İçeriğe geç / Skip to content / Zum Inhalt

Hermes Agent: Telegram, Scheduled Tasks and Security

Ahmet Balaman

6 min read

Vibe CodingHermes AgentTelegram BotAI AgentAutomationSecurity
Hermes Agent: Telegram, Scheduled Tasks and Security

Once Hermes Agent is installed, it becomes truly useful through three things: being able to talk to it from your phone, being able to schedule work, and being able to limit what the agent can touch. This post is the second part of the series. I covered installation in What Is Hermes Agent? How to Install; here we set up the Telegram gateway, scheduled tasks and security settings step by step.

This post is based on the official documentation; I have not tried these settings on my own server. The commands and key names are taken from the documentation, with sources at the end.

1. Connecting to Telegram

The gateway is the part that exposes the same agent to messaging apps. Steps for Telegram:

  1. Talk to @BotFather in Telegram, send /newbot, and pick a name and a unique username ending in bot. It will give you an API token.
  2. Find out your own numeric user ID (the documentation and guides mention bots like @userinfobot for this).
  3. Run the wizard in Hermes:
hermes gateway setup

Select Telegram and enter the token and your user ID. If you prefer to do it by hand, add these two lines to the ~/.hermes/.env file:

TELEGRAM_BOT_TOKEN=botfather_token
TELEGRAM_ALLOWED_USERS=your_user_id
  1. Start the gateway:
hermes gateway

Now when you write to the bot, the agent responds. You can also continue a session you started in the terminal from Telegram; sessions persist across platforms.

Commands that are useful inside Telegram: /model (model picker), /sethome (makes this chat the default destination for scheduled task output) and /topic (multiple sessions in direct messages).

Notes on groups

If the bot does not respond in groups, you need to turn off privacy mode with /setprivacy in BotFather or make the bot an admin. After changing the setting, you must remove the bot from the group and add it again. There is require_mention: true so it responds only when mentioned rather than to every message.

2. Scheduled tasks (cron)

Hermes has its own scheduler and can send output to the platform you want. You can create tasks three ways:

From chat:

/cron add "every 2h" "Check server status"

From the command line:

hermes cron create "every 1h" "Summarize the latest news" --skill blogwatcher --deliver telegram

In natural language: just say "Every morning at 9, check Hacker News for AI news and send me a summary on Telegram"; the agent sets it up with its own scheduling tool.

Supported time formats:

Format Example
One-time delay in 30m, in 2h
Interval every 30m, every 2h
Natural time every day at 9am, weekdays at 9am
Cron expression 0 9 * * *
Date 2026-03-15T09:00:00

The output destination is chosen with deliver: origin (the chat where it was created), local (a file under ~/.hermes/cron/output/), telegram, discord, slack, email and others, comma-separated for more than one.

Management commands: hermes cron list, /cron pause <id>, /cron resume <id>, /cron run <id> (run now), /cron remove <id>. To stop everything, hermes pause.

Limits of scheduled tasks

The documentation spells out four limits, and all of them protect you from a wrong design:

  • Each run is an isolated session. It does not remember the previous run; the prompt must contain everything the agent needs.
  • No recursive scheduling. A scheduled task cannot create another scheduled task.
  • Delivery is one-way. The agent does not see your reply to the message it sent.
  • You do not have to hand the job to the LLM. With --no-agent --script script.sh you can run just a script and avoid the model cost.

Remember that scheduled tasks call the model every time: a task that runs hourly means roughly 720 model calls a month. A third-party guide gives figures like 15 to 20 thousand input tokens per Telegram message; since it cites no source, measure your own usage.

3. Memory and skills: when do they help?

Memory provides continuity across sessions; a skill is the procedure for repeated work. A practical rule: if you are explaining a job to the agent for the third time, tell it "save this as a skill". How to write skills, and why you should read them before installing, is covered in the Agent Skill post. The same warning applies here: read the contents of a skill from someone you do not know before installing it.

Two invariant rules in the documentation also stand out: do not alter the agent's conversation history mid-session (it breaks the prompt cache), and keep chat roles in order.

4. Security: what the agent can touch

If an agent can run commands, a security setup is not a preference, it is a necessity. The layers in the documentation:

Command approval modes

  • smart (default): A helper model assesses the command's risk; it approves low-risk commands itself and asks you about uncertain ones.
  • manual: Always asks you for dangerous commands.
  • off: Disables all approval checks, same as --yolo. I would not recommend it even on your own machine.

If you answer "always" on a prompted command, it is added to the command_allowlist list in config.yaml. With approvals.deny you can define a pattern-based deny list; this list applies even in YOLO mode. In addition, commands such as rm -rf /, fork bombs and writing to block devices with dd sit on a hard block list that no setting can unlock.

Who can use the gateway

  • Always keep TELEGRAM_ALLOWED_USERS filled in. The documentation stresses this in particular; if you leave it empty, anyone who finds your bot can give commands to your agent.
  • DM pairing: If someone it does not know writes, they get an 8-character code valid for one hour; you approve it with hermes pairing approve <platform> <code>. There is rate limiting and a lockout after five failures.

Isolation

  • Docker backend: The container runs stripped of most Linux capabilities, with privilege escalation disabled and the process count limited to 256. If you use it on a server, choose this backend.
  • Do not run as root. The DataCamp guide lists this among its security recommendations.
  • Protect secrets with file permissions (.env readable only by you).
  • Update regularly: hermes update.

I explained why the framework around the agent (the harness) matters at least as much as the model in the harness post; approval modes and allowlists are exactly parts of that framework.

Frequently Asked Questions

How do I use Hermes Agent from my phone?

Set up the Telegram, Discord, Slack, WhatsApp or Signal gateway. For Telegram, create a bot in BotFather and run hermes gateway setup.

Can other people use my Telegram bot?

If TELEGRAM_ALLOWED_USERS is filled in, only the users on the list. If a user it does not know writes, a pairing code is sent and they cannot get access unless you approve.

Does a scheduled task remember the previous run?

No. Each run is an isolated session; all required information must be in the prompt.

Is Hermes Agent safe?

By default there is command approval and a hard block list. What actually determines safety is your settings: the allowlist, the Docker backend, a non-root user and the approval mode.

Should I turn on YOLO mode?

It is tempting when approving gets tiring, but what you switch off is exactly the protection layer. The smart mode gives a good enough balance for most work.

Sources

Comments