252,450 stars · MIT read from main/LICENSE, holder FILLED IN: 'Copyright (c) 2025 Nous Research'. No added conditions and no non-commercial model-weights term; the repository bundles no weights. BUT the documented install fetches a script from the company's own domain, not from this repository, which then installs uv, Python 3.11, Node.js, ripgrep, ffmpeg and a portable MinGit — none of it under this licence. · v0.21.6 (2026-10-08), settled against the package page's version ladder (0.19.0 on 20 Jul 2026, 0.18.2 and 0.18.1 on 8 Jul, 0.17.0 on 19 Jun, 0.16.0 on 6 Jun), which makes an October 2025 date impossible. Note the package index LAGS BADLY: its latest is 0.19.0 against GitHub's v0.21.6. · Track this in Scout
A self-hosted assistant that runs commands, remembers past work and answers through six chat platforms and a terminal at once.
▶Repo detailsthe review · specs · pros & cons · install
What it does
Hermes Agent is a terminal program plus one gateway process that puts the same assistant behind Telegram, Discord, Slack, WhatsApp, Signal and the command line at once, including turning voice messages into text. The terminal side has multi-line editing, command completion, history, the ability to interrupt and redirect it mid-answer, and streaming output from the tools it runs. Its central claim is a learning loop: it curates its own memory, writes itself new skills after finishing a complicated task, searches past sessions by full text, and builds a model of the person using it. A built-in scheduler runs jobs on a timer and delivers the results to whichever chat app you prefer. Work can be handed to separate isolated sub-assistants, and ordinary scripts can call its tools over a local interface. Where it runs commands is pluggable across the local machine, a container, another machine over SSH, and several hosted sandbox services. It is not tied to one model provider — one command switches between its own service, an aggregator, a commercial provider or an address you supply. It also imports an existing setup from a predecessor project with one command. It publishes no hardware requirement, no model-size requirement and, in its own security document, no default ports or bind addresses for the gateway. Its own security document is explicit that the local command backend "is outside the supported posture when untrusted input sources are present", that prompt manipulation is not treated as a vulnerability, and that exposing the gateway to the public internet without a password or a firewall is out of scope.
Why it matters
Who it suits. Anyone who wants one assistant reachable from a phone and a terminal at the same time, running on hardware they control, with memory that survives between conversations. The scheduler plus the chat gateways is the combination nothing else in this edition offers: a job that runs at seven in the morning and sends you the answer on Telegram. Skip it if you want a coding assistant specifically — several narrower tools do that better — and skip it if you cannot afford to run every request through a paid model, because that bill is unavoidable.
What people say. For a project of this size, the absence of criticism is itself the finding. The only substantive outside write-up we could verify is by Ryan Merket at RuntimeWire on 3 August 2026, covering an earlier release: clause-by-clause voice streaming, speak-to-interrupt, an on-device wake word, signed outbound webhooks, a citations skill, and the default tool-iteration ceiling raised from 90 to 500. It is useful on facts and weak as assessment: it relies almost entirely on the project's own materials, offers no criticism, and discloses no relationship; it does at least note that the project's own published commit and pull-request counts disagree with the company's own graphic, and calls both approximate. That publication sells comparison tools but no competing assistant. Everything else we found was an unauthored or auto-generated review page and we used none of it. So: no critical, independent, expert assessment of this project exists outside the repository, and for something claiming a quarter of a million stars that absence is worth printing.
Verdict. Worth a weekend if the combination of chat gateways, a scheduler and persistent memory is what you actually want; not worth it as a coding assistant, where narrower tools are better. Three warnings, in order of how much they matter. First, the install is a script fetched from the company's own address and piped into a shell — not from this repository — and it then installs a package manager, a language runtime, a search tool, a media tool and a portable git, none of which is covered by the repository's MIT licence. Second, the default place it runs commands is directly on the machine, and its own document calls the approval prompt "a heuristic, not a security boundary"; skills "execute arbitrary Python at import time", so reading a skill's description is not enough, and plugins "run with full agent privileges". Third, treat the numbers as attributed rather than established: the star count reads between 250,000 and 252,450 depending on which source answers, the issue and pull-request counts are capped by the interface at "5k+" with a third-party mirror reporting about 48,000 combined, and no reading from the main programmatic source could be obtained at all this morning. The nearest alternatives are openclaw/openclaw, the predecessor it imports from, and openai/codex if the job is really code.
- Plain MIT read from the file with the copyright holder filled in, no added conditions, and no requirement to use the authors' own model service — one command points it at an aggregator, another provider, or an address of your choosing.
- One assistant reachable from six chat platforms and a terminal at once, with a scheduler that can deliver a job's result to any of them. Nothing else here does that.
- The security document is unusually candid. It names what is out of scope, says the approval prompt is a heuristic rather than a boundary, warns that skills run code when imported, and notes that provider keys are stripped from the environment handed to subprocesses while stating plainly that this "reduces casual exfiltration but is not containment".
- The documented install pipes a remote script from the company's own address into a shell, and what lands on disk is substantially not under this repository's licence. The contributor route pipes a second remote script into a shell as well.
- By default it runs commands directly on the machine, not in a container. Skills execute code at import time and plugins run with the assistant's full privileges. Container, remote-host and hosted-sandbox backends all exist, and none of them is the default.
- Every request costs money at a model provider, and no hardware, memory or model-size figure is published anywhere — the only number offered is the marketing range "on a $5 VPS or a GPU cluster". The published scale figures do not reconcile between sources.
- openclaw/openclaw
The same self-hosted personal assistant fronted by chat apps, in TypeScript rather than Python and without the self-improvement loop; the direct predecessor it imports from.
Track this in Scout - openai/codex
A terminal assistant that runs tools on the machine but scoped to a code repository, with no chat gateways, scheduler, memory loop or provider switching.
Track this in Scout - anthropics/claude-code
A terminal assistant that reads a codebase and runs git work; single-provider and coding-focused rather than a self-hosted general assistant.
Track this in Scout
curl -fsSL https://hermes-agent.nousresearch.com/install.sh | bash source ~/.bashrc hermes
