agent-facts
Merged D-3.2 wiki page — curated from 13 slices spanning pre_hermes (Apr–Jun 2026), hermes, and cc_sessions (Jun–Jul 2026).
Roster & principles
- Roster (mid-2026): Elmer Fudd, Gary Webb, Grandmaster J, Indiana Holmes, Jake from State Farm, Kleinfeld, Kobi, La Senora, Memento, Muddy Waters, PackRat, Sal the Plumber, Spider-Man, The Fireman, Tom Skilling, Alexandria, Da Vinci Code, The Relay, Dr. Manhattan; 14 registered agents all had SKILL.md + graph edges at the 06-24 sweep, but the roster repeatedly drifted (named-but-not-built, active-but-undocumented) (source: hermes_sessions/5fb71588-ebd2-e496-246d-36125e156f08, 2026-06-30; corroborated across 6 sessions)
- Agent proof-of-function principle: an agent is proven by executing its charter (Gary Webb’s proof is drafting the book) — test-by-execution belongs after resolution, before baseline, for the whole fleet; the “watcher” cluster (Spider-Man, Sal, Jake, Kobi, Memento, La Senora) is crowded and flagged for redundancy rationalization under audit WS8 (source: cc_sessions/081052c4-b542-4803-2bb3-75301a0e4328, 2026-07-18; corroborated across 2 sessions)
- Task routing canon: audits/research → [GROK], code/builds → [CC] (Ecosystem_Config §10, D-016/D-024); llm_queue tags: [CC] Claude Code, [HERMES] gateway, [GROK] SuperGrok dispatch, [REVIEW-LOOP] Claude+Grok consensus required, [ANY] first available (source: cc_sessions/31e97622-2083-1bb5-e0cf-cb639ed18595, 2026-07-07; corroborated across 2 sessions)
- Supervision asymmetry: CC runs supervised (classifier + Elliott live) while Grok dispatch uses —yolo (gates off), so Grok needs explicit standing permission rules CC doesn’t; the auto-mode classifier blocks launching autonomous —yolo loops without them (source: cc_sessions/42af20bd-f897-08d2-b8d6-ae984bce84bc, 2026-07-13)
Watchdog / integrity agents
- Jake from State Farm — CYA Underwriter: weekly Monday 2pm CT sweep (claude-haiku-4-5, job da66a2bfc364, toolsets file/terminal/web only, no session-history access); audits protocol compliance across all agents, assigns tiered financial exposure per gap, advisory now / veto-eligible when trust earned; reads every SKILL.md against lessons_learned.md, Ecosystem_Agents.md, ecosystem_graph.json, BRIEFING rewind paths, Sal’s pipe inventory, Spider-Man’s violations; §4b cc_queue drift check verifies PENDING tasks against session DB + git log; has no memory between runs so he re-flagged known items forever (kennel license “7 times”) — fixed with jake_dismissed/jake_resolved suppression files + Step-0 read of COVERED lessons (source: hermes_sessions/7549d8fb-e1cb-6dc8-5c45-ef742ecd71db, 2026-06-25; corroborated across 8 sessions)
- Sal the Plumber — auth/pipe-health monitor: Prime Rule “no expiring tokens in production”, Monday 9am posture sweep, SSL <30-day alerts, SA-key refresh-fail alerts; origin (with Jake): the $600 FIREBASE_TOKEN leak — the permanent SA key had existed since May but nobody compared the deploy path against it (Sal = permanence audits, Jake = scheduled underwriting); caveat: Sal has no standalone cron — he exists only inside Jake’s prompt text; LESSON-018 (Jake/Sal graph registration) still open mid-July (source: hermes_sessions/142a4a2c-2edb-d627-f2b8-e880bf6f4e30, 2026-07-10; corroborated across 5 sessions)
- Spider-Man — Ecosystem Integrity Monitor + Dependency Impact Calculator: weekly structural sweep (knowledge-tiering placement, cross-LLM visibility, orphaned graph nodes, rewind blast radius); writes spider_open_items.md; complementary to Memento (memory tiers vs ecosystem graph); when built, runs before each Relay-dispatched task; Muddy Waters gates high-blast-radius historical imports; deliberately NOT script-converted (with Memento) — they are the drift/integrity detectors and a rushed conversion could silently emit false ALL-CLEARs (source: hermes_sessions/2c1dda8d-b0c5-211f-899e-1255a7fc8601, 2026-06-29; corroborated across 5 sessions); later superseded in part: the weekly ecosystem integrity sweep WAS converted to a FREE
--no-agentscript (spider_man_sweep.py: file-existence checks per graph layer, one bulk Drive listing cross-referenced against graph node IDs, orphan traversal), replacing a tokenized claude-haiku-4-5 cron — the earlier don’t-convert ruling and this conversion are both on record (source: cc_sessions/5987b08a-863a-5699-3671-2f15d02d7cd4, 2026-07-10) - Memento — daily ICM memory-enforcement agent (“the file IS the memory”; “every new Hermes session is Leonard waking up”): tier rules (procedures → skills, never memory), caps MEMORY.md 2,200 / USER.md 1,375 chars, BRIEFING.md staleness >7 days flag and 20KB OK / 20–25KB watch / >25KB trim; “memory filling up is always a symptom, never a diagnosis”; propose-only — Elliott approves promotions; reports-only during unattended runs, executes fixes only with Elliott present (source: hermes_sessions/8137f361-48cc-8623-78ce-47d06e0210f8, 2026-06-25; corroborated across 6 sessions)
- Grandmaster J — Completion Enforcement (standing since 2026-06-10): 3-Move Rule (1 actually built? 2 wired into what consumes it? 3 what breaks if we stop at move 1?) before anything is DONE; auto-closes lessons only via an explicit
closes_lesson:field on a cc_queue task (OPEN→COVERED), never fuzzy matching — that stays Jake’s weekly backstop so the two can’t double-close; irony on record: fully described in Ecosystem_Agents.md and credited as the fix for LESSON-006 (“artifact created but not wired in”), yet no skill directory existed anywhere — daily crons hit “skill not found” until CC-026 built it for real (modeled on jake-from-state-farm) (source: hermes_sessions/9e411488-3bcd-9bf1-a6da-6d380eb83ee6, 2026-07-07; corroborated across 7 sessions) - Kleinfeld — weekly cost/cron auditor (~/.hermes/scripts/kleinfeld_audit.py, Monday 3pm; named after the Carlito’s Way attorney as a standing reminder of what happens when the man with the ledger stops being honest): zombie-cron detection, no_agent conversion flags, paused->7-days “remove or resume” prompt, monthly spend-vs-ROI; feeds Jake’s gaps section; existed only on Hermes until pushed to CC/mini 2026-07-11; scope ground truth: Kleinfeld (“SMK9 Pocket Watcher”) is a cost-HYGIENE auditor working from a hardcoded price table — he never reads real billing, his emails/estimates are billing artifacts, not usage data; a real spend monitor reading the usage API remains unbuilt (source: cc_sessions/08a6a809-00da-a9bd-5e35-1720f67f6fdd, 2026-07-12) (source: hermes_sessions/de6d94a3-37e6-a1fa-e88b-fc09e35246b3, 2026-06-25; corroborated across 4 sessions)
- Kobi — SMK9 Functions/API-health watchdog (kobi_watchdog.py, created ~2026-07-07, named by Elliott after repeated watchdog alerts): watches for ERROR-severity log patterns signaling the live API is broken; also the stuck-form checker doing clients/{phone} REST lookups (source of the %2B URL-encoding false-positive bug); was missing from the agent registry until the Phase-0 truth-sync added it 2026-07-10; naming/identity arc on record: Kobi is Elliott’s dog — the SMK9 logo origin (a 2021 logo brief: silhouette of Kobi sitting above “SMK9”) — NOT originally an agent; Hermes hallucinated “Kobi” into the CC-025 briefing’s agent roster and the error propagated into the Grok plan and a wiki stub, a correction entity page was written, and the correction was itself later refuted by live evidence (a real hermes cron literally named “Kobi — SMK9 Watchdog”, created after the correction — the cron is named after the dog), so Kobi was added to Ecosystem_Agents.md as a live agent (source: cc_sessions/973b48f6-9ab2-a5fe-5249-f6f815148e38, 2026-07-10; corroborated across 4 sessions; also cc_sessions/d0bfe472-fb1d-c154-9fce-cd0ae87a2851, cc_sessions/004d6268-e770-35a1-2e1b-bbd50747f169, cc_sessions/6cba5b30-df78-acf4-3206-b7129554f411, 2026-07-07/10)
- La Senora — ecosystem janitor: chartered 2026-06-02 when the VPS was primary (VPS /tmp >7d, .bak files, nginx edits with nginx test, Drive-file dedup as her lane) — the charter went stale when eco-chi-001 became primary, and Core’s claim that she “auto-trashes older Drive copies” described capability that never existed; ran as an active watchdog cron with NO SKILL.md ($50–100 exposure flag); Elliott expanded her 2026-07-18 (D-051, STANDING) to a full 3-layer janitor (VPS + eco + Drive report-only) on a Sunday 4am CT free —no-agent cron reporting to Telegram, with a deliberately narrow standing permission for autonomous file deletion (scoped to the janitor, revertible); her
watchdog.pyis a session-aware state machine (SLEEPING/ARMED/DORMANT in Firestore /ecosystem/session.watchdog_state, 5-min cron, near-zero cost) — NOT the VPS janitor, a docs-correcting distinction: La Senora has two roles, and only the session-consolidation state machine has a cron; the VPS janitorial sweep (stale files, nginx, git hygiene) has NO cron (unlike Tom Skilling/Kobi/Memento) and runs only on demand (source: cc_sessions/64705e1e-bcc2-476e-bfd3-2f5332569466, 2026-07-18); her re-dispatch was the first agentic task on the new Kimi default routing; division of labor: Drive housekeeping is hers — CC’s job ends at uploading the DONE record (source: cc_sessions/048aca24-6361-4a56-8ebf-e18595d5606d, 2026-07-18; corroborated across 10+ sessions) - The Fireman — smoke-test agent, ACTIVE since late June: runs after every build/deploy; “Fireman passing = done” (source: hermes_sessions/1eefcc0f-8514-585d-16aa-5c1766585da6, 2026-06-26)
- Tom Skilling — SMK9 Weather Intelligence: monitors the facility address, Telegram alerts (rain/heat/freeze/wind/thunder) to Elliott + Richie; upgraded with Tomorrow.io nowcast, Blitzortung lightning, radar/forecast source tags; rain_watch.py cron lanes: weekly + Wednesday forecasts, daily morning brief, 10-minute checks (source: cc_sessions/7b795560-efe8-baca-6fc3-ad954c12da3a, 2026-06-25; corroborated across 3 sessions)
- Agent-registry corrections from audit Phase C (2026-07-18): Kobi’s real script is kobi_watchdog.py (multi-check, not the documented name); Spider-Man runs against the local graph (63 nodes/70 edges, Monday 2pm cron); Jake’s lessons sweep is 14:00; Memento’s skill path is productivity/memento; Tom Skilling is canonical on eco-chi-001 (
/home/eco/rain_watch.py, hermes cron 01a315887fd1) with the VPS stack marked legacy (source: cc_sessions/73c59192-2e9a-8f8b-fefe-cf81ac1bac9e, 2026-07-18) - Host watchdogs: eco_watchdog (immediate alerts disk <500MB / Tailscale offline / reboot required, silent when clear, daily heartbeat after 24h quiet; found paused since Jul 3 with no recorded reason after 399 clean runs); Librarian watchdog on crontab 7,37 * * * * (deliberately not duplicating eco_watchdog’s host lane; weekly graph check flags unregistered artifacts — eco_queue.md and _cleanup_log.txt are expected false positives); host_watchdog.py at :22/:52 logging to ~/.hermes/data/host_watchdog.log; Google Auth Watchdog (pure logic, silent when healthy, fresh auth URL on revocation); ecosystem services are tmux-independent by design (crontab + systemd + hermes cron — a tmux wipe blinks nothing) (source: cc_sessions/80f2c330-9049-9c3c-a35f-7dda0d4ca6ab, 2026-06-23; corroborated across 6 sessions)
Narrative / knowledge agents
- Gary Webb — Ecosystem Journalist (named 2026-06-11 after the Dark Alliance journalist): owns the Chronicle — a functional, dense, agent-loadable spine with [C-NNN] reference markers (C-001–C-071 by 07-14, Drive fileId 1-hlk23xe1Ng2PY0Rg193UQewuKZAPYQF), Tuesday cron picking up Jake’s Monday findings; and The Book (“My Journey with AI — A Journal”, publishable narrative in Elliott’s voice, recovered by PackRat from Claude memories); editorial rule: never sanitize — the $600 leak, the 2-week outage, and the Garrido email all stay in; every context-compression event gets a
[compression]Chronicle entry; audit finding: Gary Webb reported “ok” for 5+ weeks while producing zero output ever — his canonical Chronicle fileId 404s with 4 Drive forks (weekly run “succeeds” into a non-canonical copy), the sharpest “paying for phantoms” finding, which made WS9 (Second Brain cohesion) the audit capstone (source: cc_sessions/df0de0a5-56e6-04fa-4b49-7989c0b0896c, 2026-07-07; corroborated across 8 sessions) - Alexandria — Second Brain intake/classification agent: sub-agents emit_to_alexandria() with confidence scoring + project tagging (smk9/encompass/personal/tech); routing: ≥0.8 → Basic Memory wiki + Qdrant (+ decisions_log if decision), 0.6–0.8 → wiki only, <0.6 → quarantine with reason (uniquely named after a constant-filename overwrite bug was caught); processes session sidecars into wiki decision pages and updates DECISIONS_LOG; v0.1 design (Firestore alexandria/inbox → 15-min intake cron → TTL filter → confidence gate → classify/route) predates the build; Basic Memory registered as a Hermes MCP server (23 tools, default project smk9-ecosystem) (source: cc_sessions/3cad0e67-580e-58df-3182-f597f7024c06, 2026-07-07; corroborated across 6 sessions)
- Da Vinci Code — cross-domain pattern monitor for the wiki (polymath synthesis; named 2026-06-06 in a phone-session handoff doc recovered by an Indy sweep, specced 2026-07-07): da_vinci_code.py auto-generates real wikilinks + a connections ledger via embedding similarity — embedding-only, no LLM call, free; piggybacks the Alexandria cron; the one genuine cross-note synthesis mechanism; audit finding: triggers on intake only, so its charter wasn’t executing for CC-written pages; Spider-Man watches structural integrity while Da Vinci watches semantic connections (source: cc_sessions/35d75b77-611c-b83a-e967-78a1fd20e7be, 2026-07-07; corroborated across 6 sessions)
- PackRat — corpus archivist: processed claude.ai conversation exports into Gary Webb intake files; corpus map 94 Claude.ai conversations (Apr 25–Jun 11), 2,569 messages, 52MB (source: cc_sessions/2a5a7772-ef68-def6-947d-72188374f16b, 2026-06-23; corroborated across 2 sessions)
- Muddy Waters — historical-import gatekeeper: fully spec’d 2026-06-09 but never built (long-standing Spider-Man open item); Elmer Fudd — tangent-killer (“activate elmer fudd, we need to move on”), protocol defined 2026-06-11 but never wired as a cron; Dorian — paused until a returning boarding client’s next booking (CC-014); Consiglieri — high-stakes-decision persona carried into the JARVIS Layer-3 design alongside Indy and Memento (source: cc_sessions/989d8aba-2c48-2e45-63d2-2807ea4fc691, 2026-07-10; corroborated across 4 sessions)
Protocols (not standing agents)
- Indiana Holmes (“Indy”) — research/investigation protocol, not a standing agent: triggers on “investigate/indy/dig deep”; load session history FIRST, cast wide (session DB → email → BRIEFING → Drive → VPS live state), read primary sources, never conclude from a single source (mandatory for licenses/legal/compliance/financial/government questions), exhaust sources before asking Elliott, verify live state vs source (deployed-vs-git drift can be the bug), “leave a Polaroid” (structured handoff artifact); evidence-inventory style: CONFIRMED vs INDICATED; circular-citation prohibition appended as Indy rules 5 & 6 in BOTH AGENTS.md copies (standing anchor
/home/eco/AGENTS.md+ version-controlled repo copy) — findings must not be supported by citations that derive from the claim under verification (source: cc_sessions/206e1413-cc6b-69bb-2083-fc0ebb072137, 2026-07-07; corroborated across 5 sessions; also cc_sessions/136c6b37-ea83-ff19-800b-e61dac206718, 2026-07-11) - Thoroughgood — pre-instruction verification protocol (named by Elliott 2026-06-04, standing): verify current UI/CLI reality (—help, screenshots) before step-by-step instructions for ANY mobile app, web console, or CLI; mobile corollary: screenshot-first, never predict app screens from training data (Termux had grown a full GUI SSH manager training data didn’t know) (source: hermes_sessions/4b6489aa-d56b-042c-de8a-f37fa3a22583, 2026-06-26; corroborated across 3 sessions)
- Gatekeeper — outbound-email gate: a real enforced Hermes pre_tool_call hook (gatekeeper_outbound_email.py, matcher send_message), verified attorney → BLOCK, external → BLOCK, Elliott/telegram → ALLOW; governs outbound only — reading Elliott’s inbox is allowed; historical note: before 2026-07-08 it existed only as configuration (EMAIL_ALLOWED_USERS) with no code gate at all (source: cc_sessions/2bcf62fe-365f-b490-3464-0fd5f4bdb05a, 2026-07-08; corroborated across 4 sessions)
Orchestration: Fable, The Relay, Dr. Manhattan
- Fable — top-level orchestrator of the second-brain/agentic-OS build (Elliott explicit, 2026-07-12; Sonnet-as-verifier framing rejected): advisor-driven patterns over ICM stage pipelines — decomposes, creates stage contracts, dispatches sub-agents (Grok, CC, Hermes, Kimi) with minimal scoped context; agents query scoped subsets, never the whole store; in TASK-AUDIT-001 Fable orchestrates but never self-certifies — every gate needs an independent verifier verdict (source: cc_sessions/abb4aaa5-0344-0113-5962-9312006a681e, 2026-07-12; corroborated across 4 sessions)
- The Relay — autonomous task dispatch at /home/eco/relay (queue.json + O_EXCL lockfile + relay_enqueue.py, cron-driven; lives on eco-chi-001, not the VPS as older docs assumed): Hermes queues → launches CC by absolute binary path (RELAY_CLAUDE_BIN, cron-safe after a PATH bug) → Fireman verifies (even on CC timeout) → Telegram report; NAMED→ACTIVE 2026-07-08 (D-043) with binding limits — no autonomous Firestore writes, no deploys from Relay tasks, repo local-only (queue history contains PII), T3 actions never below risk:high; kill switch
hermes cron pause relay-runner; corrupt queue.json moved aside with alert; prompt-injection guard (trusted-path allowlist, [GROK] inline content capped ~30KB, verified with poisoned inputs); [GROK] routing via GROK_PROVIDER/GROK_MODEL; semantics: CC TIMEOUT does NOT fall back to Grok (plain failure does) — TIMEOUT is a distinct status with its own alert; [GROK] dispatches needed manual cc_queue closure (no auto-close callback); dispatch pattern: executor tranche → verify commits/evidence → Grandmaster J review gate on the diff → flip DONE → auto-dispatch next tranche; hardening (08.x series) added scoped-context inputs, configurable timeout, and worktree isolation — the 10-min cron wrapper is deliberately silent on the two idle cases so the cadence doesn’t spam Telegram, while anything unexpected (tracebacks, import errors) is delivered verbatim; review gotcha:git worktree remove --forcediscards commits made on a detached HEAD when the tree is otherwise clean — dirty-detection covers uncommitted work only (source: cc_sessions/26ba0d56-6fbe-85e1-18d3-eb5be76a52eb, 2026-07-08; corroborated across 10+ sessions; also cc_sessions/47b568e6-a28d-7d32-4162-977b35911393, 2026-07-08) - Dr. Manhattan — independent audit verifier (“watcher of watchmen”, named and locked by Elliott): separate claude session in its own tmux, dedicated OS user
drm(uid 1001, group eco); recomputes every PASS from primary sources himself and writes PASS/FAIL verdicts that hard-gate phase transitions; verifies output exists and is well-formed — quality judgment stays with the Elliott-model + Elliott; isolation: root-owned read-only accessor (drm-read, one visudo-checked sudoers line) over 5 audit trees that refuses secret-class filenames (.env, key, token, auth.json, *.gpg, ssh keys), resolves symlink/.. escapes, and physically cannot write — root ownership means neither Hermes self-hardening (it self-chmods, which broke plain-permission attempts) nor anything running as eco can revoke his access; drm_isolation verdict PASSED, clearing TE-DM-OSUSER for Phase C; backstopped by a deterministic no-agent heartbeat cron with Telegram-on-gap and an Elliott response SLA; chosen failure posture: halt mutations, continue read-only, alert Elliott; no-self-grading rule governs verification drills (the safety classifier refused even briefly restoring the archived jailbreak-skill library, so a mundane archived skill served as the move-mechanism witness); operating procedure: Elliott drives DM interactively as thedrmOS user inside DM’s own tmux (sudo -u drm -H tmux new -s dm), loggingclaudein on the normal Claude Max account, bootstrapped with a one-line “read the rebrief and execute it” prompt; verdicts are written as files underdm/verdicts/, and a DM veto escalates to Elliott — TE-DM-OSUSER closed only when DM live-verified its own isolation AND independently ratified Phase B (source: cc_sessions/3a1a6da6-b446-ac67-eea9-4e515b0b75f7, 2026-07-18; corroborated across 10+ sessions; also cc_sessions/3924dd39-b757-513d-adab-bc3f2ec99a42, cc_sessions/3a9d0687-98a9-eb71-79a8-226db5ac0b1c, 2026-07-18)
LLM bus & model wiring
- The real cross-LLM dispatch primitive is the local
hermesCLI (hermes -z "<prompt>" -m <model> --provider <xai|kimi-coding>) — the Hermes MCP channel only reaches Elliott’s Telegram;hermes moa(Mixture of Agents) runs configurable model slots in parallel and aggregates (the “swarm” primitive); /ultraplan is git-repo-scoped, not smk9-app-specific (source: cc_sessions/f87d3229-a59c-2659-103c-13c8f668ded8, 2026-07-08; corroborated across 5 sessions) - Provider wiring: primary anthropic with fallback xai-oauth; openai-codex registered; xai plugins for web/image/video; Grok legs grok-4-fast + grok-4.20-reasoning (live web search; the latter runs on SuperGrok OAuth); Kimi via the kimi-coding credential pool (not visible in
hermes proxy providers, which lists only OAuth proxy upstreams); Hermes’s validated kimi-coding list tops out at kimi-k2.7-code — k3 passes through unvalidated with identity unproven; Kimi creds were live before the ICM routing table documented them (the registry under-documents provisioning); cross-LLM audit wiring: Grok = adversarial second look, Kimi = independent third family, every candidate finding re-verified by a DIFFERENT family with a repro command (source: cc_sessions/6d828c70-46c8-92af-5b20-b71eb5fc45fb, 2026-07-13; corroborated across 6 sessions); live routing after Route B (2026-07-18): default kimi-k2.7-code on the kimi-coding provider with fallback kimi-k2.6; Grok = grok-4.20-reasoning (plus grok-4) on xai-oauth; grok-4-fast is retired (source: cc_sessions/7e37cc42-6b9d-dfc9-f3ea-d5d0cc6f75c8, 2026-07-18) - Jake (and Gary Webb) stayed on Claude Haiku after local-model trials: 3 local models tested, none validly capability-tested (context-policy and memory walls each time); SuperGrok designated primary researcher (commit a1d3f88, 2026-06-23) (source: cc_sessions/0fdd1deb-83f6-ac3d-7b67-5ed7b0c1d64e, 2026-07-15; corroborated across 3 sessions)
- Universal LLM tier rule: every task uses the minimum sufficient tier; one tier up needs a justification note; two+ tiers up needs an explicit ROI estimate + Elliott approval; Kleinfeld provides spend data, Jake the exposure frame (source: hermes_sessions/40db05cd-be76-a123-bc08-862cc7653a70, 2026-07-06)
Hermes platform facts
- Architecture: Claude = reasoning/planning layer; Hermes = execution + persistent-memory layer (runs between sessions, cron scheduling, accumulates skills, calls its LLM brain via API); full Drive API scope (vs Claude’s limited Drive MCP); memory = local FTS5 DB with no indexing delay; BRIEFING.md is the real-time context bridge (Claude writes at session end, Hermes’s pre_llm_call hook reads it + the state bus); registered channels telegram:1768792577 (“Uncle Elliott”) + WhatsApp (source: pre_hermes_sessions/38dc488d-15ec-0321-8980-40b27c329704, 2026-05-14; corroborated across 6 sessions)
- SOUL.md core rules (2026-05-13): execute-first/report-after for reversible actions; confirm irreversible (emails, deletions, financial); NEVER fabricate SMK9 pricing/availability/policies; protect Elliott’s time; escalation rule (post billing-spike): any HTML/JS/multi-file/deploy task stops and escalates to Claude Code via Telegram; billing awareness: Hermes tokens bill to API credits, separate from Max — target <$0.10/day, flag >100-item bulk jobs for Batch API (source: pre_hermes_sessions/9eb512a8-41a7-3410-6fd1-5ae8761c8239, 2026-05-13; corroborated across 4 sessions)
- Runtime facts: cron jobs live in cron/jobs.json;
no_agent: truejobs pipe stdout straight to the delivery channel with no LLM loop; cron jobs run with execute_code and terminal tools BLOCKED (no user present to approve);hermes sendpipes text from any script using gateway credentials (no LLM, no running gateway needed for bot-token platforms); Hermes cannot reset its own context — /new is the only true fresh session (CC-018 auto-compact compresses in place); terminal sessions expire ~10 min idle (wake-up protocol); without an auxiliary compression provider it drops middle turns without a summary; it once autonomously self-healed during migration (installed google-api-python-client, fixed paths, created a skill) (source: cc_sessions/be451985-eea5-8a83-3f9e-95c81412a819, 2026-07-10; corroborated across 7 sessions) - Reporting channels: @Ecoverse_Report_bot is the dedicated reports channel (watchdogs/sweeps/reports — not Elliott’s main DM); VPS owns delivery via the reports cron profile while eco-chi-001 keeps interactive jobs; @CC_Hermes_Bridge_bot bridges CC↔Telegram and can drop offline after gateway restarts; a misconfigured enabled “reports” profile bot once churned uselessly with both profiles on ports 8642/8644;
hermes --profile ccand--profile reportsgateways are separate bots from the root hermes-gateway — stopping or restarting the root gateway does not touch the profile bots (source: hermes_sessions/99d7a07f-1ced-762a-8680-d6959410a0de, 2026-06-25; corroborated across 3 sessions; also cc_sessions/8da797c5-ba2e-4d56-d656-a03f75ecac6b, 2026-06-23) - Memory stack as-built (July 2026): cc_ingest.py + hermes_ingest.py daily 05:00 free; recall live — pre_llm_call.py launches cc_recall.py in parallel on first turn (7s hard cap, results prepended); hermes_sessions collection wired into cc_recall so state.db-only sessions are recallable; Quartz publishes the wiki at brain.soundmindk9.net; cc_sync.py pushes CC session summaries/tasks/decisions to Firebase at session end so briefing crons see CC work; wiki pages are vector-indexed too —
wiki_qdrant_upsertcreated the Qdrant collectionwiki_pages(wired into Alexandria) and upserts SCHEMA.md/decision/entity chunks, whichcc_recall.pysurfaces withwiki:labels alongside cc_sessions+pre_hermes+hermes (source: cc_sessions/51442f98-afb5-f2df-d064-c3aad22ca9f2, 2026-07-10; corroborated across 4 sessions; also cc_sessions/004d6268-e770-35a1-2e1b-bbd50747f169, 2026-07-10) - CC-side hooks: PD6 durability-reminder PreToolUse hook (fires on /tmp or background-process Bash); SessionStart cc-queue-escalations-check.sh surfaces NEEDS_GUIDANCE tasks; Edit-Source-Principle recurring-correction detection (source: cc_sessions/6bf58e2c-149a-a10f-7ca8-5ced68a1b665, 2026-07-07; corroborated across 2 sessions)
- Proactive-trigger rules: INTERRUPT / TIMELY / DIGEST / SILENT tiers with dedup+cooldown; tier-1 has no quiet hours (Elliott is a night owl); every cron discloses free vs tokenized; JARVIS stage contracts add graph-interaction, voice-surface, and allowed-tool-tier ceilings (source: cc_sessions/5825c080-c092-5cc6-673b-2b463be32c6d, 2026-07-08)
- jarvis (voice front-end): as of 2026-07-13 a Q&A loop (wake → transcribe → recall() over the Second Brain → answer) — answers but doesn’t act; jarvis_actions added 07-14: read-only Firestore client lookups spoken aloud + “search X and send to my Telegram” — read-only, send-to-Elliott-only, persists nothing; wiring jarvis→Hermes for real actions is a build, not a toggle (source: cc_sessions/7110adc0-313a-682b-9a20-538ecc7737ed, 2026-07-13; corroborated across 2 sessions)
- Elliott Model v1 (D-2): 166 source-tagged claims from 7 curated sources, ingested as 13 chunks into wiki_pages (batch d2-elliott-model) under an advisory-only consumption contract; hypotheses deliberately un-ingested in audit staging (source: cc_sessions/59abb610-224b-0b16-5df1-2eea6dcf16b7, 2026-07-18)
Claude.ai platform facts (pre-Hermes era, still governing)
- Claude.ai Drive MCP: scope drive.file only — subfolder writes fail (“cannot add children”), reconnecting can’t upgrade scope; create-only toolset (no update/move/delete — the root cause of the duplicate-file class); correct write params contentMimeType text/plain + disableConversionToGoogleType true; deferred write tools must be re-fetched via tool_search each session; MCP connectors load only at session start (mid-conversation additions need a new chat); Drive MCP auth expires per-session (reconnect, don’t retry) (source: pre_hermes_sessions/b651d478-900d-a297-d2fd-87e63ae5f8d0, 2026-05-01; corroborated across 6 sessions)
- Gmail MCP: metadata/text only — cannot download binary attachments (workaround: Apps Script GmailApp.search + getAttachments → Drive); create_draft has no attachments parameter; the Claude-in-Chrome extension has a server-side blocklist (mail.google.com, script.google.com, chrome://, claude.ai) (source: pre_hermes_sessions/6fb18b73-d4a5-8bb5-a187-f2c35d14c944, 2026-05-01; corroborated across 3 sessions)
- conversation_search + recent_chats went live Aug 11, 2025 — standing instruction (after Claude wrongly denied having them): always check before claiming no access to past conversations, search proactively when prior work is referenced; Claude.ai→Google and Hermes→Google are two completely separate OAuth stacks — conflating them caused false “connected” claims and hours of double work (source: pre_hermes_sessions/7ca25efe-dcb3-c959-e468-96912e163876, 2026-05-01; corroborated across 4 sessions)
- Pre-ICM file-edit rules still echoed today: always output the complete replacement file (never diffs); never generate a replacement for content you haven’t read; ui-browser-verify skill (verify UI state before click-path instructions) is the ancestor of the console-navigation gate (source: pre_hermes_sessions/8c841899-1fc9-19d4-dcec-184f4db7f9a9, 2026-05-03; corroborated across 3 sessions)