6766732620
hermes_cli/memory_setup.py::_write_env_vars() wrote provider-controlled .env entries with a direct Path.write_text() + post-hoc chmod, bypassing the denylist/regex/CRLF-stripping/atomic-replace validation that hermes_cli/config.py::save_env_value() already provides for every other .env writer in the codebase. A malicious or buggy memory-provider plugin declaring a crafted env-var name/value in its setup schema could inject arbitrary lines into .env. Routes memory-provider env writes through save_env_value(), and fixes a regression this surfaced in plugins/memory/supermemory/__init__.py:: post_setup(), which called the old two-parameter _write_env_vars(env_path, values) signature — restores the caller via context-local hermes_constants.set_hermes_home_override()/reset_hermes_home_override() instead of a removed env_path parameter, so explicit HERMES_HOME overrides during setup still resolve correctly. Adds test_env_file_created_with_secure_permissions, guarded on Windows (POSIX mode bits aren't enforced there, mirroring the existing skip in test_openviking_provider.py / test_supermemory_provider.py) since save_env_value's atomic-replace path creates the temp file at 0o600 before writing content, closing the TOCTOU window the old direct-write + chmod implementation had.