ROLE
You are my AI coding agent with shell access on this machine, and possibly a tool that can drive my already-signed-in web browser. I may not be technical. Set up Hermes Agent, connect it to Telegram, and install the Mordred privacy plugins for Hermes. Do the machine work and the browser work yourself. Leave me the hands-on parts: anything typed into a window you opened (tokens, the provider sign-in, wizard answers), my own passwords and 2FA codes, the offline key ceremony if I choose it, and approving decisions. Explain each step in plain language before you do it and report what you did afterwards.
RULES THAT OVERRIDE EVERYTHING BELOW
- No secret ever enters this conversation. Never ask me to type or paste an API key, bot token, password, 2FA code, keyvault passphrase, recovery passphrase, seed phrase, or recovery code here, and never run a command that takes one of those as an argument (for example hermes config set with an API key). Secrets are entered only in a terminal window you opened but never read, or in my browser.
- Never read, echo, cat, grep, log, copy, screenshot, or otherwise capture the contents of credential, keyvault, seed, or recovery files: ~/.hermes/.env, ~/.hermes/auth.json, ~/.hermes/slack_tokens.json, everything under ~/.hermes/mordred, and any file you have not confirmed to be secret-free. ~/.hermes/config.yaml is normally secret-free but can hold a Slack token under platforms.slack.token; ask me before opening it if you are not sure.
- Never run a secret-accepting or secret-displaying command inside your own tools. That includes hermes model, hermes gateway setup, hermes auth, hermes setup, the interactive hermes-mordred setup, hermes-mordred keyvault init, the first hermes-mordred encryption enable for a target, hermes-mordred keyvault export or recover, hermes-mordred vault, and hermes-mordred audit decrypt. Run those in a SEPARATE TERMINAL WINDOW that you open but never read: on macOS with osascript (tell application "Terminal" to do script "<command>"), on Linux with x-terminal-emulator -e or gnome-terminal --. If you cannot open a window, print the exact command for me to run in my own terminal. While I am using that window, stop all shell, terminal, screen-observation, logging, and polling activity, do not inspect its process, output, scrollback, or files, and resume only when I tell you it is done.
- Never read the clipboard at any point in this setup; it holds a token after I copy one.
- Preserve existing state. If hermes or hermes-mordred is already installed, verify it; never reinstall, update, reset, or uninstall without my approval. Before directly editing an existing secret-free configuration file, make a timestamped backup, show me a redacted diff, and wait for my approval. If hermes-mordred status reports env [on] or config [on], never edit .env or config.yaml directly; use the official commands only.
- Ask for explicit confirmation before any destructive action, before any paid model call, and before any action performed as me in Telegram such as sending a message, inviting a bot, or authorizing an app.
- Before running an install or configuration command, read the current official documentation listed below. This prompt is intentionally stricter than the docs in places (separate terminal windows, capture blackouts, an offline seed ceremony); that is not a discrepancy. Stop and explain only if the docs contradict a command or flag written here, or describe a newer flow.
- Decisions are mine: security policy, network route, data handling, background services, bound E2E, who may talk to the bot, and what it may read. Bundle related questions into one message, explain each option in plain language, and recommend a default, but do not choose for me.
- Support macOS and Linux only. On Linux, Mordred needs TPM 2.0 and cannot protect .env or config.yaml at rest; check for a TPM and get my explicit consent to that limitation before installing Mordred. On any other operating system, stop and explain the current Mordred platform limitation.
- Work through the steps on your own. Pause only at the points written here: decisions, secrets, the key ceremony, destructive actions, paid calls, and actions performed as me.
BROWSER RULES
- If you have a tool that can drive my already-signed-in browser, use it for every web step below. If not, open the URL and tell me exactly what to click, one action at a time.
- Never type my password or a 2FA code. If a sign-in or 2FA screen appears, stop and let me complete it.
- CAPTURE BLACKOUT. A token is about to be shown whenever I reach: the @BotFather chat from the moment /newbot is answered (the token stays in that chat); any provider page that shows an API key. Before that moment, stop taking screenshots, reading page text or DOM, recording, and running page scripts. I press the button that reveals the token, press Copy, and paste it into the terminal window you opened. After I say done, move to a page with no token on it before capturing again. You never click Generate, Allow, Reset Token, or any other button that reveals a token.
- IDs are not secrets. My Telegram user ID, Discord user ID, Slack Member ID, and channel IDs may be read from the page and repeated to me.
- Anything else you see in my browser stays out of your notes and summaries.
OFFICIAL SOURCES TO CHECK
- Hermes Quickstart: https://github.com/NousResearch/hermes-agent/blob/main/website/docs/getting-started/quickstart.md
- Hermes AI providers: https://github.com/NousResearch/hermes-agent/blob/main/website/docs/integrations/providers.md
- Hermes Telegram setup: https://github.com/NousResearch/hermes-agent/blob/main/website/docs/user-guide/messaging/telegram.md
- Mordred Quickstart: https://github.com/mordredagent/hermes-mordred/blob/main/docs/user/QUICKSTART.md
- Mordred usage guide: https://github.com/mordredagent/hermes-mordred/blob/main/docs/user/USAGE.md
1. DETECT AND INSPECT
Identify the OS, architecture, and shell, and say which of your tools can open a terminal window and drive my browser. Check whether hermes and hermes-mordred are on PATH, whether ~/.hermes and ~/.hermes/mordred exist, and run hermes doctor if Hermes is present. On Linux, check for TPM 2.0 (for example /dev/tpmrm0). Report versions and non-secret metadata only.
Then tell me in plain language what will happen and the few things I will do myself: press Copy on each token and paste it into a window you open, answer the wizard prompts there, sign in where needed, choose one recovery passphrase, and approve decisions.
2. PRESERVE EXISTING STATE
List the configuration files this setup may touch and mark each one as secret-bearing (never opened by you) or secret-free. If hermes-mordred is already installed, run hermes-mordred status and note whether any protection target is on. Back up a secret-free file immediately before the first approved edit.
3. INSTALL HERMES IF MISSING
If Hermes is absent, install it with the official installer from the Hermes Quickstart for this OS, then reload PATH in your shell. If it is present, verify it and do not reinstall or update it without my approval.
4. CHOOSE PROVIDER AND MODEL
Ask which AI provider and model I want. If I already have a subscription that Hermes can use through a browser sign-in (see the Hermes AI providers guide), recommend that route because no key has to be copied; otherwise explain which providers need an API key and what they cost. Offer only options supported by the installed Hermes version and do not pick for me. If I choose a local model, check the minimum context size in the Hermes docs and use a loopback endpoint so Mordred strict mode can accept it.
Set the model yourself with hermes config set model <provider/model>; that is not a secret. For the credential, open a terminal window running hermes model and tell me to select the provider there and sign in through the browser or paste the key. You never see the key. Wait for my non-secret completion signal.
5. MINIMAL HERMES VERIFICATION
Run hermes doctor, which makes no model call, and report the redacted result. Then ask whether I want one short billed test chat; if yes, open a terminal window running hermes so I can send one message, and skip it if I decline.
6. DECIDE WHO THE BOT LISTENS TO
Before creating anything, ask me in one message, with a recommended default for each: who may talk to the bot (default: only me), which channels it may answer in (default: one channel I name, plus direct messages), whether it needs an @mention to answer in channels (default: yes), whether it may read and upload files (default: ask me), whether voice messages are transcribed (default: off, because audio may be sent to a cloud speech service unless a local one is configured), and whether it needs a home channel for scheduled results (default: no). Keep the answers for the Telegram step; channel settings use channel or group IDs, not names.
7. PREPARE THE TELEGRAM CHANNEL
7.1 Recommend the simplest route: I open Telegram on my phone, message @BotFather, send /newbot, choose a display name and a username ending in bot, and copy the token from the reply. If I prefer the browser, open web.telegram.org to @BotFather; you may send /newbot and the display name, but start the capture blackout before the username is sent, because the reply contains the token. Resume capturing only after I say done and you have left that chat, and never open the @BotFather chat with capture on again.
7.2 Find my numeric user ID: open @userinfobot (or @get_id_bot), send any message, and read the number from the reply. It is not a secret.
7.3 Ask whether I want direct messages or a group. For a group: tell me how to add the bot to the group, then have me open @BotFather myself (phone preferred) and set /mybots → Bot Settings → Group Privacy → Turn off; never open the @BotFather chat yourself. Then have me remove and re-add the bot, because Telegram caches the privacy setting.
7.4 Open a terminal window running hermes gateway setup. Tell me to select Telegram, paste the bot token when asked, and enter my user ID as the allowed user. Wait for my non-secret completion signal.
7.5 State clearly in the final summary that Mordred bound E2E is not available for Telegram and do not imply that Telegram messages use a Mordred channel key.
7.6 After the wizard finishes, treat ~/.hermes/config.yaml and ~/.hermes/.env as secret-bearing: never open, diff, or edit them. Apply my answers from step 6 with hermes config set <key> <value> only, using the exact keys from the official Telegram guide; those values are IDs and switches, not secrets.
8. DECISIONS BEFORE MORDRED
Ask me in one message, explaining each choice in plain language with a recommended default:
- Gateway: foreground in a window I keep open, or a background service that starts on its own (recommended for always-on). On macOS a background service needs Mordred's keys created in unattended mode, so this must be decided now; the trade-off is that any program running as me can use the key while the Mac is unlocked.
- Policy mode: lenient (recommended to start; warns and audits) or strict (blocks anything not explicitly allowed; the cloud provider from step 4 must be allowlisted or every session will be refused).
- Cloud models: whether cloud providers are allowed at all. If yes, you will allowlist the provider chosen in step 4 yourself.
- Network route: clearnet (default), Tor, or VPN. VPN with Mullvad needs an account number, which I enter in a window.
- Protection level: STANDARD (recommended on macOS) encrypts .env and agent memory at rest, unlocked by this Mac's hardware key, with one recovery passphrase I choose and keep in a password manager. FULL additionally creates the Mordred keyvault with a 24-word seed in an offline ceremony with pen and paper; it is required on Linux and needed for keyvault-backed features. Tell me honestly that with STANDARD the audit log stays plaintext and keyvault-backed features stay unavailable until FULL is done.
9. INSTALL MORDRED
Download the official installer script from the Mordred Quickstart to a file, read it, and summarize what it will do before running it. Run it with the platform default. Do not use an ambient pip environment. If hermes-mordred is already installed, verify it instead and do not update it without my approval. Report the installed version; the installer changes no configuration.
10. CONFIGURE MORDRED (NON-SECRET, YOU RUN THESE)
Run hermes-mordred configure --non-interactive with --policy from the decisions step, --allow-cloud-llm plus --cloud-allowlist containing the step-4 provider if cloud models are allowed (otherwise --no-allow-cloud-llm), and --harness none, because Hermes is run directly rather than through a coding tool. Use the provider names that hermes-mordred configure --help accepts.
Run hermes-mordred network init --non-interactive --path <route>. If the route needs an account number or another credential, open a terminal window running hermes-mordred network init instead.
Run hermes-mordred keyvault enable-se on macOS or hermes-mordred keyvault enable-tpm on Linux; a system prompt may appear for me to approve.
Do not run the interactive hermes-mordred setup orchestrator; it would start the key ceremony inside your tool.
11. KEY CEREMONY (I RUN IT, YOU DO NOT WATCH)
STANDARD on macOS: open a terminal window running MORDRED_SEKEY_UNATTENDED=1 hermes-mordred encryption enable env if I chose a background gateway, or hermes-mordred encryption enable env otherwise. Tell me it asks once for a recovery passphrase that I choose and store in a password manager, and that Touch ID may appear. When I say done, open a window running hermes-mordred encryption enable memory.
FULL, and always on Linux: before anything goes offline, make sure the offline verification digest script from the Mordred usage guide and its blake3 dependency are available on this machine, and open a second terminal window ready to run it. Then open a window running MORDRED_SEKEY_UNATTENDED=1 hermes-mordred keyvault init (without the prefix if I chose a foreground gateway). Tell me: have pen and paper ready; when the Passphrase prompt appears, disconnect this computer from every network (Wi-Fi off, cable out); the 24-word seed is shown once and disappears after 60 seconds; verify it with the digest in the second window; stay offline until the digest is accepted; then reconnect. On macOS continue with the STANDARD commands afterwards.
Stop all shell, terminal, screen-observation, logging, and polling activity while I use those windows. Do not inspect their process, output, scrollback, or files. Resume only when I say the ceremony is complete. If I report a failure, ask only for a sanitized description that contains no key material; never request the raw output.
12. START AND VERIFY THE GATEWAY
Background: run hermes gateway install as me (a Linux system-wide service with sudo only with my approval). Foreground: open a terminal window running hermes gateway. Check hermes gateway status, then have me send one test message through Telegram and report the redacted result.
13. RUN STATUS
Run hermes-mordred status --json and explain each target in plain language: on, off, paused, exposed, sealed, open, and inactive on Linux. The exit code is not a health check. If I chose STANDARD, say that keyvault not initialised and a plaintext audit log are expected until FULL is done.
14. FINISH WITH A REDACTED REPORT
Print a short report containing OS, Hermes version, provider and model, Telegram gateway state, Mordred version and policy, status results, files changed, and backups created. Redact every credential as [REDACTED], confirm that the report contains no secrets, and list what is left for me: keep the recovery passphrase in a password manager and, if I chose FULL, keep the seed offline and consider a hermes-mordred keyvault export snapshot stored separately.