Hermes Agent 0.15.0 adds speed, security, and multi-agent tools

Hermes Agent v0.15.0 shipped on May 28, 2026 with major performance, architecture, and security changes. The release cuts run_agent.py by 76%, speeds up startup and session search, and adds new defenses against prompt-injection attacks, according to the project.

Hermes Agent 0.15.0 adds speed, security, and multi-agent tools

Hermes Agent v0.15.0, released May 28, 2026, is the project’s largest recent update by volume of work and one of its most substantial changes in architecture and security. The release notes say the project landed 1,302 commits, 747 merged pull requests, 1,746 files changed, and closed more than 560 issues since v0.14.0, including 19 security-tagged issues.

The headline change is a major refactor of the agent’s core conversation loop. According to the Hermes team, run_agent.py shrank from 16,083 lines to 3,821, a 76% reduction, with the logic split across 14 modules under agent/*. The project says behavior stays the same, with thin forwarders kept on AIAgent, test patch paths preserved, and outside callers remaining compatible.

⚡ New to this?

This is a major update to an AI agent platform used for automation, coding, and task orchestration. A prompt-injection attack is when malicious text tries to trick an AI agent into ignoring its instructions; Hermes says it added new checks to block that. The release also changes how secrets are stored, using Bitwarden Secrets Manager instead of many separate API keys.

🦞 OpenClaw angle

If you run Hermes in automation flows, review any setup that still stores per-provider API keys in local env files and move those credentials into a central secret store. If your workflows use recalled memory or tool output as inputs, test them against prompt-injection cases and make sure your own tools return clear delimiters or structured output. If you use Kanban-style multi-agent runs, try the new per-task model overrides so cheap models handle routine subtasks while stronger models are reserved for verification and synthesis.

That refactor is paired with broader work on Kanban, Hermes’ multi-agent workflow system. The release adds orchestrator auto-decomposition, swarm topology creation, scheduled tasks, per-task model overrides, worktree-per-task support, and new worker visibility endpoints. The project says hermes kanban swarm now creates a full Swarm v1 graph in one command, with a root task, parallel workers, a gated verifier, a gated synthesizer, and a shared blackboard.

Performance work is another major theme. Hermes says it shaved another second off launch time, cut 47% of per-conversation function calls in a 31-turn chat test, and reduced hermes --version cold start time by 63%, from 701 milliseconds to 258 milliseconds. The release notes also say session search was rebuilt to run without an auxiliary LLM, dropping an old roughly $0.30-per-call tool that could take around 30 seconds for three sessions into a new tool that works in about 20 milliseconds for discovery and about 1 millisecond for scrolling.

Security changes are prominent in this release. Hermes says it added defenses against prompt-injection and “Brainworm”-class attacks by scanning recalled memory, marking tool results with delimiter markers, and keeping threat patterns in a central file. The project also added a security-guidance plugin that pattern-matches dangerous code writes, and it says those defenses are meant to stop attacks that try to hijack the agent through tool output, memory, or stored skills.

Credential handling also changed. Hermes now supports Bitwarden Secrets Manager, replacing multiple per-provider API keys with a single bootstrap token at startup. According to the release notes, bws installs lazily on first use, and Bitwarden can act as the source of truth so its values overwrite matching environment variables on startup unless the user flips the override setting.

The release also expands integrations. Hermes adds ntfy support as its 23rd messaging platform, new image generation providers for Krea 2 Medium and Krea 2 Large, a Nous-approved MCP catalog with an interactive picker, and a new optional OpenHands orchestration skill for delegating coding work. The Ink TUI gained a multi-session orchestrator, letting users list, switch, refresh, and close live sessions inside one window.

On the xAI side, Hermes added web search support, an xAI upstream for its local proxy, retirement detection for older models, natural speech pause tags for TTS, and a base_url guard to stop OAuth credentials from being sent to the wrong host. The release notes say Grok and xAI-backed models also now get OpenAI-style execution guidance to improve tool use and reduce bad completions.

The project says the release closed 15 P0 and 65 P1 issues in the same cycle. It frames v0.15.0 as a speed-focused update, but the release notes show that the work also reached into security, task orchestration, memory handling, model routing, and plugin architecture.

Source: Hermes Agent Releases ↗

More from Security News