mirror of
https://github.com/NousResearch/hermes-agent.git
synced 2026-05-02 16:57:36 +08:00
The env var HERMES_KEYSTORE_PASSPHRASE is now correctly positioned as a last-resort fallback for headless/Docker/systemd deployments, not as the second-choice unlock method. New unlock priority: 1. OS credential store (hermes keystore remember) 2. Interactive passphrase prompt (when TTY available) 3. HERMES_KEYSTORE_PASSPHRASE env var (headless fallback only) Updated docs and code comments to clearly communicate this is a conscious security tradeoff for unattended operation, not the recommended path.