Accepted outcome
The human Captain requests: when a first officer is asked to use Hermes Helmet to work on or review a named repo, treat that request as authorization to enroll that exact repo. An optional confirmation must not block when the Captain is away. Enroll, provision the Hermes checkout below the configured data root (in WisdomHelm /opt/data/repos), then continue the requested work. Silence by itself is not consent; the human's explicit named-repo delegation is the authority.
Merge when clean: yes
Implementation scope
Implement the portable product side in this repository. Inspect current v2 policy/CLI/setup and bundled skill contracts before choosing the smallest interface. Provide one deterministic idempotent enrollment command/transport seam reusable by issue, epic, and report-only review workflows. The first officer calls enrollment explicitly for the exact repo resolved from the human request (slug/issue/PR URL or verified Git origin); read-only status never enrolls or clones. Existing allowlisted repos remain no-ops. Honor explicit installation restrictions and allowed GitHub owners; do not add owners, credentials, token scopes, billing, or external providers. The configured Captain identity must authorize the operational enrollment and remain distinct from the worker. Reject malformed/credential-bearing URLs, unrelated repos inferred only from issue bodies, owner mismatch, path collisions/symlinks, wrong-origin or dirty existing clones, and missing worker access. Do not widen authority to forks or dependents implicitly.
Persist only the exact enrollment plus a sanitized request/actor receipt, with atomic/idempotent writes and recovery after interruption. A transport can provision the worker checkout while keeping worker credentials out of the host. Preserve merge-authority/manual-policy ceilings and independent exact-head review. Review-only enrollment must not dispatch issues or confer merge permission.
Update helmet-issue, helmet-epic, setup-helmet, portable review/recovery references, and the relevant policy/quickstart/Captain docs. Replace the current non-allowlisted-repo stop with this named-request preparation path when authorized; preserve actual scope/access blockers. Clarify that optional consultation is nonblocking because the request already grants exact-repo authority, not because lack of response grants consent. Host safety controls still apply.
Coordinate the interface through this issue/PR with the companion WisdomHelm ticket. Do not edit installed caches, generated host skill copies, or vendor checkouts. Bump the host candidate Python/plugin manifests consistently to 0.1.0rc4 / 0.1.0-rc.4; this is not authority to publish a stable release or replace an existing release artifact.
Verification
Add focused coverage for exact requested-repo enrollment and continuation, repeat/restart idempotency, read-only status/no request remaining nonmutating, review-only no dispatch, explicit restriction/owner/worker-access rejection, clone origin/path/dirty-state conflicts, atomic interrupted enrollment, and unchanged merge/identity/provider boundaries. Run the full public suite, packaging/skill contracts, Ruff and diff checks. Keep implementation proportional; reuse existing policy and provisioning contracts instead of a second queue or new consent service.
Worker writes and publishes a tested PR as yia-mw-agent. First officer independently reviews the exact head. Worker never merges. Do not directly edit another worker's branch.
Accepted outcome
The human Captain requests: when a first officer is asked to use Hermes Helmet to work on or review a named repo, treat that request as authorization to enroll that exact repo. An optional confirmation must not block when the Captain is away. Enroll, provision the Hermes checkout below the configured data root (in WisdomHelm
/opt/data/repos), then continue the requested work. Silence by itself is not consent; the human's explicit named-repo delegation is the authority.Merge when clean: yes
Implementation scope
Implement the portable product side in this repository. Inspect current v2 policy/CLI/setup and bundled skill contracts before choosing the smallest interface. Provide one deterministic idempotent enrollment command/transport seam reusable by issue, epic, and report-only review workflows. The first officer calls enrollment explicitly for the exact repo resolved from the human request (slug/issue/PR URL or verified Git origin); read-only status never enrolls or clones. Existing allowlisted repos remain no-ops. Honor explicit installation restrictions and allowed GitHub owners; do not add owners, credentials, token scopes, billing, or external providers. The configured Captain identity must authorize the operational enrollment and remain distinct from the worker. Reject malformed/credential-bearing URLs, unrelated repos inferred only from issue bodies, owner mismatch, path collisions/symlinks, wrong-origin or dirty existing clones, and missing worker access. Do not widen authority to forks or dependents implicitly.
Persist only the exact enrollment plus a sanitized request/actor receipt, with atomic/idempotent writes and recovery after interruption. A transport can provision the worker checkout while keeping worker credentials out of the host. Preserve merge-authority/manual-policy ceilings and independent exact-head review. Review-only enrollment must not dispatch issues or confer merge permission.
Update
helmet-issue,helmet-epic,setup-helmet, portable review/recovery references, and the relevant policy/quickstart/Captain docs. Replace the current non-allowlisted-repo stop with this named-request preparation path when authorized; preserve actual scope/access blockers. Clarify that optional consultation is nonblocking because the request already grants exact-repo authority, not because lack of response grants consent. Host safety controls still apply.Coordinate the interface through this issue/PR with the companion WisdomHelm ticket. Do not edit installed caches, generated host skill copies, or vendor checkouts. Bump the host candidate Python/plugin manifests consistently to
0.1.0rc4/0.1.0-rc.4; this is not authority to publish a stable release or replace an existing release artifact.Verification
Add focused coverage for exact requested-repo enrollment and continuation, repeat/restart idempotency, read-only status/no request remaining nonmutating, review-only no dispatch, explicit restriction/owner/worker-access rejection, clone origin/path/dirty-state conflicts, atomic interrupted enrollment, and unchanged merge/identity/provider boundaries. Run the full public suite, packaging/skill contracts, Ruff and diff checks. Keep implementation proportional; reuse existing policy and provisioning contracts instead of a second queue or new consent service.
Worker writes and publishes a tested PR as yia-mw-agent. First officer independently reviews the exact head. Worker never merges. Do not directly edit another worker's branch.