Agent governance · OpenClaw + HermesAgent 治理 · OpenClaw + Hermes

Let the agent study. Keep the keys.

讓 agent 去研究,鑰匙留在你手上。

A drop-in layer for an existing OpenClaw host. Hermes studies what should improve, a maintainer watches Hermes, plain Bash watches both, and high-risk changes still wait for you.

裝在既有 OpenClaw 主機上的一層。Hermes 研究哪裡該改進,維護用的 subagent 看著 Hermes,單純的 Bash 再看著兩者,高風險的變更仍然要等你點頭。

Apache-2.0Bash + systemdNo edits to OpenClaw or Hermes code不修改 OpenClaw 與 Hermes 的程式碼
Cross-patrol heartbeat交叉巡邏心跳Quiet安靜
heartbeat-patrol
Default schedules · stale after interval + grace預設排程 · 超過週期加寬限才算逾時
✓hermes_daily_doctorhermes doctor · 30 4 * * *24h+6h
✓hermes_upstream_watchgh release list · 0 5 * * *24h+6h
✓hermes_weekly_reviewhermes insights · 0 5 * * 1168h+24h
✓hermes_monthly_compress/compress · 30 5 1 * *720h+72h
✓hermes_daily_studyhermes cron · 0 10 * * * UTC24h+6h
v0.1.7Latest release, May 2026最新版本,2026 年 5 月
5Scheduled jobs with heartbeats具心跳監測的排程工作
60sBaseline check interval基線檢查週期
0Edits to OpenClaw or Hermes code對 OpenClaw、Hermes 程式碼的修改
The problem問題在哪裡

Long-running agents drift, or they overreach.

長期運作的 agent,不是漂移,就是越權。

A daily upstream-diff cron turns into alert fatigue. An ad-hoc agent session starts cold every time. An agent that updates itself can also rewrite the alarm meant to catch it. This layer separates learning, operating, watching, and approving.

每天比對上游的 cron,最後變成警報疲勞。臨時開的 agent session 每次都從零開始。能自我更新的 agent,也可能改掉原本要抓它的警報。這一層把學習、執行、監看與核准拆開。

The first thing a misaligned agent learns to do is silence the alert that would have caught it.
偏離目標的 agent,最先學會的往往是讓那個會抓到它的警報安靜下來。
How it works運作方式

Study daily. Decide monthly.

每天研究,每月決定。

Install once on a host that already runs OpenClaw. After that, the system works quietly and leaves its findings in files.

在已經跑著 OpenClaw 的主機上安裝一次。之後系統安靜運作,把發現留在檔案裡。

01

Install on a working host

裝在已運作的主機上

Render templates, freeze the baseline, install Hermes if it is missing, add one profile, register the maintainer, and schedule five jobs. Every step is safe to re-run.

渲染範本、凍結基線、需要時安裝 Hermes、新增一個 profile、註冊維護用的 subagent,再排好五個排程。每一步都可以重複執行。

02

Hermes studies by weekday

Hermes 依星期輪替研究

Monday reads a service log; later days cover upstream commits, community skills and plugins, drafting, and pack review. Saturday prunes memory, Sunday is off. The prompt caps each run at 30 minutes or 30 turns.

週一讀服務日誌,接下來幾天依序看上游 commit、社群 skill 與 plugin,起草 pack,再檢查 pack 是否就緒。週六整理記憶,週日休息。prompt 要求每次不超過 30 分鐘或 30 輪。

03

Proposals become packs

提案變成 pack

Each evolution pack declares its kind, target services, evidence, and a rollback command. Hermes can draft one. It cannot apply one.

每個 evolution pack 都寫明類型、影響的服務、證據與回滾指令。Hermes 可以起草,但不能套用。

04

You decide

由你決定

Healthy operation is silent. Read the journal, review the packs that need you, and hear from Telegram only when a job misses its window.

正常運作時完全安靜。讀 journal、審查需要你決定的 pack,只有排程錯過時間窗時,Telegram 才會通知你。

One study task a day

一天只研究一題

The prompt picks the task from the UTC weekday. Sunday only writes the heartbeat.

prompt 用 UTC 星期決定題目。週日只寫心跳。

  1. UTC weekday

    The prompt asks Hermes to check the UTC weekday itself.

  2. Today's task

    Monday through Saturday each have their own task, matching those six lanes in order.

  • weekday read
  • one task today
  • Sunday skips study
The 30 minute and 30 turn cap is only a line in the prompt.
  1. 看星期

    prompt 請 Hermes 自己看 UTC 是星期幾。

  2. 今日題目

    週一到週六各一題,順序跟那六條路一樣。

  • 星期讀到了
  • 今天只有一題
  • 週日不做研究
30 分鐘和 30 輪只是 prompt 裡的一行,腳本不會擋。
What you get你會得到什麼

Oversight that does not depend on trust.

不靠信任的監督。

The parts that must never be talked out of their job are plain code. The parts that need judgment are agents, and Hermes, the one that studies, can only propose.

絕對不能被說服放棄職責的部分,用單純的程式;需要判斷的部分交給 agent,而負責研究的 Hermes 只能提案。

01

Immutable policy baseline

不可變的政策基線

Policy, permission, and mission files, plus the watcher script, are deployed with chattr +i. Changing them takes sudo chattr -i first, and the watcher logs any file that loses the flag.

政策、權限、任務檔與 watcher 腳本都以 chattr +i 部署。要修改就得先 sudo chattr -i,任何檔案失去不可變屬性,watcher 都會記下來。

baseline.policy.yaml
02

Deterministic watcher

確定性的 watcher

A small Bash loop under a systemd user unit checks the immutable flag, SHA-256 hashes, and the gateway process every 60 seconds, and logs anomalies to the journal. It is code, not a model.

一支由 systemd user unit 管理的小型 Bash 迴圈,每 60 秒檢查不可變屬性、SHA-256 雜湊與 gateway 程序,異常就寫進 journal。它是程式,不是模型。

lib/watcher.sh
03

Cross-patrol heartbeats

交叉巡邏心跳

Every scheduled job writes its heartbeat before its real task, then checks the other four. A missed run shows up in the next peer's patrol; healthy runs send nothing.

每個排程工作先寫心跳再做正事,接著檢查另外四個工作。有工作漏跑,下一個執行的工作巡邏時就會發現;正常執行時什麼都不發。

lib/heartbeat-patrol.sh
04

A guardian for Hermes

Hermes 的守護者

The hermes-maintainer subagent runs doctor checks, upstream watch, a weekly review, and monthly compaction. It reports. It cannot upgrade Hermes.

hermes-maintainer 這個 subagent 負責 doctor 檢查、上游追蹤、每週回顧與每月壓縮。它只回報,不能自行升級 Hermes。

hermes-maintainer
05

Packs with rollback

附回滾的 pack

Five pack kinds, from skill installs to config changes. Skill, plugin, and upstream-patch packs can apply inside a weekly change budget; custom work and config changes wait for review. Each one carries evidence and a rollback.

五種 pack 類型,從安裝 skill 到修改設定。skill、plugin 與上游 patch 可以在每週變更額度內套用;自行設計的變更與設定修改要等審查。每個 pack 都附上證據與回滾方式。

upgrade-packs/inbox/
06

State you can read

看得懂的狀態

Everything this layer writes (journal, notes, packs, heartbeats) is plain JSONL, Markdown, YAML, or one-line text. A future operator, or a rescue session, can read it with cat.

這一層寫下的所有東西(journal、筆記、pack、心跳)都是純 JSONL、Markdown、YAML 或單行文字。未來的管理者或救援 session,用 cat 就讀得懂。

evolution-journal.jsonl

Three checks a minute

每分鐘三項檢查

A small Bash script that systemd runs every minute.

一支小 Bash 腳本,systemd 每一分鐘叫它跑一次。

  1. 60s tick

    If the script fails, systemd starts it again.

  2. Three checks

    One pass checks that the files are still locked, that the hash list matches, and that the gateway process is up.

  3. Journal line

    Something wrong adds one line to the journal.

  • locks checked
  • hashes checked
  • gateway checked
A clean minute writes nothing, except a heartbeat about once an hour.
  1. 六十秒

    腳本失敗的話,systemd 會再把它叫起來。

  2. 三項檢查

    一輪要看檔案有沒有鎖著、雜湊清單對不對,還有 gateway 行程在不在。

  3. 紀錄一列

    有問題就在紀錄裡多寫一列。

  • 鎖看過了
  • 雜湊對過了
  • gateway 看過了
平常什麼都不寫,大約一小時才補一列心跳。

Only a late job alerts

沒遲到就不出聲

Five jobs each write a heartbeat, then look at the other four.

五個工作先寫自己的心跳,再看另外四個。

  1. Write beat

    Time, interval, and grace all go into that file.

  2. Check peers

    Late starts after the interval plus the grace, and four fresh peers mean it stays quiet.

  3. Alert path

    An alert goes to a chat when one is set, and otherwise it stays in a local file.

  • beat written
  • peers checked
  • fresh means quiet
They watch each other: the daily doctor, the upstream watch, the weekly review, the monthly compress, and the daily study.
  1. 寫下心跳

    時間、週期和寬限都寫進那個檔。

  2. 檢查同伴

    超過週期加寬限才算晚,四個都還新就繼續安靜。

  3. 警報出口

    有設好聊天就發過去,沒有的話就留在本機檔案。

  • 心跳寫好了
  • 同伴看過了
  • 都新就安靜
互相看的是這五個:每天的 doctor、上游監視、每週回顧、每月壓縮,還有每天的研究。

Some packs can apply

有的 pack 能套用

The main agent counts the weekly budget.

每週額度是主 agent 在算的。

  1. Draft pack

    Hermes writes a manifest under upgrade-packs/inbox and cannot apply it.

  2. Kind and tier

    A week allows 5 low, 2 medium, and 1 high. Only skill, plugin, and upstream patch packs can go in without you.

  • draft written
  • kind checked
  • budget counted outside
Forbidden changes such as hermes update have a budget of 0.
  1. 起草 pack

    Hermes 把清單寫到 upgrade-packs/inbox,自己不能套。

  2. 類型和額度

    一週低 5、中 2、高 1。不必等你點頭的,只有 skill、plugin 和上游 patch。

  • 草稿寫好了
  • 類型看過了
  • 額度在別處算
hermes update 這類禁止的變更,額度是 0。
Architecture系統架構

Four roles, one principal.

四個角色,一個決策者。

The agents do not negotiate over a hidden live channel. They exchange files the operator can inspect, and deterministic code guards the cognitive parts.

Agent 之間不透過隱藏的即時通道協商,而是交換管理者看得到的檔案。認知型的部分,由確定性的程式看守。

Draft → flag → verify → approve起草 → 標記 → 驗證 → 核准
Hermesopenclaw-evolutionStudies, drafts packs研究並起草 packCannot apply不能套用
Guardian守護者hermes-maintainerFlags packs for main把 pack 轉給主 agentCannot upgrade Hermes不能升級 Hermes
Main主 agentOpenClaw agentOpenClaw 內建Verifies packs驗證 packApplies within budget額度內套用
Operator管理者Approves high-risk packs核准高風險 packHolds sudo and chattr掌握 sudo 與 chattrRuns hermes update執行 hermes update
watcher.sh · heartbeat-patrol.sh · evolution-journal.jsonl

You still approve

高風險要你點頭

Hermes can draft, the guardian can flag, and the watcher only checks files.

Hermes 能起草,守護者能標記,看守程式只檢查檔案。

  1. Hermes

    The study profile can write a pack, and that is where it stops.

  2. Guardian

    hermes-maintainer can report doctor, upstream, review, and compress, and hermes update stays yours.

  3. Watcher

    It can look at the frozen files, and it cannot change them.

  4. Operator

    sudo and chattr stay with you, along with any custom or config pack.

  • draft is a file
  • watcher only reads
  • sudo stays with you
  • Agents
  • Needs you
  • Operator
A draft stays a draft until you approve it.
  1. Hermes

    研究用的 profile 寫得出 pack,寫完就停。

  2. 守護者

    hermes-maintainer 回報 doctor、上游、回顧和壓縮,hermes update 留在你手上。

  3. 看守程式

    它看得到鎖住的檔,但改不了。

  4. 管理者

    sudo、chattr,還有自訂和設定 pack,都等你點頭。

  • 草稿只是檔
  • 看守程式只讀
  • sudo 在你手上
  • Agent 這邊
  • 要你點頭
  • 管理者
草稿就只是草稿,要你點頭才算數。
Design decisions設計取捨

Why it is shaped this way.

為什麼長這個樣子。

01

A layer, not a fork

是一層,不是 fork

Forking OpenClaw or Hermes would mean owning their upgrades forever. Staying on public CLIs lets upstream releases flow through, and keeps this repository small.

fork OpenClaw 或 Hermes,等於永遠要自己扛升級。只走公開 CLI,上游版本可以直接流進來,這個 repo 也能維持精簡。

02

Bash for the guard, a model for the thinking

看守用 Bash,思考交給模型

Anything that must never be argued out of its job is plain Bash under systemd. Models are used where judgment helps, never as the last line of defense.

任何不能被說服放棄職責的東西,都是 systemd 管理的純 Bash。模型只用在需要判斷的地方,絕不當最後一道防線。

03

Silence is the healthy state

安靜才是健康

Approval fatigue quietly kills oversight. The heartbeat design alerts only when a job actually misses its window, so every message deserves a look.

審批疲勞會悄悄讓監督失效。心跳設計只在排程真的錯過時間窗時才通知,所以每一則訊息都值得看。

Start here從這裡開始

Five commands on an existing host.

五個指令,就能裝好。

You need a Linux host where OpenClaw already runs, an authenticated gh CLI, sudo for chattr, and bash 4+, jq, curl, envsubst, and systemd user services with linger enabled. Telegram is optional.

你需要一台已經在跑 OpenClaw 的 Linux 主機、登入好的 gh CLI、可以執行 chattr 的 sudo 權限,以及 bash 4+、jq、curl、envsubst,還有開啟 linger 的 systemd user service。Telegram 可有可無。

Clone and configure

Clone 並填寫設定

machine.env holds non-secret settings. For Telegram, also copy machine.env.secrets.example to machine.env.secrets and put the bot tokens there; that file stays out of git.

machine.env 放非機密設定。要用 Telegram 的話,再把 machine.env.secrets.example 複製成 machine.env.secrets,bot token 放在那裡,這個檔案不進 git。

git clone https://github.com/teddashh/openclaw-hermes-watcher
cd openclaw-hermes-watcher
cp config/machine.env.example config/machine.env
$EDITOR config/machine.env

Run the installer

執行安裝

Steps 00 to 11 run in order and are safe to re-run. It asks for sudo to set chattr, and the first Hermes install takes 10 to 20 minutes.

依序執行 00 到 11 步,可以放心重跑。設定 chattr 時會要求 sudo,第一次安裝 Hermes 約需 10 到 20 分鐘。

bash scripts/all.sh

Verify

驗證

all.sh already runs the smoke test once. Re-run it any time: 41 checks, non-zero exit on any failure.

all.sh 已經跑過一次冒煙測試,之後隨時可以重跑:共 41 項檢查,只要有一項失敗就以非零狀態結束。

bash scripts/07-smoke-test.sh

Install, then lock files

安裝時把檔鎖上

Run the installer on a host that already has OpenClaw. Running it again is safe.

在已經有 OpenClaw 的主機上跑安裝程式。再跑一次也沒關係。

  1. Fill config

    Non-secret settings go in machine.env, and bot tokens live in a separate file that git ignores.

  2. Run installer

    Templates get filled in, Hermes is installed when it is missing, and the maintainer is registered.

  3. Freeze files

    The policy, the permissions, the mission, and the watcher files are locked so they cannot be changed.

  4. Smoke test

    It runs 41 checks.

  • templates filled
  • files frozen
  • smoke test done
The last three checks only warn. A real failure still exits non-zero.
  1. 填寫設定

    非機密的設定放 machine.env,bot token 放另一個 git 會忽略的檔。

  2. 執行安裝

    先把範本填好,沒有 Hermes 才裝,再註冊維護用的 subagent。

  3. 凍結檔案

    政策、權限、任務和看守腳本會鎖上,之後就改不了。

  4. 冒煙測試

    一共檢查 41 項。

  • 範本填好了
  • 檔案鎖上了
  • 冒煙測完了
最後三項只會警告,真的失敗才會以非零結束。
Honest status誠實的現況

Where it stands.

目前的樣子。

A template extracted from a working deployment and migration-tested on a real host since v0.1.4. No feature changes since May 2026; an October 2026 cleanup fixed docs, template wording, the CI render check, and an install summary that printed the patrol bot token.

從實際運作的部署抽出來的範本,v0.1.4 起在真實主機上做過遷移測試。2026 年 5 月以後沒有新功能;2026 年 10 月的整理修正了文件、範本用字、CI 的渲染檢查,以及安裝摘要會印出巡邏 bot token 的問題。

Works today

目前可用

  • One-command install with scripts/all.sh, re-runnable on an existing host
  • scripts/all.sh 一鍵安裝,可以在既有主機上重跑
  • Immutable baseline, 60-second watcher, and five heartbeat-checked jobs
  • 不可變基線、每 60 秒的 watcher,以及五個具心跳檢查的排程工作
  • Optional Telegram bots, separate for the maintainer and for Hermes
  • 可選的 Telegram bot,維護用的 subagent 與 Hermes 各自一個
  • A 41-check smoke test after install
  • 安裝後有 41 項檢查的冒煙測試
  • CI runs shell syntax checks, a PII guard, and a template-render smoke test
  • CI 會跑 shell 語法檢查、PII 防護與範本渲染冒煙測試

Limits and not yet

限制與尚未完成

  • Linux only, and OpenClaw must already be installed and working
  • 只支援 Linux,而且要先有正常運作的 OpenClaw
  • Agents run as the installing user and the installer leaves sudo alone, so chattr +i holds only if that user needs a password for sudo
  • agent 和安裝時用的是同一個 Linux 帳號,安裝程式也不會動 sudo 設定;只有這個帳號執行 sudo 需要密碼時,chattr +i 才擋得住 agent
  • 8 of the 11 forbidden actions in the policy, stopping the watcher among them, have no deterministic check yet (marked todo_implement)
  • 政策列出的 11 項禁止行為,有 8 項還沒有確定性的檢查(標為 todo_implement),停掉 watcher 就是其中之一
  • Config paths were verified against OpenClaw v2026.5.x. On 2026.5.20 or later, talk-helpers on main finds only the two default agents; the fix is in open pull request #1
  • 設定路徑是以 OpenClaw v2026.5.x 驗證的。2026.5.20 以後,main 分支的 talk-helpers 只找得到兩個預設 agent,修正還在尚未合併的 PR #1
  • The daily-study prompt spells out /home/ubuntu paths, so another Linux user needs a template edit
  • 每日研究的 prompt 直接寫死 /home/ubuntu 路徑,換成其他 Linux 帳號就得改範本
  • Patrol alerts reach Telegram through an HTTP proxy at 127.0.0.1:8118 by default, and blanking the setting does not turn it off, so a host without that proxy only logs alerts to a file
  • 巡邏警報預設經過 127.0.0.1:8118 的 HTTP proxy 送到 Telegram,把設定清空也關不掉;主機上沒有這個 proxy 的話,警報只會寫進記錄檔
  • The 30-minute, 30-turn budget is a prompt instruction, not a hard limit, and there are no measured token-cost figures
  • 30 分鐘、30 輪的預算只是 prompt 裡的指示,不是硬性限制,也沒有實測的 token 用量數字
Version版本
v0.1.7
License授權
Apache-2.0
Stack技術
Bash · systemd · YAML
Requires需求
Linux + OpenClawLinux + OpenClaw
Last commit最後提交
2026-10-06
Verified查核日期
2026-10-06

More from Ted Huang. Every public project has a page like this one, in English and Traditional Chinese.

Ted Huang 的其他作品。每個公開專案都有一頁像這樣的中英雙語介紹。

All projects →全部專案 →