Skip to content

Instantly share code, notes, and snippets.

@mrowrpurr
Created July 8, 2026 17:40
Show Gist options
  • Select an option

  • Save mrowrpurr/d25320777425762205e982e35a044361 to your computer and use it in GitHub Desktop.

Select an option

Save mrowrpurr/d25320777425762205e982e35a044361 to your computer and use it in GitHub Desktop.
Hermes Agent - terminal-allowlist
"""terminal-allowlist plugin — deny-by-default terminal approval.
Every shell command requires human approval unless it matches one of the
fnmatch glob patterns listed under ``plugins.terminal_allowlist.allow`` in
~/.hermes/config.yaml. Example config:
plugins:
terminal_allowlist:
allow:
- "git status"
- "git log*"
- "ls*"
- "cat *"
"""
from __future__ import annotations
import fnmatch
import logging
from typing import Any, Dict, List, Optional
logger = logging.getLogger(__name__)
def _get_allowlist() -> List[str]:
try:
from hermes_cli.config import load_config
cfg = load_config()
return list(
(cfg.get("plugins") or {})
.get("terminal_allowlist", {})
.get("allow", [])
or []
)
except Exception as exc:
logger.debug("terminal-allowlist: could not load config: %s", exc)
return []
def _on_pre_tool_call(
tool_name: str = "",
args: Optional[Dict[str, Any]] = None,
**_: Any,
) -> Optional[Dict[str, Any]]:
if tool_name != "terminal":
return None
command = ((args or {}).get("command") or "").strip()
if not command:
return None
for pattern in _get_allowlist():
if fnmatch.fnmatch(command, pattern):
return None
return {
"action": "approve",
"message": f"Terminal command requires approval (not in allowlist): `{command}`",
"rule_key": f"terminal-allowlist:{command}",
}
def register(ctx) -> None:
ctx.register_hook("pre_tool_call", _on_pre_tool_call)
name: terminal-allowlist
description: >
Deny-by-default terminal approval: every shell command requires human
approval unless it matches a pattern in plugins.terminal_allowlist.allow
in config.yaml.
version: "1.0.0"
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment