hermes-memory

A project rule that requires Hermes records for meaningful engineering work. Hermes is the repository's system for storing task notes, bug explanations, features, decisions, and current project status.

In plain words
What is it for?
Use it to document code changes, bug fixes, investigations, refactors, deployments, and reviews under the repository's Hermes folders.
Why use it?
It keeps the reasoning, changes, checks, and follow-up work recorded instead of leaving important project knowledge only in chat or memory.

Cursor rule for Cursor

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add rules/jacson10l/hermes-runtime/hermes-memory
Clone the repo
git clone --depth 1 https://github.com/jacson10l/Hermes-Runtime

Made for: Cursor.

Per session 245 This file is loaded in full into every session.
When invoked 245 The same file — it is already loaded in full.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00245 $0.00245
Opus 5 $0.00122 $0.00122
Sonnet 5 $0.00049 $0.00049
Haiku 4.5 $0.00024 $0.00024

Measured 2d ago against content hash 635817e5a1dc, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

hermes-memory scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

.cursor/rules/hermes-memory.mdc · 23 lines

What it actually says

Hermes Memory Rule

Before making code changes, read hermes/retrieval/index.md and any referenced Hermes memory files relevant to the task.

For every meaningful requirement, bugfix, investigation, refactor, deployment, or review task:

  1. Create or update a task record under hermes/tickets/.
  2. Record context, goal, changed files, behavior changes, verification, and follow-ups.
  3. For bugfixes with a useful root cause, create or update hermes/memory/bugs/.
  4. For durable feature behavior, create or update hermes/memory/features/.
  5. For architecture or technical decisions, create or update hermes/memory/decisions/.
  6. Update hermes/memory/core/current-state.md when project status, active problems, or next steps change.

Before claiming completion, verify that code changes, tests/checks, ticket updates, and relevant Hermes memory updates are all closed.

Do not use the legacy docs/ directory as the Hermes memory root. Hermes memory belongs under hermes/.

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 23 lines · 245 tokens per session scan A 635817e5a1dc

Subscribe to this mod's changes

hermes-memory is a cursor rule published in the GitHub repository jacson10l/Hermes-Runtime (4 stars, last pushed 1mo ago), licensed Apache-2.0. It adds 245 tokens to every session, about $0.0012 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.