تأمين Hermes على جهاز شخصي أو جهاز عمل
Running Hermes on a Personal or Work Machine
ما هذه الصفحة، وماذا تحتوي.
الأمان والموافقات: القواعد التي تحدّد ما يفعله Hermes وحده، وما يجب أن يستأذنك فيه أولًا. الوكيل ينفّذ ما فهمه لا ما قصدته. الموافقة هي فرصتك لتصحيح الفهم قبل أن يقع الفعل. الصفحة فيها تحذير من المصدر، و8 دقائق قراءة. انتبه: لا تلغِ الموافقات لتوفير الوقت. ابدأ بصلاحية القراءة فقط، ووسّع خطوة خطوة بعد أن تثق بالنتائج.
A security-posture walkthrough for running Hermes Agent on the machine you live on — what the defaults protect, how to tighten further, and how to undo mistakes
نتائج مأخوذة من هذه الصفحة، لا من قالب.
- تعرف ما الأمان والموافقات ولماذا قد تحتاجه.
- تنفّذ
hermes chatوتفهم ما يحدث بعدها. - تقرأ الجدول وتأخذ منه السطر الذي يخصّك فقط.
- تضبط
HERMES_WRITE_SAFE_ROOTفي المكان الصحيح.
كما تظهر تمامًا داخل Hermes.
hermes chat
HERMES_WRITE_SAFE_ROOTTERMINAL_SSH_HOSTTERMINAL_SSH_USERTERMINAL_SSH_KEYGATEWAY_ALLOW_ALL_USERSTELEGRAM_ALLOWED_USERSGATEWAY_ALLOWED_USERS
انتقل مباشرة إلى ما تحتاجه.
بلا اختصار أو حذف.
النص أدناه منقول من المصدر الرسمي بالإنجليزية حتى تبقى الأوامر والأسماء دقيقة كما هي. قبل كل قسم شرح عربي يوضّح ما بداخله.
You're about to run an agent on the machine you live on — a personal laptop or an employer-managed workstation. What's the safe posture?
Short answer: the defaults already do most of the work. Hermes ships secure-by-default, with a defense-in-depth model covering command approval, file-write safety, and credential handling. This page walks through what's on out of the box, which knobs to tighten for a shared or work machine, and how to undo mistakes when they happen. Every control here is covered in depth in the Security guide.
What the Defaults Already Protect
شرح للفكرة نفسها. اقرأه ببطء، فبقية الأقسام تبني عليه. تذكير: القواعد التي تحدّد ما يفعله Hermes وحده، وما يجب أن يستأذنك فيه أولًا.
Fresh install, no configuration — these protections are active:
Dangerous commands require approval. Before executing any command, Hermes checks it against a curated list of dangerous patterns — recursive deletes, writes to /etc/, disk operations, pipe-to-shell, and more. The default approvals.mode: smart uses an auxiliary LLM to assess risk: low-risk commands are auto-approved for that command only, genuinely dangerous commands are auto-denied, and uncertain cases escalate to a manual prompt.
Approval prompts fail closed. If you don't respond to an approval prompt within the timeout (default 300 seconds), the command is denied. Walking away from your desk never silently approves anything.
A hardline blocklist is the always-on floor. Some commands — rm -rf /, fork bombs, zeroing a physical disk — are refused regardless of approval mode, --yolo, or an explicit "allow always". The blocklist trips before the approval layer even sees the command, and there is no override flag.
File writes to sensitive paths are blocked. The write_file and patch tools cannot touch OS credential stores (~/.ssh/, ~/.aws/, ~/.kube/, /etc/sudoers, ~/.netrc), Hermes credential stores (auth.json, .env, pairing data), or project secret files (.env, .env.local, .envrc) anywhere on disk. Blocked writes return an error immediately — there is no approval prompt and no way to override from the chat UI.
Secrets are redacted from output. security.redact_secrets is on by default: patterns that look like API keys, tokens, and passwords in tool output are redacted before they enter the conversation context and logs.
Your data goes only where you point it. API calls go only to the LLM provider you configure. Hermes Agent does not collect telemetry, usage data, or analytics. Your conversations, memory, and skills are stored locally in ~/.hermes/. See the FAQ.
The Undo Layer: Checkpoints and `/rollback`
جدول مرجعي. لا تقرأه كله، ابحث عن السطر الذي يخصّك فقط. الأوامر هنا: hermes chat.
Approval gates prevent damage; checkpoints reverse it. When enabled, Hermes automatically snapshots your project before destructive operations — write_file, patch, and destructive terminal commands like rm, mv, sed -i, and git reset — into a shadow git store under ~/.hermes/checkpoints/store/. Your real project .git is never touched.
Checkpoints are opt-in. Enable per-session:
hermes chat --checkpointsOr globally:
checkpoints:
enabled: trueThen, in a session:
| Command | Description |
|---|---|
/rollback | List all checkpoints with change stats |
/rollback diff <N> | Preview what changed since checkpoint N |
/rollback <N> | Restore to checkpoint N (also undoes the last chat turn) |
/rollback <N> <file> | Restore a single file from checkpoint N |
What This Threat Model Is — and Isn't
شرح للفكرة نفسها. اقرأه ببطء، فبقية الأقسام تبني عليه.
Be clear-eyed about what these controls defend against. As the Security guide puts it:
Deny rules are a guardrail against an honest-but-wrong agent, the same threat model as the dangerous-pattern detector. They are not a sandbox against a deliberately adversarial process — for that, use an isolated backend (Docker, Modal) or an egress-restricted environment.
The same applies to the file-write guards: they apply to write_file and patch only, while the terminal tool runs as the same OS user. The denylist reduces accidental damage and gives models a clear stop signal; it does not sandbox a hostile or compromised agent. If your requirement is containment rather than guardrails, the answer is an isolated terminal backend — that's the boundary designed for it.
A Cautious Starting Config
إعدادات تضبطها مرة وتنساها. غيّر واحدًا في كل مرة حتى تعرف أثر كل تغيير. تضبط HERMES_WRITE_SAFE_ROOT خارج المحادثة، في بيئة التشغيل.
Everything above, assembled. Adjust to taste in ~/.hermes/config.yaml:
approvals:
mode: manual # See every flagged command yourself
timeout: 300 # Unanswered prompts are denied (fail-closed)
deny: # Never-run list — survives even /yolo
- "git push --force*"
- "*curl*|*sh*"
- "dd if=* of=/dev/*"
security:
redact_secrets: true # Already the default; stated here for clarity
checkpoints:
enabled: true # Snapshot before destructive operations
terminal:
backend: docker # Or ssh — keep execution off the host
docker_forward_env: [] # No host secrets inside the containerAnd in ~/.hermes/.env, if you want the write sandbox:
HERMES_WRITE_SAFE_ROOT=/path/to/project:/home/you/.hermesSee Also
شرح للفكرة نفسها. اقرأه ببطء، فبقية الأقسام تبني عليه.
- Security — the full defense-in-depth reference: every approval pattern, container hardening flags, gateway authorization, MCP credential filtering
- Checkpoints & Rollback — configuration, store maintenance, and restore workflows
- Tools & Toolsets — all terminal backends and their configuration
- Configuration — the complete
config.yamlreference
5 أسئلة إجاباتها كلها في هذه الصفحة.
كل خيار اسم حقيقي من توثيق Hermes. حتى الخيارات الخاطئة حقيقية، لكنها من صفحات أخرى.