Hermes Mobile is designed for private-network first use.
- backend URL
- selected theme
- workbench default path
- encrypted dashboard cookies
- transient UI state
- provider API keys
- dashboard password after login
- raw cookies outside encrypted preferences
- Hermes memory database
- desktop project files
- desktop-host secrets
- raw gateway frames
- prompt bodies in diagnostic breadcrumbs
These actions should remain locked unless separately designed, confirmed, and verified:
- environment reveal
- credential edits
- provider secret edits
- service restart
- destructive file operations
- imports/deletes/updates
- hooks and automation changes
- privileged command approval without explicit confirmation
Allowed:
ws.openws.closedws.failuresession.create.requestsession.resume.okprompt.submit.failed
Not allowed:
- prompt bodies
- passwords
- secret values
- cookies
- tokens
- raw WebSocket frames
- local machine usernames or absolute private paths
Do not commit:
local.propertiesdevice-verification/- screenshots
- logcat output
- build outputs
- encrypted app state
- real dashboard URLs
- real tailnet hostnames or IPs