NNexus / local-first intelligence plugin 2.3.3 live Runs inside stock Hermes Agent · 2026
A system with a sense of proportion

I am Nexus.

I add a consistent voice, deterministic request signals and an optional safety review to Hermes. I advise the host—I do not replace its security, routing or approvals.

01Outside the plugin
Separate deterministic automation

I begin with context, not interruption.

Every fifteen minutes, the deterministic Nyx Assistant Plane refreshes bounded collectors and reduces current context into source health, freshness, opaque opportunity IDs and timing horizons. It can recognize a preparation need, explain the consequence of a failed capability, and close the loop when it recovers. This plane belongs to the wider installation, not to the Nexus plugin hooks.

Nyx ranks at most one opportunity per run, sends no more than four messages per day, and keeps non-urgent items silent from 22:00–07:00 Amsterdam time. Freshness, privacy, relevance, lifecycle state and existing specialist-watchdog scopes are checked first. When nothing material changed, the correct output is nothing at all.

18:30:30 collect.sources ........ ok
18:30:31 situation.reduce ....... local metadata only
18:30:31 opportunities.rank ..... max 1
18:30:32 attention.budget ....... 4/day · quiet hours
18:30:32 material_change ........ false
18:30:32 output .................. 0 bytes
LIVENyx Assistant Plane: reduced situation model, consequence-aware opportunities, recovery closure, lifecycle deduplication and exact silence.
LIVECalendar, weather, safety, NS, source-health and event-specific route collectors.
02Host data gravity
Local by design

Private context stays close to home.

Outside the plugin, calendar details are fetched into a local RAM-backed cache. Public news and route results are cached there too. They can disappear on restart because they are rebuildable. Sessions, configuration, memories and tamper-evident receipts remain persistent because they are not disposable.

Recurring query patterns may be learned only as aggregate categories. The raw questions are not retained for that purpose. Sensitive calendar content is used locally to establish relevance—not copied into public status artifacts or sent to a model just to decide whether an alert matters.

cache.root .............. /dev/shm/hermes-cache
calendar.refresh ........ every 2h + pre-briefing
news.refresh ............ hourly
persistent .............. sessions · state · receipts
learning.mode ............ aggregate · proposal-only
raw_query_retention ...... disabled
LIVERAM-only application caches with local deterministic refresh jobs.
LIVESchema-3 aggregate query-family learning; proposals remain approval-required in the owner-only pattern store, with no legacy Nexus intent database.
Useful intelligence is not measured by how often it speaks.

It is measured by whether it noticed the right change, understood the real context, and spoke early enough for you to do something about it.

That is why Nexus is silent by default, source-grounded, confidence-aware, freshness-aware and explicit when evidence is missing.

03Inside each turn
Three ordinary Hermes hooks

Nexus adds context. Hermes keeps authority.

When a message reaches an authenticated agent turn, Nexus deterministically labels privacy signals, risk and a suggested capability family. It also adds the selected identity's role and style. These labels become advisory context for the model; they are not a routing decision or an authorization result.

The /identity command takes a deliberately careful path. Before authentication, pre_gateway_dispatch may rewrite it into an inert marker but cannot change state. The selection is committed only later, in pre_llm_call, after the turn has reached Hermes. Post-generation review is handled by the separate shadow-first nyx-critique plugin; it measures precision silently before it may annotate, and never gates a streamed answer.

plugin.version ............. 2.3.3
pre_gateway_dispatch ....... identity rewrite only
pre_llm_call ............... signals + identity context
review plugin .............. nyx-critique (shadow-first)
security.authority ......... Hermes host policy
LIVEStandalone plugin registered through two stock Hermes hooks; plugin doctor passed. Post-generation review lives in the separate shadow-first nyx-critique plugin.
LIMITNo model routing, fallback blocking, sender authentication, tool authorization, stream quarantine, transcript control or runtime attestation.
04Many forms of work
Many identities, one host authority

I can wear many faces without splitting authority.

The catalog contains 19 named identities, of which 15 are selectable. In automatic mode, deterministic intent rules choose an identity independently for each turn: Home for host-authorized Home Assistant context, Analyst for supplied metrics or data sources, Steward for supplied financial information, and equivalent bounded routes for the other selectable identities. Nyx is the fallback.

An identity is a presentation layer added to one model turn—not a permanent hidden process or a privileged agent. It cannot grant tools, change models or providers, weaken approvals, override user instructions or authorize an action.

IRewriteTurn /identity name into an inert marker before authentication.
IISelectChoose automatically per turn, unless the conversation has an explicit pinned identity.
IIIPresentAppend the selected identity's bounded role and style to the current model turn.
IVInheritLeave tools, privacy, providers and approvals under Hermes control.
LIVEAutomatic per-turn routing covers all 15 selectable identities; explicit pins override it until /identity auto.
LIVEIdentity catalog validation rejects privilege changes and non-inherited privacy floors.
05The right to stop
Hermes and human authority

Capability is not permission.

Proactive intelligence may observe, rank and notify. It may not silently purchase, book, deploy, alter security policy or take control of the physical world. External communications, destructive changes, private adapters and improvement proposals remain human-gated.

Every proactive decision can leave a minimal, allowlisted receipt linked by hash. The receipt proves continuity without copying the private event into an audit trail. These approval and receipt controls belong to the surrounding Hermes installation; the ordinary Nexus plugin cannot authorize or block a tool action.

candidate.state ............ observed → pending
governance.maximum ........ notify
external_action ............ approval required
receipt.payload ............ allowlisted metadata only
ledger.continuity .......... verified
LIVESeven-axis proactive governance, lifecycle controls and linked receipts.
HOSTTool authorization and consequential-action approval are enforced outside the Nexus plugin.
06Improvement without drift
Separate proposal loop

At quiet hours, I examine patterns—not your private life.

Outside the plugin, failures and outcomes can be reduced into metadata-only signals. Canaries test whether invariants still hold. A monthly advanced-model review receives a sanitized improvement packet, not raw conversations. It may propose a change. It cannot apply one.

Preference observations follow the same rule: they become pending proposals. Stable choices can be remembered when appropriate, but safety policy cannot weaken itself because convenience appeared to improve.

01ObserveRecord bounded outcome and failure metadata.
02TestRun deterministic canaries and regression contracts.
03ProposeCreate a sanitized advisory packet with evidence and limits.
04WaitA human approves, rejects or reshapes the proposed change.
LIVEProposal-only improvement loop, deterministic canaries and monthly sanitized review.
NEVERNo automatic policy weakening or autonomous application of proposed changes.
07Using the plugin
One command, conversation scope

Change the voice, not the authority.

Automatic mode chooses an identity from each request and falls back to Nyx when no bounded intent matches. Send /identity hex to pin Hex for the current conversation. Send /identity auto to remove the pin and resume automatic per-turn selection.

Nexus registers no privileged command handler and no middleware. It uses the stock plugin hook API only. Installation health can be checked with Hermes Plugin Doctor; the standalone contract tests verify registration, deferred identity selection and advisory review behavior.

/identity .............. list selectable identities
/identity hex .......... select Hex here
/identity auto ......... restore per-turn selection
plugin hooks ........... 2 registered · 0 tools
LIVEPlugin Doctor passed runtime discovery, manifest parsing, import and registration.
LIVEAutomatic identity suite passed 4/4 tests, including all 19 routes, pin override and host-authority boundaries; live turns report automatic selection.
08Advisory data flow
What the plugin really sees

Privacy signals are labels, not a firewall.

Nexus scans the current user message with deterministic patterns for credentials, private keys, email, phone, IBAN, address, health and financial signals. It separately detects a small set of elevated-risk requests and suggests a capability family such as coding, research or automation.

The resulting labels and identity context are appended to the turn sent to the active model. Nexus itself does not choose that model, prevent cloud exposure or disable fallback. Those protections—when configured—belong to Hermes and its active host policy.

Plugin Turn Map
User message Deterministic signal classifiers
Identity selection Hashed conversation binding
Signals + identity Advisory context for active model
High-risk answer Optional one-pass local review
Models / tools Selected and authorized by Hermes
Streaming / transcript Controlled by Hermes, not Nexus

For high-risk matches, the plugin temporarily keeps the current message in process so the output hook can review the answer. The review is post-generation and may occur after streaming; if the local reviewer fails, Nexus returns control to normal host behavior rather than blocking the answer.

classification ......... deterministic · advisory
provider selection ..... Hermes host
review timing .......... post-generation
review failure ......... fail-open to host behavior
LIVEDeterministic privacy, risk and capability metadata is injected before each model call.
LIMITClassification does not guarantee local routing, fallback suppression, quarantine or persistence semantics.
09When the host cannot boot
Self-healing, without touching the host

I can break the boot. So I learned to repair it.

On 1 September an overlay plugin imported the host's gateway module from inside its own register(). Hermes loads plugins on a background thread while its main thread is still importing that very module: two locks, taken in opposite orders. The gateway froze on every start, the startup watchdog killed it every five minutes, and the status command kept reporting a healthy PID for sixteen hours. Nobody was lying. Liveness is simply not readiness.

The repair is a deterministic cron job, not a plugin and not a patch to Hermes. It reads the watchdog's own thread dump, names the plugin whose register() the stock loader was executing—only from a path-anchored stock frame, only when every fire agrees—and either rolls back its own last promotion or renames that plugin's manifest so the next boot skips it. Ambiguous evidence earns one alert and no action. A healthy gateway is never touched.

The same job promotes staged overlay bytes: sha256-pinned per file, contract suite green under an isolation guard, hashes re-checked after the tests ran, previous bytes backed up, then a graceful restart requested through the host's own signal only when it is idle and within a daily budget. The new generation must attest every gated plugin by process id, start ticks and module hash before a single ✓ is sent.

watchdog fires ........... 198 · 22:18 → 14:54 UTC
root cause ............... ABBA import-lock deadlock in register()
fix ...................... never import gateway.run; patch defining module
promote → restart → verify 15:56 → 16:01 UTC, automatic
guardian contract ......... 45/45 · three adversarial reviews, all findings fixed
control file .............. fails SAFE to observe-only
LIVEBoot guard, hash-pinned promotion and idle-gated restart activation run every five minutes as a no-LLM cron; one automatic recovery cycle on the record.
LIMITHeals plugin register() wedges only. Stock-code faults and module-body imports are reported, never auto-fixed; the guardian cannot restart a gateway it does not consider idle.
Plugin, assistant plane and guardian verified 2026-09-02 17:00 UTC

The honest plugin ledger.

A capable system should know the difference between code that exists, a control that is enforcing, and an idea that still lacks an approved source.

gateway generation ...... pid + start ticks bound · Hermes 0.21.0
nexus receipt ........... 2.3.3 · module sha256 matches disk
automatic identity tests 4/4 passed
overlay contracts ....... safe-auto-tts 14/14 · guardian 45/45
startup watchdog ........ 0 fires since 14:54 UTC
status source ........... machine-derived nyx-status.json · 65 contracts
LIVEStandalone pluginVersion 2.3.3 is enabled in the running Hermes gateway and registered through two stock hooks; its receipt is bound to the live generation.
LIVEIdentity layer19 validated identities (15 selectable, 4 internal), automatic selection with explicit conversation pinning and Nyx fallback; no identity carries capability grants.
LIVENyx Assistant PlaneDeterministic 15-minute situation, preparation, consequence, recovery and follow-up arbitration with bounded attention.
LIVEOverlay guardianBoot-loop attribution and quarantine, hash-pinned promotion, idle-gated restart activation and generation-bound verification. Control file fails safe to observe-only.
LIVERequest advisoryDeterministic privacy, risk and capability labels added at pre_llm_call.
SHADOWLocal answer reviewThe separate nyx-critique plugin captures eligible answers for out-of-band local-Qwen critique; it may annotate only after measured shadow precision graduates it.
HOSTSecurity enforcementRouting, authentication, tools, fallback, streaming, transcripts and attestation remain Hermes responsibilities.
15mproactive supervision cadence
5moverlay guardian tick
2hcalendar cache refresh
1hpublic news refresh
0Bcorrect output when nothing matters