Agent skill

Hermesone

by BankrBot in BankrBot/skills

Install, update, and manage the Hermes One desktop app via the hermesone npm package.

ISCAuto-check passed

Install Hermesone

skills CLI
$ npx skills add BankrBot/skills --skill hermesone -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install BankrBot/skills hermesone --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/BankrBot/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/hermesone .claude/skills/hermesone && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
hermesone
GitHub stars
1.2k
Token cost
~3.1k tokens
SKILL.md length
1,123 words
Files
3
Skills in repo
106
Repo updated
First seen
Licence
ISC

At a glance

Install, update, and manage the Hermes One desktop app via the hermesone npm package.

  • A user wants to set up Hermes One
  • SKILL.md covers Safety & approval, Recommended flow, Preview a release and CLI reference, plus 8 more sections
  • Calls npm and npx
  • Upgrade it from the command line

What it does

Hermesone is an agent skill from BankrBot/skills. Install, update, and manage the Hermes One desktop app via the hermesone npm package. Use when a user wants to set up Hermes One, install or upgrade it from the command line, check the installed version, preview a release before installing, pin a specific version, or drive the installer programmatically from Node. Triggers on mentions of hermesone, Hermes One, Hermes Desktop (the former name), or installing/updating the Hermes app.

Its SKILL.md is about 3.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `catalog.json`). Compatibility notes: Requires Node.js 18+ (built-in fetch) and network access to GitHub. Cross-platform — macOS (signed app, arm64/x64), Windows (setup.exe), Linux (.AppImage)…

It works with npm and GitHub. The repository describes itself as: Bankr Skills equip builders with plug-and-play tools to build more powerful agents. The licence is ISC.

When your agent uses it

  • A user wants to set up Hermes One
  • Upgrade it from the command line
  • Check the installed version
  • Preview a release before installing

Example prompts

  • “/hermesone”

Requirements

  • Node.js
  • Compatibility (from SKILL.md): Requires Node.js 18+ (built-in fetch) and network access to GitHub. Cross-platform — macOS (signed app, arm64/x64), Windows (setup.exe), Linux (.AppImage). The interactive UI needs a TTY; in non-interactive contexts it falls back to plain output. Works in Claude Code and any environment with a shell and npm.

What it can do on your machine

Read from SKILL.md and the folder at commit dc47eed. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm
    • npx

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • github.com
    • hermesone.org
    • bankr.bot

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Requires Node.js 18+ (built-in fetch) and network access to GitHub. Cross-platform — macOS (signed app, arm64/x64), Windows (setup.exe), Linux (.AppImage). The interactive UI needs a TTY; in non-interactive contexts it falls back to plain output. Works in Claude Code and any environment with a shell and npm.

    From compatibility in the SKILL.md frontmatter.

Context cost

Hermesone loads about 3.1k tokens when it runs. Until then it costs about 112 tokens; SKILL.md has 1,123 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~112
When it runs · the whole SKILL.md, loaded when a task matches
~3.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from BankrBot/skills at commit dc47eed, republished under its ISC licence (© BankrBot). 1,123 words, ~3,061 tokens.

Download SKILL.mdSave it as .claude/skills/hermesone/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
hermesone
description
Install, update, and manage the Hermes One desktop app via the `hermesone` npm package. Use when a user wants to set up Hermes One, install or upgrade it from the command line, check the installed version, preview a release before installing, pin a specific version, or drive the installer programmatically from Node. Triggers on mentions of hermesone, Hermes One, Hermes Desktop (the former name), or installing/updating the Hermes app.
compatibility
Requires Node.js 18+ (built-in fetch) and network access to GitHub. Cross-platform — macOS (signed app, arm64/x64), Windows (setup.exe), Linux (.AppImage). The interactive UI needs a TTY; in non-interactive contexts it falls back to plain output. Works in Claude Code and any environment with a shell and npm.
license
ISC
metadata.author
fathah
metadata.version
0.2.0

Hermesone: Install & Update Hermes One

hermesone (v0.2.0) is the npm package that installs and updates the Hermes One desktop app. It detects the host OS/arch, downloads the matching GitHub release, verifies its sha512 checksum, and installs it — on macOS the signed app goes straight into /Applications, ready to launch (no drag step). It ships a CLI and a programmatic API.

⚠️ This installs and runs third-party native code on the user's machine. The package mitigates this — it verifies every download against the publisher's sha512 manifest (and refuses to run an unverified build), and in an interactive terminal it asks for confirmation first — but installing software is still a host-level action. See Safety & approval.

Naming: the app is Hermes One (formerly "Hermes Desktop"). The GitHub repo it's released from is still named fathah/hermes-desktop, and the installed macOS bundle is Hermes One.app — so you'll see both names. Use "Hermes One" with users; the hermes-desktop slug is just where the release assets live.

Why this lives in Bankr Skills. Hermes One is building toward an agent economy, with Bankr as the primary transaction layer for agent payments. This skill is the entry point: it gets Hermes One installed and current on the host so an agent can participate. Today the package does install/update/version only — no accounts, keys, or onchain actions. Bankr-settled transactions and agent-economy hooks are on the roadmap and will be documented here as they ship.

Safety & approval

Installing or updating Hermes One modifies the host. The package enforces two guardrails for you: it verifies sha512 before installing (fail-closed — it refuses if no published checksum is found), and on an interactive terminal it shows a confirmation prompt with the release, size, and checksum status. Still follow these rules:

  • Require explicit user approval before any install or update. Never trigger one as a silent side effect of another task or an autonomous workflow.
  • In non-interactive/agent contexts the confirm prompt is skipped (and --yes does the same). There, you are the approval gate: run hermesone plan first, show the user the resolved release/asset/size/sha512, get a yes, then run install.
  • Don't override verification. Only set HERMESONE_ALLOW_UNVERIFIED=1 if the user explicitly accepts installing a build with no published checksum.
  • Pin what you install (@0.2.0 for the package; a release tag for the app) when reproducibility matters — see Pinning.

Installing the npm package no longer installs the app as a side effect (see Postinstall behavior). The clean path is: install the CLI, preview, then install on confirmation.

bash
# 1. Install the CLI (no host change — the app is not installed yet).
npm install -g hermesone@0.2.0

# 2. Preview the exact release that would be installed.
hermesone plan

# 3. Install. Interactive terminals show a confirmation prompt + live progress;
#    non-interactive contexts proceed (add --yes to be explicit) and print plain lines.
hermesone install

hermesone update is safe to run repeatedly — it no-ops when already current and only downloads when a newer release exists.

Preview a release

hermesone plan [tag] resolves and prints what would be installed — release tag, asset, size, and the expected sha512 — without downloading or installing anything. Use it to show the user before asking them to approve an install.

CLI reference

hermesone <command> [tag]
CommandDescription
install [tag]Download, verify (sha512), and install Hermes One — latest, or a pinned release tag.
update [tag]Update Hermes One if a newer release is available (no-op when current).
plan [tag]Show what would be downloaded (tag, asset, size, expected checksum). No changes.
versionPrint the installed Hermes One version, or a "not installed" message.
helpShow usage.
Flag / EnvEffect
-y, --yesSkip the confirmation prompt (for non-interactive/scripted installs).
HERMESONE_VERSION=<tag>Pin the release tag (same as the [tag] argument).
HERMESONE_ALLOW_UNVERIFIED=1Proceed even if no published checksum is found. Not recommended.

In an interactive terminal, install renders a confirmation box, a live download progress bar, and per-step status (resolve → download → verify → install). In a non-interactive context it prints plain status lines and never blocks. Color honors NO_COLOR.

What gets installed per OS

OSArtifactBehavior
macOS*-mac.zip (signed)Verified, unzipped, installed into /Applications (or ~/Applications), then launched — no drag. Updates replace in place.
Windows*-setup.exeVerified, then the installer is launched.
Linux*.AppImageVerified, marked executable, then launched.

Pin a specific release

install/update use the latest release by default. To install a known build, pass a tag or set the env var:

bash
hermesone install v0.6.35
HERMESONE_VERSION=v0.6.35 hermesone install
Show full SKILL.md (445 more words)Show less

Checksum verification (built in)

Each download is verified against the base64 sha512 published in the release's electron-builder manifest (latest-mac.yml / latest.yml / latest-linux.yml). On mismatch the file is deleted and nothing is installed. If a release publishes no checksum for the asset, install refuses unless HERMESONE_ALLOW_UNVERIFIED=1 is set. You do not need to verify manually — surface the result from plan to the user and let the package enforce it.

Programmatic API

ts
import { plan, install, update, getInstalledVersion } from "hermesone";

// Preview without downloading — show this to the user for approval.
const p = await plan();                       // { tag, asset, url, size, sha512 }

// Install (verifies sha512 before installing). Optionally pin a tag, and/or
// subscribe to progress events to render your own UI.
await install({
  tag: "v0.6.35",
  onProgress: (e) => console.log(e.phase),    // resolve|download|verify|extract|launch|installed...
});

await update();                                // no-op if already current
const current = await getInstalledVersion();   // e.g. "0.6.35", or null

Also exported: fetchRelease, parseChecksums, selectAsset, getTarget, isNewer, and types Release, ReleaseAsset, State, Target, InstallOptions, InstallPlan, ProgressEvent. The library prints nothing on its own — all output is driven by your onProgress handler.

Version tracking

  • The installed version is detected from the app on disk first. On macOS this reads CFBundleShortVersionString from Hermes One.app/Contents/Info.plist (/Applications and ~/Applications), so manual installs are recognized too.
  • Otherwise it falls back to ~/.hermesone/state.json, written after each install/update done through this tool.
  • version returns null (CLI prints "Hermes One is not installed.") when neither source yields a version.

Postinstall behavior

npm install hermesone does not download or launch the app — running an installer as a silent side effect of npm install is surprising, so it's opt-in. After installing the package it prints the next step (npx hermesone install). Controls:

Env (set before npm install)Effect
(none)Prints guidance; does not install the app.
HERMESONE_AUTO_INSTALL=1Runs the install automatically during postinstall.
HERMESONE_SKIP_INSTALL=1Silences the postinstall notice entirely.

Troubleshooting

SymptomCause / fix
No published checksum found for <asset>The release has no sha512 manifest entry for this asset. Prefer a release that does; only override with HERMESONE_ALLOW_UNVERIFIED=1 if the user accepts it.
Checksum mismatch for <asset>The download didn't match the published sha512 — the file was deleted and nothing installed. Retry; if it persists, the release/asset may be compromised or corrupted.
Failed to fetch release ...: 403GitHub API rate limit (unauthenticated). Wait and retry.
No Hermes One build available for <platform>/<arch>The release has no asset for this OS/arch. Check the releases page.
Prompt didn't appear / it just proceededNot a TTY (CI, pipe, agent). That's expected — it runs non-interactively. Use plan first to gate, or --yes to be explicit.
version says not installed after a manual installOnly macOS auto-detects from disk. On Windows/Linux, install once via this tool so ~/.hermesone/state.json is written.

Notes & guardrails

  • Host-level code execution. Install/update download a native build from fathah/hermes-desktop and run it. The package verifies sha512 and (interactively) prompts, but only run it on explicit user intent — never automatically from an agent workflow.
  • Preview, then install. Use plan to show the release/asset/size/sha512; in non-interactive contexts that preview is your approval gate.
  • No credentials. The tool needs no API key or account and performs no onchain or payment actions.

© BankrBot, ISC. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files in hermesone of BankrBot/skills.

  • SKILL.md
  • catalog.json
  • hermesone.svg

Open the folder on GitHubat commit dc47eed

Compare with similar skills

Hermesone next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Hermesone compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Hermesone this skillBankrBot/skills1.2k—~3.1kAutomated safety check: PassISC
Proxychains Network Fallback2025Emma/vibe-coding-cn23k1 repos~1.1kAutomated safety check: NotesMIT
Cutting A ReleaseTriliumNext/Trilium38k—~3.2kAutomated safety check: PassAGPL-3.0
Verdaccio Pull Request Workflowverdaccio/verdaccio18k—~1.9kAutomated safety check: PassMIT
Update .NET Supported OS Matrixdotnet/core22k—~4.1kAutomated safety check: PassMIT
Hunk Release Workflowmodem-dev/hunk9.6k—~3.8kAutomated safety check: PassMIT

Similar skills

  • Proxychains Network Fallback

    2025Emma/vibe-coding-cn

    Retries failed network commands through proxychains4 and a local proxy when it sees timeouts, DNS failures or blocked access.

    23k GitHub starsUsed in 1 repo~1.1k tokens
    DevOps & CloudAuto-check: notes
  • Cutting A Release

    TriliumNext/Trilium

    A skill your agent uses when cutting, preparing, or debugging a Trilium release — bumping the monorepo version, tagging, or diagnosing a failed "Release" workflow run.

    38k GitHub stars~3.2k tokensUpdated today
    DevelopmentAuto-check passed
  • Takes a change through a verdaccio pull request: branch, local checks, changeset, title and body, labels, CI and review rounds, and ports to other release lines.

    18k GitHub stars~1.9k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Official

    Audits and updates the supported-os.json files for .NET releases, checking them against upstream lifecycle data and regenerating the markdown with the release-notes tool.

    22k GitHub stars~4.1k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Hunk Release Workflow

    modem-dev/hunk

    Maintainer workflow for preparing, publishing, verifying and curating Hunk releases, with confirmation gates before tags, publishes and public edits.

    9.6k GitHub stars~3.8k tokensUpdated 3 days ago
    DevelopmentAuto-check passed
  • Version Release

    NG-ZORRO/ng-zorro-antd

    NG-ZORRO/ng-zorro-antd repository release workflow. An agent skill from NG-ZORRO/ng-zorro-antd.

    9.2k GitHub stars~3.1k tokensUpdated yesterday
    DevelopmentAuto-check passed

More from BankrBot/skills

All 106 skills in this repo
  • OnchainKit App Builder

    BankrBot/skills

    Builds onchain apps with Coinbase's OnchainKit React components and TypeScript utilities: wallet connection, identity, token swaps, transactions and checkout flows.

    1.2k GitHub stars~2.4k tokensUpdated today
    Auto-check passed
  • Lists AgenticBets prediction markets on Base, shows odds, places UP or DOWN bets on token prices in USDC and claims winnings through the Bankr wallet API.

    1.2k GitHub stars~2.4k tokensUpdated today
    Auto-check passed
  • AI2Human Task Router

    BankrBot/skills

    Creates AI2Human tasks for steps that need a real person, such as manual QA or local checks, and returns a task URL the agent can track.

    1.2k GitHub stars~3.2k tokensUpdated today
    Auto-check passed
  • Lets an agent inspect and operate AZZLE V2 tasks on Base through Bankr, from posting and claiming to funding, delivery, release and disputes, behind verified deployment pins.

    1.2k GitHub stars~3.4k tokensUpdated today
    Auto-check passed
  • B20 Console

    BankrBot/skills

    Inspect B20 token contract addresses on Base through B20 Console.

    1.2k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Capacitr

    BankrBot/skills

    Paste a URL or free text and get matched Polymarket / Hyperliquid / Deribit markets with Quotient edge scores.

    1.2k GitHub stars~3k tokensUpdated today
    Auto-check passed

Works with

Questions about Hermesone

What does Hermesone do?

Install, update, and manage the Hermes One desktop app via the hermesone npm package. Hermesone is an agent skill from BankrBot/skills. Install, update, and manage the Hermes One desktop app via the hermesone npm package.

When should I use Hermesone?

Hermesone fits situations like: A user wants to set up Hermes One; upgrade it from the command line; check the installed version; preview a release before installing.

How do I install Hermesone in Claude Code?

Run `npx skills add BankrBot/skills --skill hermesone -a claude-code`. Or copy the skill folder (hermesone in BankrBot/skills) into .claude/skills/hermesone in your project. Claude Code loads it when a task matches its description.

How do I install Hermesone in Codex?

Run `npx skills add BankrBot/skills --skill hermesone -a codex`. Or copy the skill folder (hermesone in BankrBot/skills) into .agents/skills/hermesone in your project. Codex loads it when a task matches its description.

Can I use Hermesone in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add BankrBot/skills --skill hermesone -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/hermesone, .gemini/skills/hermesone, .github/skills/hermesone and .opencode/skills/hermesone in your project.

What does Hermesone need to run?

Going by SKILL.md and its folder, Hermesone needs the command-line tools its instructions call (npm and npx). Our summary lists: Node.js. Compatibility (from SKILL.md): Requires Node.js 18+ (built-in fetch) and network access to GitHub. Cross-platform — macOS (signed app, arm64/x64), Windows (setup.exe), Linux (.AppImage). The interactive UI needs a TTY; in non-interactive contexts it falls back to plain output. Works in Claude Code and any environment with a shell and npm..

Does Hermesone access the network?

SKILL.md names 3 domains. As links in the text: github.com, hermesone.org and bankr.bot. This is read from the text; nothing was executed.

Is Hermesone safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Hermesone use?

Hermesone is published under the ISC licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Hermesone use?

About 3.1k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Hermesone?

Skills that share tags, products or a category with Hermesone: Proxychains Network Fallback (2025Emma/vibe-coding-cn, 23k stars), Cutting A Release (TriliumNext/Trilium, 38k stars), Verdaccio Pull Request Workflow (verdaccio/verdaccio, 18k stars) and Update .NET Supported OS Matrix (dotnet/core, 22k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Hermesone?

BankrBot (a GitHub organization) maintains it in BankrBot/skills, which has 1,202 GitHub stars. The repository holds 106 skills in this directory. The repository was last updated on October 10, 2026.

Source: BankrBot/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.