Commit graph

10 commits

Author SHA1 Message Date
59bd0a0547 fix: chmod DESCRIPTION.md before overwrite in Nix sandbox
copytree makes files read-only in Nix sandbox; rglob("DESCRIPTION.md")
then tries to overwrite skill-level copies → PermissionError. chmod
0o644 before copy2 to handle already-existing read-only targets.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-03-22 02:00:02 +07:00
Ciphercat
880796fc0e feat(skills): add bundled.include for cherry-picking bundled skills
When bundled.include is set to a non-empty list, only the listed skills
are installed from the upstream bundled skills directory. When empty
(default), all bundled skills are installed (existing behavior).

Invalid include paths cause a build error with available skills listed.
DESCRIPTION.md files are only copied for categories that have at least
one included skill.
2026-03-18 22:03:07 +00:00
Ciphercat
0a03c43f90 docs: remove superseded skills PRD 2026-03-18 02:38:52 +00:00
Ciphercat
1a1f06aaa5 test: add skills coexistence e2e coverage 2026-03-18 02:32:27 +00:00
Ciphercat
a1b9295c8e feat: add declarative Hermes skills phase 1 2026-03-18 02:31:46 +00:00
Ciphercat
ba6c63e9bf ci: fix lint glob + format nix files 2026-03-18 02:24:18 +00:00
Ciphercat
e7b70a7b4d feat: persistent auth — seed-once, never overwrite on rebuild
- authFile now only copies to auth.json if it doesn't already exist
- Runtime token refreshes (OAuth rotate) survive nixos-rebuild
- Added authFileForceOverwrite option (default false) as escape hatch
- Committed AUTH-ANALYSIS.md documenting full auth architecture
2026-03-16 11:45:02 +00:00
Ciphercat
5930ea925d feat: add authFile option + sops-nix documentation
- authFile option for declarative OAuth token management
- sops-nix integration examples in README
- Plain file secrets example in README
2026-03-16 00:36:12 +00:00
Ciphercat
3dd03ba2ae feat: declarative NixOS module following nix-openclaw patterns
- Deep-merge config attrset → cli-config.yaml (like nix-openclaw's JSON config)
- Declarative documents option (SOUL.md, AGENTS.md, USER.md — inline or file paths)
- MCP servers as structured Nix options (merged into config)
- Environment files for secrets (systemd EnvironmentFile, outside Nix store)
- Non-secret environment vars (separate from secrets)
- Proper tmpfiles rules, activation scripts for config + document linking
- systemd hardening (NoNewPrivileges, ProtectSystem, PrivateTmp)
- Comprehensive README with full usage examples
2026-03-15 23:59:09 +00:00
Ciphercat
f70dc0f39b feat: initial nix package and NixOS module for hermes-agent v0.2.0
- buildPythonApplication with Python 3.12
- All extras included (messaging, cron, tts, voice, mcp, honcho, acp)
- Custom PyPI packages: fal-client, honcho-ai, agent-client-protocol
- NixOS module with systemd service for gateway mode
- Runtime deps wrapped: nodejs 22, ripgrep, ffmpeg, git
- Flake-based with overlay support
2026-03-15 23:49:39 +00:00