Sign inSign up

sbx/hermes-agent-mixin:latest

Multi-platform
Manifest digest

sha256:3e25b89c13aeaec77e5f7e3b7d89382de62153b076be99eef33871ec1cd2ef82

Last pushed

about 3 hours by sbx

Type

Sandbox Kit

Manifest digest

sha256:3e25b89c13aeaec77e5f7e3b7d89382de62153b076be99eef33871ec1cd2ef82

yaml
schemaVersion: "3"
displayName: Hermes Agent (mixin)
description: Nous Research's self-improving agent as a mixin — the Hermes install in an overlay, with the Anthropic, OpenAI and OpenRouter credentials, the egress policy its provider resolution needs, and the startup hook that works out which of the three is genuinely bound. Layer it onto a shell base and run `hermes`.
version: 2026.9.14
kind: mixin
provides:
    - [email protected]
capabilities:
    - type: com.docker.sandbox/network-policy@1
      config:
        runtime:
            allow:
                - openrouter.ai
                - '*.openrouter.ai'
                - api.openai.com
                - api.anthropic.com
                - platform.claude.com
                - models.dev
                - opencode.ai
                - github.com
                - api.github.com
                - raw.githubusercontent.com
                - api.githubcopilot.com
                - api.individual.githubcopilot.com
                - api.business.githubcopilot.com
                - api.enterprise.githubcopilot.com
                - copilot.github.com
                - hermes-agent.nousresearch.com
    - type: com.docker.sandbox/credential@1
      optional: true
      config:
        apiKey:
            inject:
                - domain: api.anthropic.com
                  format: '%s'
                  header: x-api-key
            name: ANTHROPIC_API_KEY
            proxyManaged: true
        oauth:
            credentialFile:
                path: ~/.claude/.credentials.json
                structure:
                    claudeAiOauth:
                        accessToken: '{{.AccessToken}}'
                        expiresAt: '{{.ExpiresAt}}'
                        refreshToken: '{{.RefreshToken}}'
                        scopes: '{{.Scopes}}'
            resourceHosts:
                - api.anthropic.com
            sentinels:
                accessToken: sk-ant-oat01-proxy-managed
                refreshToken: sk-ant-ort01-proxy-managed
            tokenEndpoint:
                host: platform.claude.com
                path: /v1/oauth/token
        phase: runtime
        service: anthropic
      description: Anthropic API access (API key or claude.ai OAuth)
    - type: com.docker.sandbox/credential@1
      optional: true
      config:
        apiKey:
            inject:
                - domain: api.openai.com
                  format: Bearer %s
                  header: Authorization
            name: OPENAI_API_KEY
            proxyManaged: true
        phase: runtime
        service: openai
      description: OpenAI API access
    - type: com.docker.sandbox/credential@1
      optional: true
      config:
        apiKey:
            inject:
                - domain: openrouter.ai
                  format: Bearer %s
                  header: Authorization
            name: OPENROUTER_API_KEY
            proxyManaged: true
        phase: runtime
        service: openrouter
      description: OpenRouter API access (200+ models)
    - type: com.docker.sandbox/credential@1
      optional: true
      config:
        apiKey:
            inject:
                - domain: api.githubcopilot.com
                  format: Bearer %s
                  header: Authorization
                - domain: api.individual.githubcopilot.com
                  format: Bearer %s
                  header: Authorization
                - domain: api.business.githubcopilot.com
                  format: Bearer %s
                  header: Authorization
                - domain: api.enterprise.githubcopilot.com
                  format: Bearer %s
                  header: Authorization
                - domain: copilot.github.com
                  format: Bearer %s
                  header: Authorization
            name: COPILOT_GITHUB_TOKEN
        phase: runtime
        service: copilot
      description: GitHub Copilot model access
    - type: com.docker.sandbox/lifecycle@1
      config:
        startup:
            - command:
                - sh
                - /home/agent/.local/bin/hermes-credential-auth.sh
              description: Resolve which of the anthropic/openai/openrouter/copilot credentials are genuinely bound, record the result for `sbx exec` login shells, and pin the active provider in config.yaml when only an Anthropic OAuth login or only Copilot is bound
              env:
                - HERMES_HOME
                - SBX_CRED_ANTHROPIC_MODE
                - SBX_CRED_OPENAI_MODE
                - SBX_CRED_OPENROUTER_MODE
                - SBX_CRED_COPILOT_MODE
              user: "1000"
    - type: com.docker.sandbox/agent-context@1
      config:
        contentFile: /usr/share/sandbox/kit/hermes-agent-mixin/hermes-agent-mixin-context.md
args:
    version:
        default: 2026.9.14
        description: hermes-agent release to install, without the tag's leading "v"
        pattern: ^[0-9]{4}\.[0-9]{1,2}\.[0-9]{1,2}(\.[0-9]+)?$
        buildArg: HERMES_VERSION