fix: compose kind classification with capability manifests; per-entry isolation; docs
Follow-ups on salvaged #85287: - discover_entrypoint_manifests() now carries BOTH the import-free kind classification (from #85527) and capability declarations — the two contracts compose in one function instead of the capability rewrite dropping classification. - Per-entry exception isolation: one malformed distribution no longer blanks every other plugin's manifest (same contract as providers/__init__.py entry-point scan). - Documented the hermes_agent.plugin_capabilities group in the plugin developer guide (pyproject example).
This commit is contained in:
@@ -253,6 +253,25 @@ config keys (`plugins.entries.<id>.allow_tool_override`, …) still work but
|
||||
are deprecated — declare capabilities instead so users get a single,
|
||||
auditable consent screen. Capabilities are consent + audit, **not a
|
||||
sandbox**: they gate host API surfaces, nothing more.
|
||||
|
||||
**Pip-distributed plugins** have no `plugin.yaml` directory once installed,
|
||||
so declare capabilities in distribution metadata instead, via the companion
|
||||
`hermes_agent.plugin_capabilities` entry-point group. Each declaration is
|
||||
named `<plugin-id>.<capability-id>` and points at the same object as your
|
||||
`hermes_agent.plugins` entry point:
|
||||
|
||||
```toml
|
||||
[project.entry-points."hermes_agent.plugins"]
|
||||
calculator = "my_pkg:register"
|
||||
|
||||
[project.entry-points."hermes_agent.plugin_capabilities"]
|
||||
"calculator.tools.override" = "my_pkg:register"
|
||||
```
|
||||
|
||||
Hermes reads these from installed metadata without importing your code, so
|
||||
`hermes plugins capabilities` and the consent flow stay accurate for pip
|
||||
installs.
|
||||
|
||||
### Manifest v2 reference
|
||||
|
||||
`plugin.yaml` also supports an additive **v2 schema** (#64165). Every field is
|
||||
|
||||
Reference in New Issue
Block a user