Authenticated Hermes Agent backend with private continuous Timmy chat #48

Closed
opened 2026-08-20 15:23:48 +00:00 by timmy · 2 comments
Owner

Parent epic: #6

Depends on the simplified Timmy shell and must preserve #5 safety/privacy boundaries.

Outcome

Replace canned prompt buttons with a smart conversational Timmy backed by the full server-side Hermes Agent while preventing an unauthenticated browser from spending privileged tool authority.

Acceptance criteria

  • Hermes credentials and real Hermes session IDs never reach browser JavaScript
  • Agent is disabled by default and requires explicit server configuration plus authenticated browser access
  • Browser sessions map to opaque server-owned Hermes sessions with continuity
  • Same-origin, body/time/concurrency/rate limits, cancellation, sanitized errors, and expiry fail closed
  • Medical system brief prohibits diagnosis, symptom invention, autonomous treatment, and suppression of deterministic escalation
  • Smart chat supports free text and ledger-aware context, with graceful local fallback
  • Adversarial tests cover unauthorized use, session theft, prompt attempts to change tool policy, oversized input, and timeout
  • Release demo shows real chat continuity without exposing sensitive data

Required evidence

RED/GREEN tests, exact CLI/runtime receipt, API probes, mobile visual proof, and full suite.

Parent epic: #6 Depends on the simplified Timmy shell and must preserve #5 safety/privacy boundaries. ## Outcome Replace canned prompt buttons with a smart conversational Timmy backed by the full server-side Hermes Agent while preventing an unauthenticated browser from spending privileged tool authority. ## Acceptance criteria - [ ] Hermes credentials and real Hermes session IDs never reach browser JavaScript - [ ] Agent is disabled by default and requires explicit server configuration plus authenticated browser access - [ ] Browser sessions map to opaque server-owned Hermes sessions with continuity - [ ] Same-origin, body/time/concurrency/rate limits, cancellation, sanitized errors, and expiry fail closed - [ ] Medical system brief prohibits diagnosis, symptom invention, autonomous treatment, and suppression of deterministic escalation - [ ] Smart chat supports free text and ledger-aware context, with graceful local fallback - [ ] Adversarial tests cover unauthorized use, session theft, prompt attempts to change tool policy, oversized input, and timeout - [ ] Release demo shows real chat continuity without exposing sensitive data ## Required evidence RED/GREEN tests, exact CLI/runtime receipt, API probes, mobile visual proof, and full suite.
timmy added this to the M3 — Private Beta & Longitudinal Value milestone 2026-08-20 15:23:48 +00:00
timmy self-assigned this 2026-08-20 15:23:48 +00:00
timmy closed this issue 2026-08-20 16:25:48 +00:00
timmy reopened this issue 2026-08-20 16:35:36 +00:00
Author
Owner

Independent post-merge review found that deterministic urgent-symptom interception existed only in browser code, omitted common phrases, and did not inspect ledger flags at the authoritative server boundary. Hotfix in progress with red/green regression tests at domain, service, HTTP, and browser layers.

Independent post-merge review found that deterministic urgent-symptom interception existed only in browser code, omitted common phrases, and did not inspect ledger flags at the authoritative server boundary. Hotfix in progress with red/green regression tests at domain, service, HTTP, and browser layers.
timmy closed this issue 2026-08-20 16:48:03 +00:00
timmy reopened this issue 2026-08-20 16:56:21 +00:00
Author
Owner

Follow-up hostile review found a remaining common-phrase bypass: I threw up was not recognized. Release daily-2026-08-20.2 is superseded. A second red/green hotfix is in progress with domain, authoritative service, and browser coverage.

Follow-up hostile review found a remaining common-phrase bypass: `I threw up` was not recognized. Release daily-2026-08-20.2 is superseded. A second red/green hotfix is in progress with domain, authoritative service, and browser coverage.
timmy closed this issue 2026-08-20 17:17:34 +00:00
Sign in to join this conversation.
No project
No Assignees
1 Participants
Notifications
Due Date
The due date is invalid or out of range. Please use the format 'yyyy-mm-dd'.

No due date set.

Dependencies

No dependencies set.

Reference: stackchain/timmy-talking-turd#48
No description provided.