Hermes (repository hermes-refuse) is a fail-closed execution layer for agent-driven work on macOS, built by Marcus Richards and published as open source under the Apache-2.0 license. It provides allowlisted capabilities, exact target resolution, isolated execution, independent validation, rollback, idempotent operations, redacted append-only receipts, and a safe Automator front end, explicitly without unrestricted shell access, root privilege, credential access, network authority, or deletion power.
It is a technical artifact of Memory Utility Labs and is intended for the AEGIS and AION stack. As of October 2026 it is an early public scaffold: the architecture and boundaries are documented, implementation is landing, and production readiness is explicitly not claimed. It is not affiliated with Quantify Labs' Aegis Memory.
Background
Agents and automations that can act on a real Mac create a high-blast-radius control plane. A single ambiguous path, an over-broad shell grant, or a silent success without audit turns helpful automation into uncontrolled system change. Hermes exists to make that execution narrow, inspectable, and fail-closed: when anything is ambiguous, the answer is refusal, not a best guess.
Design
Execution passes through a fixed set of controls. Allowlisted capabilities define what may run at all. Exact target resolution requires every path, app, or resource to resolve to exactly one candidate; ambiguity refuses. Isolated execution contains the blast radius. Independent validation checks the result separately from the actor that produced it. Rollback and idempotent operations make actions safe to retry and safe to undo. Every execution writes a redacted, append-only receipt, so the audit trail survives even when the action itself is sensitive. A safe Automator front end gives humans a governed way to invoke the layer.
The negative space is the point. Hermes grants no unrestricted shell, no root, no credential access, no network authority, and no deletion power. A capability that is not explicitly granted does not exist.
Threat model
The documented threat model names its assets, host filesystem integrity, credentials and secrets, network identity, the privilege boundary, and auditability, and designs against seven failure modes:
- Over-broad agent intent, a model asking to "clean up" without a named, resolvable target.
- Ambiguous resolution, a target resolving to more than one candidate.
- Privilege escalation, a request implying root, credential access, or unrestricted shell.
- Silent mutation, work that appears to succeed with no receipt.
- Replay and double-apply, the same action compounding damage.
- Confused deputy, a front end used to bypass allowlist policy.
- Supply-chain and prompt injection, untrusted content coercing forbidden capabilities.
Explicitly out of scope for now: full malware analysis of third-party binaries Hermes might invoke, and guarantees against a human operator who already holds admin.
Limitations
Development history
Hermes was created in September 2026 and published under the Apache-2.0 license as an early public scaffold. Development continues as of October 2026.
See also
References
- Hermes source repository. github.com/marsojuji-cmyk/hermes-refuse (public, Apache-2.0).