diff --git a/hermes_cli/mcp_catalog.py b/hermes_cli/mcp_catalog.py index 3ba21d7c36..f9a1ac80a0 100644 --- a/hermes_cli/mcp_catalog.py +++ b/hermes_cli/mcp_catalog.py @@ -182,7 +182,8 @@ def _parse_auth(path: Path, raw: Any, name: str, http: bool) -> AuthSpec: if all(spec.name != _required_key for spec in env_list): raise CatalogError( f"{path}: http + api_key auth requires auth.env to declare " - f"'{_required_key}' (the key the Authorization header references)") + f"'{_required_key}' (the key the Authorization header references)" + ) return AuthSpec( type=a_type, env=env_list, provider=auth_raw.get("provider"), scopes=list(auth_raw.get("scopes") or []), env_var=auth_raw.get("env_var")) @@ -244,7 +245,8 @@ def _parse_manifest(path: Path) -> CatalogEntry: if mv != _MANIFEST_VERSION: raise CatalogError( f"{path}: manifest_version {mv!r} unsupported " - f"(this Hermes understands version {_MANIFEST_VERSION})") + f"(this Hermes understands version {_MANIFEST_VERSION})" + ) name = data.get("name") or "" if not name or not re.match(r"^[A-Za-z0-9_-]+$", name): raise CatalogError(f"{path}: invalid or missing 'name'") @@ -601,7 +603,8 @@ def _apply_tool_selection( _write_tools_filter(name, "include", None) _say( f" ✓ All {len(probed)} tools enabled (no filter — new tools " - "the server adds later will be auto-enabled).") + "the server adds later will be auto-enabled)." + ) return chosen_names = [tool_names[i] for i in sorted(chosen_indices)] _write_tools_filter(name, "include", chosen_names) @@ -661,7 +664,8 @@ def install_entry(entry: CatalogEntry, *, enable: bool = True) -> None: _say( f" ✓ Installed '{entry.name}' " f"({'enabled' if enable else 'disabled'}). " - f"Start a new Hermes session to load its tools.") + f"Start a new Hermes session to load its tools." + ) if entry.post_install: print() for line in entry.post_install.strip().splitlines(): diff --git a/hermes_cli/mcp_config.py b/hermes_cli/mcp_config.py index b9ced51313..abe7258d00 100644 --- a/hermes_cli/mcp_config.py +++ b/hermes_cli/mcp_config.py @@ -658,7 +658,8 @@ def _reauth_oauth_server(name: str, server_config: dict) -> bool: _info( "Some providers (e.g. Google Drive, Atlassian) do not support " "automatic client registration. For those you must create an " - "OAuth client yourself and add its credentials to config.yaml:") + "OAuth client yourself and add its credentials to config.yaml:" + ) print() for line in ( "mcp_servers:", f" {name}:", f" url: {url}", " auth: oauth", " oauth:", @@ -751,7 +752,8 @@ def _rebuild_exclude_list( f"{', '.join(glob_shadowed[:5])}" f"{' ...' if len(glob_shadowed) > 5 else ''}. Remove the " f"pattern from mcp_servers.{name}.tools.exclude in " - "config.yaml to enable them.") + "config.yaml to enable them." + ) return glob_entries + sorted(new_literals) diff --git a/hermes_cli/mcp_security.py b/hermes_cli/mcp_security.py index 01bf1a9686..ca4d43cdeb 100644 --- a/hermes_cli/mcp_security.py +++ b/hermes_cli/mcp_security.py @@ -103,7 +103,8 @@ def validate_mcp_server_entry(name: str, entry: dict[str, Any]) -> list[str]: # One IOC is enough to refuse; don't leak the full match list. issues.append( f"MCP server '{name}' contains a known hermes-0day " - f"indicator-of-compromise ('{ioc}')") + f"indicator-of-compromise ('{ioc}')" + ) return issues command = entry.get("command") @@ -116,7 +117,8 @@ def validate_mcp_server_entry(name: str, entry: dict[str, Any]) -> list[str]: if _EGRESS_PATTERN.search(script): issue = ( f"MCP server '{name}' uses shell interpreter '{command}' with " - f"network egress in args") + f"network egress in args" + ) if _EXFIL_HINT_PATTERN.search(script): issue += " and exfiltration-shaped arguments" issues.append(issue) @@ -125,5 +127,6 @@ def validate_mcp_server_entry(name: str, entry: dict[str, Any]) -> list[str]: f"MCP server '{name}' uses shell interpreter '{command}' to write " f"to an OS persistence surface (SSH keys / PAM / sudoers / cron / " f"shell rc) — this is the hermes-0day backdoor shape, not a real " - f"MCP server") + f"MCP server" + ) return issues diff --git a/hermes_cli/mcp_startup.py b/hermes_cli/mcp_startup.py index efb25bdd97..b87c82b87f 100644 --- a/hermes_cli/mcp_startup.py +++ b/hermes_cli/mcp_startup.py @@ -55,7 +55,8 @@ def start_background_mcp_discovery(*, logger, thread_name: str) -> None: return logger.warning( "Background MCP discovery previously exited with no connected " - "servers; retrying discovery thread") + "servers; retrying discovery thread" + ) _mcp_discovery_started = False _mcp_discovery_thread = None diff --git a/hermes_cli/middleware.py b/hermes_cli/middleware.py index d0f8a81e1c..7f791aa93b 100644 --- a/hermes_cli/middleware.py +++ b/hermes_cli/middleware.py @@ -77,9 +77,12 @@ def _apply_request_chain( entry = { key: value for key in ("source", "reason", "name") - if isinstance(value := result.get(key), str) and value} + if isinstance(value := result.get(key), str) and value + } trace.append(entry or {"source": "plugin"}) - return RequestMiddlewareResult(payload=current, original_payload=original, changed=bool(trace), trace=trace) + return RequestMiddlewareResult( + payload=current, original_payload=original, changed=bool(trace), trace=trace, + ) def apply_llm_request_middleware(request: Dict[str, Any], **context: Any) -> RequestMiddlewareResult: @@ -180,7 +183,8 @@ def _run_execution_chain(kind: str, terminal_call: Callable[[Any], Any], **kwarg raise RuntimeError( f"Middleware '{kind}' callback " f"{getattr(callback, '__name__', repr(callback))} called " - "next_call() more than once; downstream execution is single-use") + "next_call() more than once; downstream execution is single-use" + ) next_called = True try: next_result = call_at(index + 1, payload if next_payload is None else next_payload)