Finding / hermes-agent

2026-09-21-hermes-agent-unattended-platforms-webhook-msgraph-webhook-api-server-now-deny-dangerous-commands-by-def

Unattended platforms (webhook, msgraph_webhook, api_server) now deny dangerous commands by default. Before v2026.8.31, a webhook session hitting a dangerous command sat for the full approvals.timeout with nobody able to answer (#37284). Now webhook, msgraph_webhook, and api_server resolve instantly through unattended_mode (deny | approve), mirroring cron_mode.

Channel: tagged-release. Half: defect. Date: commit 2026-08-30; tagged 2026-08-31.

Operator consequence: Webhook and API-server automations that previously stalled will now fail fast with a BLOCKED result. Do not set unattended_mode: approve to make them pass; that auto-approves every flagged command from a caller who authenticated only with a webhook secret. Use command_allowlist pattern keys instead (honored when unattended as of v2026.9.21).

Receipt

Finding metadata

Run: 2026-09-21-weekly-digest-2026-08-20_2026-09-21-frontier-v0

Finding ID: 2026-09-21-hermes-agent-unattended-platforms-webhook-msgraph-webhook-api-server-now-deny-dangerous-commands-by-def

Profile citations

Source links

Primary links, including exact changelog lines when available.