Wiki article · Published October 2, 2026 · Living document

Hermes

Fail-closed macOS execution layer for agent-driven work — Apache-2.0, early scaffold

Agents that can act on a real Mac are a high-blast-radius control plane. Hermes makes execution narrow, inspectable, and fail-closed: allowlists decide what may run, gates decide when, receipts record what did.

Golden Gate Book
Wiki · MMXXVI

Hermes (repository hermes-refuse) is a fail-closed execution layer for agent-driven work on macOS, built by Marcus Richards and published as open source under the Apache-2.0 license. It provides allowlisted capabilities, exact target resolution, isolated execution, independent validation, rollback, idempotent operations, redacted append-only receipts, and a safe Automator front end, explicitly without unrestricted shell access, root privilege, credential access, network authority, or deletion power.

It is a technical artifact of Memory Utility Labs and is intended for the AEGIS and AION stack. As of October 2026 it is an early public scaffold: the architecture and boundaries are documented, implementation is landing, and production readiness is explicitly not claimed. It is not affiliated with Quantify Labs' Aegis Memory.

Background

Agents and automations that can act on a real Mac create a high-blast-radius control plane. A single ambiguous path, an over-broad shell grant, or a silent success without audit turns helpful automation into uncontrolled system change. Hermes exists to make that execution narrow, inspectable, and fail-closed: when anything is ambiguous, the answer is refusal, not a best guess.

Design

Execution passes through a fixed set of controls. Allowlisted capabilities define what may run at all. Exact target resolution requires every path, app, or resource to resolve to exactly one candidate; ambiguity refuses. Isolated execution contains the blast radius. Independent validation checks the result separately from the actor that produced it. Rollback and idempotent operations make actions safe to retry and safe to undo. Every execution writes a redacted, append-only receipt, so the audit trail survives even when the action itself is sensitive. A safe Automator front end gives humans a governed way to invoke the layer.

The negative space is the point. Hermes grants no unrestricted shell, no root, no credential access, no network authority, and no deletion power. A capability that is not explicitly granted does not exist.

Threat model

The documented threat model names its assets, host filesystem integrity, credentials and secrets, network identity, the privilege boundary, and auditability, and designs against seven failure modes:

  • Over-broad agent intent, a model asking to "clean up" without a named, resolvable target.
  • Ambiguous resolution, a target resolving to more than one candidate.
  • Privilege escalation, a request implying root, credential access, or unrestricted shell.
  • Silent mutation, work that appears to succeed with no receipt.
  • Replay and double-apply, the same action compounding damage.
  • Confused deputy, a front end used to bypass allowlist policy.
  • Supply-chain and prompt injection, untrusted content coercing forbidden capabilities.

Explicitly out of scope for now: full malware analysis of third-party binaries Hermes might invoke, and guarantees against a human operator who already holds admin.

Limitations

What is not claimed. Hermes is an early scaffold, and its own documentation says so directly: the document describes intended architecture and boundaries, implementation is landing, and production readiness should not be assumed. It is a design with a threat model, not yet a hardened system.

Development history

Hermes was created in September 2026 and published under the Apache-2.0 license as an early public scaffold. Development continues as of October 2026.

See also

  • AEGIS, the governance substrate Hermes is intended to serve
  • Interlock, the agent safety substrate

References

  1. Hermes source repository. github.com/marsojuji-cmyk/hermes-refuse (public, Apache-2.0).