6fbbe18be8
On an Anthropic subscription OAuth credential, every request failed with HTTP 400 "You're out of extra usage. Add more at claude.ai/settings/usage". That is not a billing condition: Anthropic's server-side content filter rejects the first sentence of Hermes' own built-in SKILLS_GUIDANCE prompt, and the rejection is surfaced with a billing-shaped message. Because the message points at the usage settings page, it reliably sends people to buy quota they do not need — the reporter lost three debugging sessions to it. Bisected against the live API with the real 71,721-char assembled prompt: the first SKILLS_GUIDANCE sentence alone reproduces the 400 and removing it alone clears it. Size was ruled out (20 KB of unrelated filler returns 200) and so was the system[0] identity gate (that returns 429, a different failure). Three changes, all serving the same outcome — a subscription user can no longer be misdirected by this 400: - agent/prompt_builder.py: reword the triggering sentence to the phrasing the reporter verified returns 200. Meaning, the skill_manage reference, and the ## Skill Safety Rule block are all preserved. The reword is empirically validated rather than understood, so a comment records the bisect and warns that any rewrite must be re-verified against an OAuth token, not an API key. - agent/conversation_loop.py: the Anthropic branch of the billing guidance no longer asserts exhaustion as fact. It hedges the opening line, names the content-filter alternative, and gives the operator a way to tell the two apart (if the usage page still shows quota, suspect a content rejection). It also points at `hermes auth reset anthropic`, because the credential exhaustion latch replays the stored error for ~60 min without issuing a request — which makes a real fix look like it did not work. - hermes_cli/auth.py: document that CLAUDE_CODE_OAUTH_TOKEN is an OAuth token, not an API key, despite auth_type="api_key". It stays in api_key_env_vars because that tuple doubles as the credential-discovery list; removing it would stop Hermes finding a `claude setup-token` credential at all. Docs updated to match the reworded prompt. Fixes #82154