Nous Research · Hermes Agent · Placement proposal · Oct 2026

The browser
is a surface.
Not a plugin.

A placement for Hermes Browser Extension inside the Core & Edges plan — grounded in the draft map's own rules, and in code that is already on origin/main.

Read againstCore & Edges draft map
snapshot ac9a850 · 27 Sep 2026
ProductHermes Browser Extension
v0.3.4 · Chrome, Edge, Firefox
MaintainerJon Komet
github.com/abundantbeing
Hermes Browser Extension · Core & Edges — a placement proposal00 / 09
01 · The verdict

One product, three rings.

The map's own core test decides it. Run in order, the first yes wins — and it wins three different ways, because Hermes Browser Extension is three different things.

The ruling

A surface, beside the Desktop app.

The map's Surfaces layer is "how people reach the agent": CLI, Ink TUI, Desktop app, Dashboard, API server, webhook, Bot Mode. Hermes Browser Extension is exactly that — a full client for the agent, living where the user already works. Surfaces are core by the map's own ledger. The extension never enters the Python tree, so it costs the core zero lines.

Under it, two small edges. The controller lane — the part that lets the agent drive the user's real tabs — is the browser half of a ruling Teknium already made on 27 Sep: browser, local and on by default. The companion plugin is the opposite shape: optional, fail-soft, and it should leave core entirely.

Surface → core, external Controller lane → happy path Companion → official plugin Not a vendor plugin Not community

Why not vendor: rule ii says the vendor owns the vendor's integration — and the vendor here is Nous. There is no other company whose product this is. Why not community: a community entry has no corporate owner and no support commitment. A surface people reach the agent through cannot be adopt-a-plugin.

The core test, applied
01
Is the kernel broken without it?
Loop, prompt, tools, state, config, security, plugin host.
No → not kernel
02
Do most users touch it in session one — or is it Nous's own product?
The map's happy-path test, second clause.
Yes → happy path
03
Is there a company whose product it is, who could keep it working?
Nous → not vendor
04
Strategic for Nous, but not for everyone?
That's the official-plugin ring. Fits the companion only.
Companion only
01 · Verdict · the core test, applied verbatim01 / 09
02 · The map

Where everything lives today.

Every third-party integration in the tree, placed by the draft map's own proposal — category by sector, proposed home by ring. Solid dots are still wired into core; hollow ones are already plugins. The gold star is where Hermes Browser Extension's controller lane lands: the browser sector, happy-path ring, beside the Browser Use CLI and Chromium — both already ruled core.

Rings · proposed home

Core — the kernel, never a plugin
Happy path — in every install, on by default
Official plugin — Nous-maintained, own repo
Vendor plugin — the vendor maintains it
Community — catalog, adopt-a-plugin

Dots · where it lives today

Hardwired in core — solid dot
Split — plugin plus core residue
Already a plugin, or external
Hermes Browser Extension · proposed

The count

159third-party
integrations
51.8kvendor lines
still in core
30plugin seams
already built

Hover any dot. Data transcribed from the draft map, re-scanned against origin/main ac9a850 on 27 Sep 2026. The star is the only mark this proposal adds.

02 · Third-party ledger, as proposed · 159 integrations02 / 09
03 · The five rings

The line, and where we fall.

The map draws five homes. Hermes Browser Extension touches three of them — and the split is the whole argument.

Ring 01 · Core

The kernel

Loop, prompt, tools, state, config, security, plugin host. Never a plugin. Surfaces live here too: CLI, TUI, Desktop, Dashboard.

→ Hermes Browser Extension the product sits with the surfaces. It ships as its own repo and store listings — like Desktop ships as its own app — so the kernel stays untouched.
Ring 02 · Happy path

Day one

What most users hit in session one, on by default. Nous Portal, the big model routes, the big chat apps, a keyless web and voice path.

→ The controller lane. Browser Use CLI + Chromium are already ruled into this ring. The extension is the second browser, the one the user already has open.
Ring 03 · Official

Nous-maintained

Own repo, one click from setup. For what is strategic but not for everyone: hyperscalers, open protocols, power-user modes.

→ The companion plugin. Optional context cache, fail-soft, no core residue. Same shape as kanban, MoA and the Codex runtime in this plan.
Ring 04 · Vendor

Their product

When a company ships the product, it maintains the plugin in its own org. Nous keeps official plugins only where no vendor will.

→ Not us. The vendor of Hermes Browser Extension is Nous. Ruled out by rule ii.
Ring 05 · Community

No owner

No corporate owner; catalog plus adopt-a-plugin. Fine for niche engines and one-off skills. Not for a way people reach the agent.

→ Where it sits today, by default of never having been placed. This proposal moves it.
03 · Five rings · three of them ours03 / 09
04 · What is already true

Half of this already shipped.

The placement asks for nothing the architecture doesn't already do. The controller lane is on origin/main today, written against the map's own rules.

On origin/main   PR #91535 · merged Aug 2026

The controller lane

PR
#91535 — authenticated extension controller (salvage #85351)
Broker
gateway/browser_control_broker.py — 512 lines, transport-neutral
Router
tools/browser_extension_router.py — browser_* tools route per call
Contract
POST /v1/browser-control/register + WS /v1/browser-control/ws
Tickets
short-lived, single-use, identity-bound, consumed once
Safety
fail-closed once bound — never jumps to another browser
Config
extension_control, default off · developer_mode gates CDP
Tests
seven upstream test modules: broker, router, API, cloud, artifacts

Authored by abundantbeing and landed via PR #91535. Routes the existing browser_* tools — no new tool schema, no new names in the core tool list. That is rule v, one source of truth, already satisfied.

Open   not yet merged

The pairing flow

PR
#88203 — loopback extension pairing with scoped tokens
State
open, unmerged (companion pairing cited in #91535)
What
one approval click mints a bearer scoped to chat, models, context
Bound
loopback only — 403 for any non-loopback peer
Never
exposes the raw API server key

This is the one ask that touches core, and it is a security improvement on an open port rather than a feature. Everything else in this proposal lives outside the Python tree.

1,609GitHub stars
156forks
16contributors
21locales shipped
226test files
0core tool-schema lines

Repo figures from the GitHub API and extension repo (v0.3.4), Oct 2026. Tests cover the extension repo only; the seven controller-lane modules live in the hermes-agent repo.

04 · Already on origin/main · PR #88203 still open04 / 09
05 · How it wires

Two browsers, one router.

The map's section 05 keeps the Browser Use CLI as the default driver and moves agent-browser out to an optional browser-classic plugin. Hermes Browser Extension doesn't disturb that. It joins the router as a second lane — the user's own browser, with their sessions, behind one approval.

Agent loop
Decides a browser action. Knows nothing about which browser runs it.
browser_* tools
navigate, snapshot, click, type, scroll, back, press. One schema, unchanged.
Core · one source of truth
Extension router
Per call: bound controller and in scope → extension lane. No controller → legacy lane. Bound but unavailable → fail closed, never fall through.
On origin/main today
→no
controller
→controller
bound
Browser Use CLI 3.0
Drives a Hermes-managed Chromium over CDP. Ruled core, on by default, 27 Sep.
Core · ruling made
Hermes Browser Extension
The user's real browser. Tab leases, explicit consent, scoped bearer. Their logins stay in their browser — nothing is copied out.
Happy path · this proposal
browser-classic
agent-browser, Camofox, the legacy tools. The map already proposes this as an optional official plugin.
Official plugin · map's own plan

What the extension is

A full client, not a toolbar. Side panel over the page you're on, Bot Mode group chats across the agent roster, Hermes Assist drafting beside text fields, file attachments, voice, 21 locales. It speaks the gateway's existing API — sessions, runs, models, skills — so it inherits whatever the core becomes.

What it refuses

No silent capture. Page context is opt-in per connection, and remote or chat-only sessions never capture it. No credential handling — the vault work stays in core where the map put it. No second tool schema. When the extension isn't connected, every path reports unavailable and the agent carries on.

05 · Routing · fail closed, one schema05 / 09
06 · The seams it touches

Use the seams. Add one.

The map's rule iii: a category may only shed members after its seam exists and the built-ins go through it. Hermes Browser Extension was built against the seams that exist, and it needs exactly one that doesn't.

SeamStateWhat Hermes Browser Extension does with it
Cloud browsers
register_browser_provider
Extend · P2The map's own pluggability audit says this seam covers cloud browsers only, and lists extending it to local engines as the fix. The extension lane is that local engine. The router already behaves like the seam; registering it makes the seam honest.
Tools
ctx.register_tool
ExistsThe companion registers seven tools here. All fail-soft. None are kernel tools, so none belong in _HERMES_CORE_TOOLS — which is the map's stated end state for that list.
Hooks
pre_llm_call
ExistsThe companion lifts browser context out of the prompt here. Context stays untrusted data, never instruction.
Skills
register_skill
ExistsThe hermes-browser skill ships inside the companion and teaches the agent when the tools are worth calling.
Desktop UI
plugin contributions
Exists84 desktop catalog entries already. Browser control status and pairing approval render as contributions, not as forks of the Desktop app.
Credential vault
local Fernet store
Stays coreUntouched. The map keeps the local vault in core and moves 1Password and Bitwarden out to an official plugin. The extension never holds a credential.
Setup / tools UX
generic setup contract
Missing · P0The map flags this as the blocker for every extraction: once plugins declare their own config, hermes setup, hermes tools and the Desktop pickers must render it with first-party polish. The extension's connect flow is the first real client of that contract — so it funds the enabler instead of routing around it.

Seam states and priorities transcribed from the draft map's pluggability audit. P0 = the map's own "fund before anything else leaves" tier.

06 · Seven seams · one extension · zero new tool schema06 / 09
07 · Roadmap

It rides waves already planned.

The map sequences six waves, memory first, each with an exit you can check in the tree. Hermes Browser Extension doesn't insert a wave. It attaches to four that exist — and it can fund the one the map says to fund before anything else leaves.

Wave 1 · Enablers · next

Setup contract

Generic left-core migrator, plugin-declared config rendered with first-party polish, one source of truth for providers. The map says fund this before anything else leaves core.

Where we fitThe connect flow is the first client of that contract. We build against it rather than hardcoding a private setup path.
Wave 2 · Misplaced code · next

Delete the residue

Vendor tools left behind in core move into the plugins that already own them. Exit: deleting a plugin directory deletes the integration everywhere.

Where we fitNo residue to move. Context travels inside the prompt and the companion's own store. Uninstall is total.
Map §05 · Browser · ruled

Local, on by default

Browser Use CLI becomes the driver, Chromium ships through the package manager, agent-browser retires to browser-classic. Three PRs, each with a testable exit.

Where we fitThe controller lane lands beside that work, same router, same fail-closed rule. PR #88203 is the pairing piece.
Wave 5 · Long tail · later

Official repos

Kanban, MoA, pets, the local runtime and research tooling move to official repos. The companion plugin is the same shape and ships in the same wave.

Exit for usCompanion installs from the catalog in one command. Gone from every profile, the agent still runs.
Distribution · ongoing

Stores, not core

Chrome Web Store and Firefox AMO listings, owned by Nous, versioned with the agent. The extension repo stays standalone — store review cycles don't gate agent releases.

OwnershipTransfer the repo to the Nous org, or keep it community-owned under a written maintainer agreement. Either is honest. Undecided is not.
Explicitly not proposed

What we won't do

No bundled Chromium of our own. No second browser tool schema. No credential storage. No default-on page capture. No fork of the Desktop app.

The ruleIf a change can't name the seam it passes through, it doesn't ship. The map's rules apply to us first.
07 · Four existing waves · no new ones07 / 09
08 · The rulings, and the ask

Three rulings made.
This fits all three.

@Teknium · Sep 17

Memory leaves core

Providers move to their creators' repos, catalog-listed, auto-migrated. The companion follows the same shape: maintainer-owned, catalog-listed, gone without a trace.

@Teknium · Sep 27

Browser: local, default on

Browser Use CLI is the preferred driver. Chromium ships through the package manager. The extension is the other local browser — the user's own — behind the same router.

@Teknium · Sep 27

Computer use stays bundled

cua-driver is the only OS path to computer use, and it stays core. The extension never touches that path. Tab control is not desktop control, and the line should stay sharp.

What would make it official
01

Place it

Adopt the three-ring placement: surface beside Desktop, controller lane on the happy path, companion as an official plugin. Say it in the map so the next pass counts it.

02

Land the pairing

Review PR #88203. It's the only core change, it's loopback-only, and it removes a reason to share the raw API key.

03

Name the owner

Transfer the repo to the Nous org, or keep the current maintainer under a written agreement. Maintenance continues either way — the catalog needs an owner of record.

04

List it where users look

One catalog entry, one setup line, store listings under the Nous name. Rule iv: no UX regression. Connecting should feel like the Desktop app, not a sideload.

Bundling and packaging less things with the core agent, more plugins, leaner core. Not that we're not trying to be a personal assistant agent.

@Teknium · Sep 17, 2026 · the brief this map answers

Hermes Browser Extension is that sentence in product form. The core stays lean because the surface lives in its own repo, the plugin stays optional because it fails soft, and the agent becomes more of a personal assistant because it can finally see the page its user is looking at — with permission, and only then.

1open PR
touching core
0new tools
in the schema
3rulings
already met
08 · The ask · four decisions, no new architecture08 / 09
09 · Open decisions

Questions for alignment.

Key architectural decisions to settle during the technical review to align the browser surface with the core roadmap and upcoming unified gateway.

Q1

Does the three-ring split match how you see surfaces — product official, mechanism bundled, extras opt-in?

Context: Determines whether Desktop's proven model (core surface app + cataloged plugins) serves as the standard template for client surfaces.

Q2

The map moves agent-browser to an optional plugin. Should the user's own browser be on by default beside Browser Use, or opt-in?

Context: Evaluates day-one setup friction versus explicit user consent. The existing router supports either behavior without modification.

Q3

Is the extension's repo a Nous repo, or a community repo with a named maintainer agreement?

Context: Clarifies preference between formal organization repository ownership versus an official catalog listing with a dedicated maintainer.

Q4

PR #88203 has been open since August. Is loopback pairing the auth model you want, or is there a gateway-side plan it should fold into?

Context: Ensures alignment with upcoming unified gateway API authentication plans so the scoped pairing handshake converges seamlessly.

Q5

Store distribution — Chrome Web Store and Firefox AMO under the Nous publisher name. Who signs?

Context: Addresses official publisher credentials and whether extension signing should gate on core agent releases or follow an independent cadence.

Q6

The setup UX contract is the map's P0 enabler. Can the extension's connect flow be its first client, so the contract gets a real user instead of a spec?

Context: Determines whether the browser extension's connection flow can serve as the first production implementation of the generic setup contract.

Verification & Provenance

Every figure in this deck is verified against the draft map's data, the hermes-agent tree at origin/main, and the extension repository. Controller lane verified on origin/main as of October 2026: broker, router, seven test modules, extension_control defaulting off. Pairing verified as PR #88203 (open, unmerged). Stars, forks, and contributor counts verified via the GitHub API for Hermes Browser Extension v0.3.4. Designed to adapt cleanly to the unified gateway specifications.

09 · Open decisions · Jon Komet · abundantbeing · Hermes Browser Extension v0.3.409 / 09