fix: compose kind classification with capability manifests; per-entry isolation; docs

Follow-ups on salvaged #85287:
- discover_entrypoint_manifests() now carries BOTH the import-free kind
  classification (from #85527) and capability declarations — the two
  contracts compose in one function instead of the capability rewrite
  dropping classification.
- Per-entry exception isolation: one malformed distribution no longer
  blanks every other plugin's manifest (same contract as
  providers/__init__.py entry-point scan).
- Documented the hermes_agent.plugin_capabilities group in the plugin
  developer guide (pyproject example).
This commit is contained in:
Teknium
2026-08-13 11:52:13 -07:00
parent 90dacec87e
commit 4d30bb6bb8
@@ -253,6 +253,25 @@ config keys (`plugins.entries.<id>.allow_tool_override`, …) still work but
are deprecated — declare capabilities instead so users get a single,
auditable consent screen. Capabilities are consent + audit, **not a
sandbox**: they gate host API surfaces, nothing more.
**Pip-distributed plugins** have no `plugin.yaml` directory once installed,
so declare capabilities in distribution metadata instead, via the companion
`hermes_agent.plugin_capabilities` entry-point group. Each declaration is
named `<plugin-id>.<capability-id>` and points at the same object as your
`hermes_agent.plugins` entry point:
```toml
[project.entry-points."hermes_agent.plugins"]
calculator = "my_pkg:register"
[project.entry-points."hermes_agent.plugin_capabilities"]
"calculator.tools.override" = "my_pkg:register"
```
Hermes reads these from installed metadata without importing your code, so
`hermes plugins capabilities` and the consent flow stay accurate for pip
installs.
### Manifest v2 reference
`plugin.yaml` also supports an additive **v2 schema** (#64165). Every field is