الأكاديمية ← ميزات Hermesتوثيق رسمي · إرشاد عربي

الأدوات ومجموعات الأدوات

Tools & Toolsets

متوسط إلى متقدم9 دقائق قراءةالدرس 25 أسئلة✓ 2026-08-18
قبل أن تقرأ

ما هذه الصفحة، وماذا تحتوي.

الأدوات: الأفعال التي يستطيع Hermes تنفيذها فعلًا: قراءة ملف، تشغيل أمر، البحث في الويب، إرسال رسالة. الفرق بين مساعد يتكلّم ووكيل ينجز هو الأدوات. من دونها يبقى كلامًا. الصفحة فيها تحذير من المصدر، و9 دقائق قراءة. انتبه: كل أداة تفتح بابًا. أدوات الكتابة والحذف والإرسال تستحق وقفة قبل تفعيلها، وليست كل مهمة تحتاجها.

6أقسام
13أمثلة برمجية
2جداول
4أوامر
1,527كلمة من المصدر
الوصف الرسمي في سطر

Overview of Hermes Agent's tools — what's available, how toolsets work, and terminal backends

ماذا ستستطيع بعدها

نتائج مأخوذة من هذه الصفحة، لا من قالب.

  • تعرف ما الأدوات ولماذا قد تحتاجه.
  • تنفّذ hermes config set terminal وhermes chat وتفهم ما يحدث بعدها.
  • تقرأ الجدول وتأخذ منه السطر الذي يخصّك فقط.
  • تضبط NVM_DIR في المكان الصحيح.
ما ستقابله من أسماء

كما تظهر تمامًا داخل Hermes.

الأوامر
  • hermes config set terminal
  • hermes chat
  • hermes tools
  • hermes model
متغيرات البيئة
  • NVM_DIR
  • TERMINAL_SSH_HOST
  • TERMINAL_SSH_USER
  • TERMINAL_SSH_KEY
  • VERCEL_TOKEN
  • VERCEL_PROJECT_ID
  • VERCEL_TEAM_ID
  • VERCEL_OIDC_TOKEN
خريطة الصفحة

انتقل مباشرة إلى ما تحتاجه.

  1. 01Available Tools
  2. 02Using Toolsets
  3. 03Tool result annotations
  4. 04Terminal Backends
  5. 05Background Process Management
  6. 06Sudo Support
الصفحة الرسمية كاملة

بلا اختصار أو حذف.

النص أدناه منقول من المصدر الرسمي بالإنجليزية حتى تبقى الأوامر والأسماء دقيقة كما هي. قبل كل قسم شرح عربي يوضّح ما بداخله.

Tools are functions that extend the agent's capabilities. They're organized into logical toolsets that can be enabled or disabled per platform.

Available Tools

جدول مرجعي. لا تقرأه كله، ابحث عن السطر الذي يخصّك فقط. الأوامر هنا: hermes model، hermes tools.

Hermes ships with a broad built-in tool registry covering web search, browser automation, terminal execution, file editing, memory, delegation, scheduled tasks, Home Assistant, and more.

High-level categories:

CategoryExamplesDescription
Webweb_search, web_extractSearch the web and extract page content.
X Searchx_searchSearch X (Twitter) posts and threads via xAI's built-in x_search Responses tool — gated on xAI credentials (SuperGrok OAuth or XAI_API_KEY); off by default, opt in via hermes tools → 🐦 X (Twitter) Search.
Terminal & Filesterminal, process, read_file, patchExecute commands and manipulate files.
Browserbrowser_navigate, browser_snapshot, browser_visionInteractive browser automation with text and vision support.
Mediavision_analyze, image_generate, text_to_speechMultimodal analysis and generation.
Agent orchestrationtodo, clarify, execute_code, delegate_taskPlanning, clarification, code execution, and subagent delegation.
Memory & recallmemory, session_searchPersistent memory and session search.
AutomationcronjobScheduled tasks with create/list/update/pause/resume/run/remove actions. Outbound delivery is handled by cron's own delivery, the hermes send CLI, and the gateway notifier — not by an agent-callable tool.
Integrationsha_*, MCP server toolsHome Assistant, MCP, and other integrations.

For the authoritative code-derived registry, see Built-in Tools Reference and Toolsets Reference.

Using Toolsets

أوامر تكتبها في الطرفية. افهم ما يفعله الأمر قبل نسخه. الأوامر هنا: hermes tools، hermes chat.

Shell8 أسطر
# Use specific toolsets
hermes chat --toolsets "web,terminal"

# See all available tools
hermes tools

# Configure tools per platform (interactive)
hermes tools

Common toolsets include web, search, terminal, file, browser, vision, image_gen, skills, tts, todo, memory, session_search, cronjob, code_execution, delegation, clarify, homeassistant, messaging, spotify, discord, discord_admin, debugging, and safe.

See Toolsets Reference for the full set, including platform presets such as hermes-cli, hermes-telegram, and dynamic MCP toolsets like mcp-<server>.

Tool result annotations

شرح للفكرة نفسها. اقرأه ببطء، فبقية الأقسام تبني عليه. تذكير: الأفعال التي يستطيع Hermes تنفيذها فعلًا: قراءة ملف، تشغيل أمر، البحث في الويب، إرسال رسالة.

A few tool behaviors are worth knowing when you read agent transcripts:

  • Signal deaths are explained. When a terminal command is killed by a signal, the result carries a human-readable note instead of a bare numeric code — e.g. exit -9/137 becomes "terminated by signal 9: SIGKILL — often the kernel OOM killer on memory exhaustion, or an explicit kill -9", and segfaults, aborts, SIGTERM, broken pipes, and CPU/file-size limits are labeled the same way. Negative codes (subprocess semantics) are stated definitively; the shell's 128+signum convention is hedged with "usually" since an application can legitimately exit with those codes.
  • UTF-16 text files are transcoded, not refused. read_file detects UTF-16 (BOM or byte-pattern heuristic, either endianness — common for Windows Notepad files and PowerShell > redirects) and transcodes it to UTF-8 for display instead of flagging the file as binary. The result includes a hint disclosing the conversion; edits via patch/write_file re-encode as UTF-8. Files over 10 MB and genuinely binary files still get the binary-file refusal.

Terminal Backends

جدول مرجعي. لا تقرأه كله، ابحث عن السطر الذي يخصّك فقط. الأوامر هنا: hermes config set terminal، hermes chat.

The terminal tool can execute commands in different environments:

BackendDescriptionUse Case
localRun on your machine (default)Development, trusted tasks
dockerIsolated containersSecurity, reproducibility
sshRemote serverSandboxing, keep agent away from its own code
singularityHPC containersCluster computing, rootless
modalCloud executionServerless, scale
daytonaCloud sandbox workspacePersistent remote dev environments
vercel_sandboxVercel Sandbox cloud microVMCloud execution with snapshot-backed filesystem persistence

Configuration

YAML5 أسطر
# In ~/.hermes/config.yaml
terminal:
  backend: local    # or: docker, ssh, singularity, modal, daytona, vercel_sandbox
  cwd: "."          # Working directory
  timeout: 180      # Command timeout in seconds

Shell startup files and non-interactive commands

Agent terminal calls run your shell non-interactively — there is no TTY and no human at the prompt. Heavy or interactive shell initialisation that you never notice in a normal terminal can break or badly slow every command the agent runs:

  • Slow init (nvm, version managers, network-touching prompts): the classic nvm.sh sourcing adds noticeable latency to every shell start, and the agent starts many shells. Multi-second rc files turn a quick git status into a timeout risk.
  • TTY-expecting blocks: anything in .bashrc/.zshrc that prompts, runs tmux/screen attach, calls read, or prints a menu will hang a non-interactive shell — the command appears to run forever and then times out.
  • Unconditional output: rc files that echo banners pollute every command's output the agent has to parse.

The fix is the standard guard most distros already ship at the top of .bashrc — return early when the shell is non-interactive, and keep anything heavy or interactive below it:

Shell9 أسطر
# ~/.bashrc — keep this guard near the top
case $- in
  *i*) ;;      # interactive: continue
  *) return;;  # non-interactive: stop here
esac

# heavy/interactive init goes BELOW the guard
export NVM_DIR="$HOME/.nvm"
[ -s "$NVM_DIR/nvm.sh" ] && \. "$NVM_DIR/nvm.sh"

Zsh users: put login-only setup in .zprofile and interactive-only setup in .zshrc; keep .zshenv minimal, since it runs for every shell including non-interactive ones. If the agent genuinely needs a tool that only your rc file puts on PATH, export the PATH change above the guard (path exports are cheap) or symlink the binary into ~/.local/bin.

If agent terminal commands hang or time out immediately after working in your own terminal, your shell init is the first suspect.

Docker Backend

YAML3 أسطر
terminal:
  backend: docker
  docker_image: python:3.11-slim

One persistent container, shared across the whole process. Hermes starts a single long-lived container on first use (docker run -d ... sleep infinity) and routes every terminal, file, and execute_code call through docker exec into that same container. Working-directory changes, installed packages, environment tweaks, and files written to /workspace all carry over from one tool call to the next, across /new, /reset, and delegate_task subagents, for the lifetime of the Hermes process. The container is stopped and removed on shutdown.

This means the Docker backend behaves like a persistent sandbox VM, not a fresh container per command. If you pip install foo once, it's there for the rest of the session. If you cd /workspace/project, subsequent ls calls see that directory. See Configuration → Docker Backend for the full lifecycle details and the container_persistent flag that controls whether /workspace and /root survive across Hermes restarts.

SSH Backend

Recommended for security — agent can't modify its own code:

YAMLسطران
terminal:
  backend: ssh
Shell4 أسطر
# Set credentials in ~/.hermes/.env
TERMINAL_SSH_HOST=my-server.example.com
TERMINAL_SSH_USER=myuser
TERMINAL_SSH_KEY=~/.ssh/id_rsa

Singularity/Apptainer

Shell6 أسطر
# Pre-build SIF for parallel workers
apptainer build ~/python.sif docker://python:3.11-slim

# Configure
hermes config set terminal.backend singularity
hermes config set terminal.singularity_image ~/python.sif
Shell3 أسطر
uv pip install modal
modal setup
hermes config set terminal.backend modal

Vercel Sandbox

Shell3 أسطر
pip install 'hermes-agent[vercel]'
hermes config set terminal.backend vercel_sandbox
hermes config set terminal.vercel_runtime node24

Authenticate with all three of VERCEL_TOKEN, VERCEL_PROJECT_ID, and VERCEL_TEAM_ID. This access-token setup is the supported path for deployments and normal long-running Hermes processes on Render, Railway, Docker, and similar hosts. Supported runtimes are node24, node22, and python3.13; Hermes defaults to /vercel/sandbox as the remote workspace root.

For one-off local development, Hermes also accepts short-lived Vercel OIDC tokens:

Shellسطر واحد
VERCEL_OIDC_TOKEN="$(vc project token <project-name>)" hermes chat

From a linked Vercel project directory:

Shellسطر واحد
VERCEL_OIDC_TOKEN="$(vc project token)" hermes chat

With container_persistent: true, Hermes uses Vercel snapshots to preserve filesystem state across sandbox recreation for the same task. This can include Hermes-synced credentials, skills, and cache files inside the sandbox. Snapshots do not preserve live processes, PID space, or the same live sandbox identity.

Background terminal commands use Hermes' generic non-local process flow: spawn, poll, wait, log, and kill work through the normal process tool while the sandbox is alive, but Hermes does not provide native Vercel detached-process recovery after cleanup or restart.

Leave container_disk unset or at the shared default 51200; custom disk sizing is unsupported for Vercel Sandbox and will fail diagnostics/backend creation.

Container Resources

Configure CPU, memory, disk, and persistence for all container backends:

YAML6 أسطر
terminal:
  backend: docker  # or singularity, modal, daytona, vercel_sandbox
  container_cpu: 1              # CPU cores (default: 1)
  container_memory: 5120        # Memory in MB (default: 5GB)
  container_disk: 51200         # Disk in MB (default: 50GB)
  container_persistent: true    # Persist filesystem across sessions (default: true)

When container_persistent: true, installed packages, files, and config survive across sessions.

Container Security

All container backends run with security hardening:

  • Read-only root filesystem (Docker)
  • All Linux capabilities dropped
  • No privilege escalation
  • PID limits (256 processes)
  • Full namespace isolation
  • Persistent workspace via volumes, not writable root layer

Docker can optionally receive an explicit env allowlist via terminal.docker_forward_env, but forwarded variables are visible to commands inside the container and should be treated as exposed to that session.

Background Process Management

شرح للفكرة نفسها. اقرأه ببطء، فبقية الأقسام تبني عليه.

Start background processes and manage them:

Python10 أسطر
terminal(command="pytest -v tests/", background=true)
# Returns: {"session_id": "proc_abc123", "pid": 12345}

# Then manage with the process tool:
process(action="list")       # Show all running processes
process(action="poll", session_id="proc_abc123")   # Check status
process(action="wait", session_id="proc_abc123")   # Block until done
process(action="log", session_id="proc_abc123")    # Full output
process(action="kill", session_id="proc_abc123")   # Terminate
process(action="write", session_id="proc_abc123", data="y")  # Send input

PTY mode (pty=true) enables interactive CLI tools like Codex and Claude Code.

Sudo Support

فيه تحذير مهم. اقرأه قبل أن تنفّذ أي شيء من هذا القسم. نصّ التحذير من المصدر مذكور أسفل هذا الشرح.

If a command needs sudo, you'll be prompted for your password (cached for the session). Or set SUDO_PASSWORD in ~/.hermes/.env.

اختبار الفهم

5 أسئلة إجاباتها كلها في هذه الصفحة.

كل خيار اسم حقيقي من توثيق Hermes. حتى الخيارات الخاطئة حقيقية، لكنها من صفحات أخرى.

1. في جدول هذا الدرس، ما «Examples» المقابل لـ«Integrations»؟
2. أي متغير بيئة من التالي يظهر فعليًا في هذا الدرس؟
3. ما التحذير الذي يذكره المصدر في هذا الدرس؟
4. أي عنوان من التالي لا يظهر في هذا الدرس؟
5. أي مفتاح إعداد يظهر في أمثلة هذا الدرس؟