Sign inSign up

docker/sbx-kit-hermes-agent-mixin:latest

Multi-platform
Manifest digest

sha256:940edc8cf40a0b9083815d36d609a022ca395f3b426349e9c2f0656c37c2af44

Last pushed

9 days by cdupuis

Type

Sandbox Kit

Manifest digest

sha256:940edc8cf40a0b9083815d36d609a022ca395f3b426349e9c2f0656c37c2af44

yaml
schemaVersion: "3"
displayName: Hermes Agent (mixin)
description: Nous Research's self-improving agent as a mixin — the Hermes install in an overlay, with the Anthropic, OpenAI and OpenRouter credentials, the egress policy its provider resolution needs, and the startup hook that works out which of the three is genuinely bound. Layer it onto a shell base and run `hermes`.
version: 2026.9.14
kind: mixin
provides:
    - [email protected]
capabilities:
    - type: com.docker.sandbox/network-policy@1
      config:
        runtime:
            allow:
                - openrouter.ai
                - '*.openrouter.ai'
                - api.openai.com
                - api.anthropic.com
                - platform.claude.com
                - models.dev
                - opencode.ai
                - github.com
                - api.github.com
                - raw.githubusercontent.com
                - api.githubcopilot.com
                - hermes-agent.nousresearch.com
    - type: com.docker.sandbox/credential@1
      optional: true
      config:
        apiKey:
            inject:
                - domain: api.anthropic.com
                  format: '%s'
                  header: x-api-key
            name: ANTHROPIC_API_KEY
            proxyManaged: true
        oauth:
            credentialFile:
                path: ~/.claude/.credentials.json
                structure:
                    claudeAiOauth:
                        accessToken: '{{.AccessToken}}'
                        expiresAt: '{{.ExpiresAt}}'
                        refreshToken: '{{.RefreshToken}}'
                        scopes: '{{.Scopes}}'
            resourceHosts:
                - api.anthropic.com
            sentinels:
                accessToken: sk-ant-oat01-proxy-managed
                refreshToken: sk-ant-ort01-proxy-managed
            tokenEndpoint:
                host: platform.claude.com
                path: /v1/oauth/token
        phase: runtime
        service: anthropic
      description: Anthropic API access (API key or claude.ai OAuth)
    - type: com.docker.sandbox/credential@1
      optional: true
      config:
        apiKey:
            inject:
                - domain: api.openai.com
                  format: Bearer %s
                  header: Authorization
            name: OPENAI_API_KEY
            proxyManaged: true
        phase: runtime
        service: openai
      description: OpenAI API access
    - type: com.docker.sandbox/credential@1
      optional: true
      config:
        apiKey:
            inject:
                - domain: openrouter.ai
                  format: Bearer %s
                  header: Authorization
            name: OPENROUTER_API_KEY
            proxyManaged: true
        phase: runtime
        service: openrouter
      description: OpenRouter API access (200+ models)
    - type: com.docker.sandbox/lifecycle@1
      config:
        startup:
            - command:
                - sh
                - /home/agent/.local/bin/hermes-anthropic-auth.sh
              description: Resolve which of the anthropic/openai/openrouter credentials are genuinely bound, record the result for `sbx exec` login shells, and pin the active provider in config.yaml when only an Anthropic OAuth login is bound
              env:
                - HERMES_HOME
                - SBX_CRED_ANTHROPIC_MODE
                - SBX_CRED_OPENAI_MODE
                - SBX_CRED_OPENROUTER_MODE
              user: "1000"
    - type: com.docker.sandbox/agent-context@1
      config:
        contentFile: /usr/share/sandbox/kit/hermes-agent-mixin/hermes-agent-mixin-context.md
args:
    version:
        default: 2026.9.14
        description: hermes-agent release to install, without the tag's leading "v"
        pattern: ^[0-9]{4}\.[0-9]{1,2}\.[0-9]{1,2}(\.[0-9]+)?$
        buildArg: HERMES_VERSION