Skip to main content
Xerg supports optional local trace enrichment from the exact certified briancaffey/hermes-otel commit 0180c5e63b9d035ee0754d9a0d75c3499a8def26. This is not required for Hermes analysis parity: the first-party Xerg observer is the primary request and mechanical source. For the 0.33.0 compatibility update, separate bounded live acceptance passed with this plugin commit and Hermes v0.21.0 exactly 29112bef099274229cadff79cdff7bf7b99c4b77. The exercised gate verified request and tool correlation, state-authoritative economics, and content-free capture privacy. It does not certify other plugin/runtime revisions, every workload, or first-party observer delivery. Established older OTLP support remains unchanged. Use collect hermes --hermes-profile <name> to pair one profile’s state and capture. All-profile collection and upload fan-out are not supported. Hermes traces are never an independent monetary audit. A matching, auditable state.db is always required.

Start the collector

Xerg binds only to 127.0.0.1, accepts OTLP/HTTP protobuf traces at /v1/traces, prints the required plugin configuration, and waits for Ctrl-C. It never installs, enables, or edits the third-party plugin and never pushes automatically. Required plugin configuration:
Set HERMES_OTEL_DEBUG=false. The pinned plugin resolves YAML from ~/.hermes/plugins/hermes_otel/config.yaml, even when Hermes itself uses a non-default HERMES_HOME. For a non-default profile, use the equivalent environment configuration that xerg collect hermes prints (OTEL_JAEGER_ENDPOINT plus the HERMES_OTEL_* privacy and sampling variables). Environment values override plugin defaults. Xerg still does not edit either location.

Audit an existing capture

You may also add --hermes-events-dir. The observer remains primary. If observer and trace request totals disagree, Xerg retains the original state.db aggregate and reports the conflict. It never creates duplicate economic calls. The certified plugin reports its prompt-token bucket inclusive of cache reads and writes. Xerg converts that value to the uncached input bucket before exact reconciliation, preserving the separate cache buckets used by state.db and the first-party observer. Adding or removing optional trace enrichment does not change the authoritative economicAuditId or comparison key. The analysis auditId changes when trace evidence changes detector coverage or findings.

Correlation and privacy

Xerg creates one owner-only 32-byte correlation key per installation. Native session, trace, span, turn, and tool-call identifiers are HMACed before capture persistence. Only the key ID is stored in a capture. A moved capture without the matching local key remains readable for descriptive diagnostics but cannot split state economics. The sanitizer persists only bounded provider/model/tool/role/skill names, statuses, durations, token buckets, counts, hashed ancestry, and the certified plugin commit target. It drops prompt/response values, conversation content, invocation parameters, tool arguments/results, commands, paths/targets, goals, summaries, approval text, skill paths, user IDs, and arbitrary attributes even when plugin privacy settings are wrong. Limits match the OpenClaw collector: 16 MiB per request, 256 MiB per sanitized capture, and 100,000 decoded spans. Files are owner-only and no-overwrite; metrics, logs, JSON, gRPC, remote binding, and remote collection are rejected.