.sh) still runs the desktop app. Runtime state ~/.config/shonar-desktop/ (settings.json read at engine start; engine.db).
§
Vizio E3D470VX TV: laptop flaps link then 'no signal' — fix = force 1920x1080@59.94 on DP output when Vizio detected (same as Epson projector fix). skill_manage gotcha: patch op needs old_string+new_string; file_content is ignored ('old_string is required' loop). Full rewrite of a references/ file = write_file op.
§
Avi's Wi-Fi (10.144.x.x) isolates devices — phone can never reach laptop LAN IPs; share local apps via cloudflared quick tunnel (~/.local/bin/cloudflared tunnel --url http://localhost:PORT) + qrencode QR (typing trycloudflare URLs on the phone fails). He rejects USB/adb workarounds.

View file

@ -0,0 +1,33 @@
# Restoring Hermes from this vault (computer-dies procedure)
> **Path note (2026-10-01 Orion reorg):** `04-SYSTEMS/hermes-memory/`, `04-SYSTEMS/hermes-config.yaml` and `04-SYSTEMS/hermes-automation/` below now live under `2. Areas/Home Personal/knowledge/hermes/` (this file's own directory). Daily knowledge-routing now targets the Orion areas (`2. Areas/*/knowledge/`, `3. Resources/Research/`, `4. Decisions/`).
If a brand-new Hermes instance is installed on a new machine, point it at this vault and it can rebuild itself from these pieces:
## What's here
- `03-SKILLS/hermes-skills/` — full copy of `~/.hermes/skills/` (learned procedures + scripts/templates/references).
- `03-SKILLS/Knowledge Vault Skills Index.md` — machine-generated catalog of every skill (name, trigger description, path). Do not hand-edit; rebuilt hourly.
- `04-SYSTEMS/hermes-memory/mnemosyne-export.json` — full Mnemosyne export (working memories, annotations, canonical facts). Restorable with the `mnemosyne_import` tool (`input_path` mode).
- `04-SYSTEMS/hermes-memory/mnemosyne.db` — hourly WAL-safe live copy of the Mnemosyne DB (superset of the JSON export; use this if the JSON is older).
- `04-SYSTEMS/hermes-memory/MEMORY.md` + `USER.md` — legacy Hermes memory + user profile.
- `04-SYSTEMS/hermes-config.yaml` — Hermes config. Contains NO literal secrets (API keys are `${ENV_VAR}` references); the env vars themselves live in `~/.hermes/.env` which is deliberately NOT copied here.
- `04-SYSTEMS/hermes-automation/` — `scripts/` (vault-sync.sh, skills-index.py, release-watch) and `cron-jobs.json` (all scheduled job definitions, so automation can be recreated without re-authoring prompts).
## Restore steps for the new instance
1. `cp -a "<vault>/03-SKILLS/hermes-skills/." ~/.hermes/skills/`
2. Ask the agent to run `mnemosyne_import` with `input_path` = this vault's `04-SYSTEMS/hermes-memory/mnemosyne-export.json` (idempotent; skips duplicates).
3. `cp` the two memory files into `~/.hermes/memories/`.
4. Diff `hermes-config.yaml` against the new default config rather than blind-copying (schema may have changed).
5. Restore automation: `cp -a "<vault>/04-SYSTEMS/hermes-automation/scripts/." ~/.hermes/scripts/`, then recreate the cron jobs from `cron-jobs.json` (names, schedules, and full prompts are in there).
6. Re-supply secrets: set the env vars referenced in config (e.g. `HERMES_CUSTOM_*_API_KEY`) in `~/.hermes/.env`. These are NOT in the vault by design.
## Automatic sync (running since 2026-09-11)
- **Hourly** (cron `vault-sync-mechanical`, script `~/.hermes/scripts/vault-sync.sh`): mirrors skills dir, rebuilds the skills index, copies automation scripts + cron job definitions, memory .md files, config, and a WAL-safe live copy of the Mnemosyne DB into this vault. Silent unless it errors.
- **Daily 11pm** (cron `vault-knowledge-routing`): agent reviews new memories/skills since `.last-sync` and routes them to `02-WORKFLOWS/`, `04-SYSTEMS/`, `05-KNOWLEDGE/`, `06-DECISIONS/`, `07-TROUBLESHOOTING/` as proper notes.
- `.last-sync` in this dir marks the last successful hourly sync.
## Known limits
- Secrets (`~/.hermes/.env`) are intentionally NOT in the vault — a new machine needs them re-entered.
- `~/.hermes/sessions/` (raw chat transcripts, ~360K) is not backed up; memory + skills are the durable layer. Say the word if you want transcripts mirrored too.
Last verified: 2026-09-13 (by Hermes, full audit + gap fixes).

View file

@ -0,0 +1,9 @@
Design/doc preferences: no metaphor framing in design docs — describe systems plainly (metaphors read as confusing). Visual taste = subtle ambient effects; when something "looks odd" dial it down, don't delete it. Expects per-unit commits and on-device verification (screencap/dumpsys readback) before any feature is reported done.
§
Scope pivots mid-build: expects prior work preserved-but-isolated (deferred branch/module), never deleted, and directives obeyed immediately. Wants honest status over optimistic UI — unfinished integrations must be labeled/hid, not left configurable.
§
Runs Hermes on a Framework Laptop (Omarchy/Hyprland). Disaster-recovery knowledge base = Obsidian vault at /home/avi/484vault (auto-synced off-device via Syncthing to phone + server; user chose Syncthing because his Nextcloud server lacks full uptime). Prefers automation of durable chores over being asked to repeat them.
§
Don't deep-verify the user's Syncthing/sync health unless asked — he knows his own sync topology and cut off a live verification dive as unnecessary.
§
Answers the exact ask: a small specific question gets just that answer — no unsolicited adjacent repo work (cut off mid-flight surgery over this: "i was just asking for a short description... what are you doing?"). Large fixes are fine when he requests them; scope creep is not.

File diff suppressed because one or more lines are too long