Give the canary the prompt. Keep the tools out of reach.
Little Canary checks a Hermes Agent user turn with structural rules and a local, powerless model. When it returns BLOCK, this plugin withholds downstream tool calls for that turn.
Maintained by Hermes Labs. Installed from the Nous Research community plugin catalog at reviewed commit 6abccc1aa9f3.
Install
You need Hermes Agent 0.21.3 or later, a local Ollama runtime, and the qwen2.5:1.5b model. Start Ollama if it is not running, then pull the model.
ollama pull qwen2.5:1.5b
hermes plugins install little-canary
hermes plugins enable little-canary
hermes plugins listThe catalog install selects the reviewed plugin directory and its compatible Python dependencies. hermes plugins list should show Little Canary enabled. The plugin calls the canary inside Hermes; you do not need to start the separate little-canary serve HTTP adapter for this integration.
To watch a clean and synthetic-attack pair through Ollama before trying the plugin, use the standalone live demo in a separate Python environment. The published little-canary==0.4.0 package is not the Hermes directory install route.
What a BLOCK does
The pre_llm_call hook checks the user message once. Its result can add a short warning, but Hermes still delivers the original prompt to the model. If screening returns BLOCK, the pre_tool_call hook refuses subsequent tools in that turn. No new tool is added to the agent.
If Ollama or screening is unavailable, the plugin reports degraded coverage and leaves tool calls available. It does not screen prior messages, tool responses, retrieved files, or every possible route into an agent.
If the catalog entry has not reached your client
Hermes caches its plugin catalog for up to six hours. You can inspect availability with hermes plugins search little-canary. For an immediate install from source, use the focused plugin directory:
hermes plugins install hermes-labs-ai/little-canary/integrations/hermes-agent --no-enable
hermes plugins enable little-canaryThat direct source command follows the repo revision instead of the catalog's reviewed pin. For a reproducible catalog install, use the short name after your client sees the entry.
Read the reviewed plugin source or the general Little Canary guide.