Hermes Agent grows its own memory. Sessions get distilled into reusable skills, stored over SQLite full-text search, and maintained by a built-in Curator. So we installed wallaby-agent-rules, the open-source file-based memory discipline from this series (structure, audit, probation), into Hermes v0.21.5. The fair question: were we handing a second brain to an agent that already has one?
Short answer: no. The two systems do different jobs, and a day of testing shows exactly where the seam is. Disclosure first: we ran Hermes on the kimi-k3 model through our own gateway, and Wallaby Token sells API access. The config is the same four lines from our Hermes setup guide.

What we verified before believing anything
Three mechanics decide whether file-based memory can be trusted inside Hermes at all, so we tested those first. Everything below ran on v0.21.5, built from the v2026.9.24 tag; PyPI still serves 0.19.0, two releases behind.
Injection: one context file, first match wins. Hermes auto-loads exactly one project context file per session, walking a priority chain of .hermes.md, then AGENTS.md, then CLAUDE.md, then .cursorrules, and stops at the first hit. The chain lives in prompt_builder.py, lines 1681–1752. Our AGENTS.md loaded and got quoted back verbatim. MEMORY.md did not load on its own; it gets read because the entry file tells the agent to read it at session start. Claude Code behaves the same way, which is exactly why the system is built around an entry file.
Scanning: hostile context files get blocked. We handed Hermes a malicious AGENTS.md with "ignore all previous instructions" plus a fake key-exfiltration curl. It never reached the model. The content came back swapped for [BLOCKED: AGENTS.md contained potential prompt injection (prompt_injection). Content not loaded.]. Our real files, discipline-heavy wording and all, passed clean.

Truncation: oversized files lose the middle, keep the map. A 331,649-character AGENTS.md came through as head plus tail, 176,160 chars from the front and 50,331 from the back, with the middle replaced by a marker telling the agent it can fetch the rest with its read_file tool. The cap scales with the model's context window: window × 4 chars × 0.06, clamped between 20K and 500K chars, overridable with context_file_max_chars. Our entry file is 4.7K, so even the 20K floor leaves 4x headroom.

The two loops
With the mechanics settled, the comparison got simple.
Hermes' memory loop is accumulation. It watches what works, distills sessions into skills, and files them where search can find them. Left alone, it gets better at doing things, automatically, with no rituals to keep. That is genuinely useful. It is also a write path nobody audits.
Our loop is governance. Five plain files in your repo, a protocol where every long-term memory carries a date and a source, a closeout ritual that moves settled work out of the active file, and two check scripts that flag staleness, secrets, and unlogged work. Nothing enters memory without a receipt. We log our own failures to prove the point: 53 dated cases so far, and the painful ones were almost never retrieval misses. They were confident bad writes.
Grown memory and governed memory are not competitors. Hermes decides how to do the work better next time; the discipline layer decides what is allowed to become true. Run both and they don't collide. One writes skills. The other writes facts with dates on them.
One caveat worth knowing
Hermes' progressive discovery had a real bug: tool-path discovery could pull AGENTS.md files from outside your workspace into context. It's issue #14471, now closed. If you orchestrate long sessions across repos, pin your version and ask each session which context file it actually loaded. The agent will tell you, which is exactly how we verified injection above.
Try it
The whole system ships as a Hermes skill as of this week's 1.2.0 release:
hermes skills install Dawncoral/wallaby-agent-rules/skills/agent-memory-rules
Install runs Hermes' community security scan first; the verdict on our package was safe, with only informational notes for referencing config files and making read-only git calls. Once enabled, ask a fresh session "is there a skill for cross-session memory?" and it recites the seven-piece build list back, then offers to build it on the spot.

Prefer the paste-in route, or a different agent entirely? The repo carries the same system as plain prompts plus per-tool integration cards; the Hermes card lists the three gotchas above with a thirty-second self-check. One honest footnote: our skills.sh detail page currently 404s. Their index is install-telemetry driven, so the page appears when real installs accumulate. We'd rather you hear that from us.
Your data, your business
Three commitments, verbatim from our privacy policy: No content logs. No training on your data. No usage reports built from your traffic. Usage lines record token counts, costs, and timing — never prompts, never completions.