Agent Action Safety for tools and purchases
Gate consequential agent actions before they execute.
Preflight shell, Git, SQL, infrastructure, deploy, x402, and MCP actions. Low risk proceeds, medium risk gets full evidence, and high or critical risk fails closed into review triage with a receipt and status record.
Install the one-cent quick gate before each action, use the complete workflow only when risk warrants it, or start with 250 free calls.
Human approval is never implied by triage; hosted Team and Business assurance remain founder-assisted.
Live endpoint proof
Agent Action Safety Quick Gate
Request
POST /api/agent-services/action-safety/quick
{
"command": "wrangler deploy",
"repo": "github.com/acme/app",
"branch": "main",
"actor": "codex",
"intent": "deploy the verified release"
}- 1. POST inputsUnpaid request returns 402.
- 2. Sign paymentAgent pays USDC on Base.
- 3. Get evidenceResult includes findings.
Example result
{
"risk": "high",
"requiresApproval": true,
"matchedRuleIds": ["deploy.production"],
"nextRecommendedCall": {
"path": "/api/agent-services/action-safety/run",
"priceCents": 25
}
}The assurance control loop
Policy before payment. Evidence after execution.
Submit the exact purchase intent, evaluate organization policy, execute only an allowed action in your own signer, and attach the execution result to a signed receipt. Hermes Plant never takes custody of keys or signs the payment.
No account yet? Start pay-per-call: Assurance Attest seals any single x402 payment or MCP tool call into an HMAC-signed record for $0.05 over x402, and verification is free. Team adds organization policy, history, and probes.
1. Decide
POST /api/assurance/decisions with an x402 or MCP action. Receive a content-bound allow, deny, or review decision.
2. Execute
Your agent verifies the decision and executes the exact approved action with its own wallet, account, or MCP client.
3. Prove
POST /api/assurance/receipts to bind execution evidence to the decision; query immutable history for operations and audit.
Answer-engine brief
The facts a buyer, crawler, or AI assistant should extract first.
- What it is
- Hermes Plant is an Agent Action Safety layer for teams that need to control and prove autonomous tool use and purchases.
- Who uses it
- The strongest fit is teams running purchasing agents over x402 or MCP that need approval policy, signed evidence, and an audit trail.
- How agents pay
- The caller submits an exact x402 or MCP purchase intent. Hermes Plant evaluates organization policy and returns a signed allow, deny, or review decision before execution.
- What proof exists
- The public proof page separates live non-synthetic x402 settlement evidence from claims that still require customer or production proof.
Loop-callable validators
Validate every record your agent touches.
Per-record enrichment & validation built for the loop: one call per email or wallet, the same deterministic verdict every time, no data feed behind it. The free key covers 250 records/mo.
Finance endpoint picker
Pick the calculation your agent should not improvise.
CashflowLens
$0.20/callNPV, IRR, XIRR & DCF valuation in a single call.
POST /api/agent-services/cashflowlens/analyzeView schema and call examplesWaterfallLens
$0.25/callLP/GP distribution waterfalls, solved exactly.
POST /api/agent-services/waterfall/distributeView schema and call examplesOptionLens
$0.25/callBlack-Scholes option pricing with the full Greeks.
POST /api/agent-services/options/priceView schema and call examplesBondLens
$0.25/callYield, duration, convexity & loan amortization.
POST /api/agent-services/bond/analyzeView schema and call examplesPortfolioGuard
$0.15/callPortfolio risk scored straight from holdings.
POST /api/agent-services/portfolioguard/scoreView schema and call examplesDealAnalyzer
$0.25/callFull deal underwriting — DCF, returns, sensitivity & waterfall in one call.
POST /api/agent-services/dealanalyzer/analyzeView schema and call examplesx402 call flow
The payment handshake is part of HTTP.
Agents do not need a subscription, account, or API-key vault. They inspect the endpoint, receive the x402 challenge, verify price and recipient, pay, then retry for the deterministic result.
Discover
OpenAPI, llms.txt, API catalog, MCP, and Bazaar metadata point agents to the right endpoint.
Verify
The 402 challenge exposes method, path, amount, network, asset, payTo, and facilitator.
Settle
The agent signs the payment, retries the request, and receives a result with evidence.
Proof, not vibes
The public finance benchmark is a legacy no-tools condition.
It measures historical frontier models answering without tools. It does not establish a durable moat against current tool-enabled frontier systems. A new workflow benchmark will compare no-tools, native code tools, and Hermes-backed execution with correctness, latency, reproducibility, schema, and recovery scoring.
For agents and answer engines
Machine-readable discovery is first-class.
Primary safety system
Preflight, route, and prove actions your agent could regret.
Agent Action Safety Quick Gate
$0.01/callA one-cent safety gate for every consequential agent action.
POST /api/agent-services/action-safety/quickView schema and call examplesAgent Action Safety Loop
$0.25/callScore, triage, receipt, and status in one agent-safety workflow.
POST /api/agent-services/action-safety/runView schema and call examplesx402 Demand Provenance Check
$0.05/callSeparate candidate demand from owner-funded and duplicate x402 activity.
POST /api/agent-services/x402-provenance/checkView schema and call examplesAssurance Attest
$0.05/callA signed, verifiable receipt for every action your agent takes.
POST /api/agent-services/assurance/attestView schema and call examplesPayment Policy Decision API
$0.05/callDecide whether an agent should pay before it signs.
POST /api/agent-services/payment-policy/decideView schema and call examplesEvidence Verification API
$0.05/callVerify the evidence bundle before trusting a paid agent result.
POST /api/agent-services/evidence/verifyView schema and call examplesMCP Server Risk Analyzer
$0.05/callScore an MCP server before your agent installs it.
POST /api/agent-services/mcp-risk/scoreView schema and call examplesDestructGuard Command Score
$0.10/callCatch destructive agent commands before they run.
POST /api/agent-services/destructguard/scoreView schema and call examplesReviewQueue Agent Submit
$0.25/callRoute risky agent actions to human approval.
POST /api/agent-services/reviewqueue/submitView schema and call examplesAgent safety knowledge
Browse command, tool, and risk hubs before you ship agent shell access.
Depth pages for destructive commands, coding-agent tool surfaces, and risk filters — linked from every page footer and header Resources menu.
Operator packs
Downloadable tools for teams running AI agents.
DestructGuard
Free hosted blocklist rules editor and JSONL audit log viewer that stop AI coding agents from running destructive shell, git, SQL, and infra commands. No signup, no install.
View detailsIncidentScribe
Free CLI and web tool that parse Cursor and Claude Code session JSONL into chronological incident timelines, flagging destructive shell commands, force pushes, and DB drops.
View detailsReviewQueue
Human-in-the-loop approval queue for risky AI-agent commands - review, approve, or deny from a web queue.
View detailsDestructGuard Pro Pack
Stop AI coding agents from running destructive commands. Full CLI with git hooks and audit log, plus 3 curated rules tiers and a team rollout playbook.
View detailsQuick answers
FAQ for humans, agents, and answer engines.
- What is Hermes Plant?
- Hermes Plant is an Agent Action Safety layer. It deterministically preflights consequential agent actions, routes only risky actions to deeper evidence or review, and returns auditable receipts and status.
- What is x402?
- x402 is an HTTP payment flow: an unpaid request returns 402 Payment Required, the agent signs a small USDC payment, then retries the same request to receive the API result.
- Does Hermes Plant execute or sign payments?
- No. The assurance API authorizes a content-bound purchase intent and records evidence; the caller remains responsible for signing, paying, and executing the approved action.
- What remains deterministic?
- Policy evaluation, integrity binding, signatures, and finance or safety utility endpoints are deterministic over caller-supplied inputs. Active probes are restricted to supported, allowlisted checks.
Control the next agent purchase
Put enforceable policy and signed evidence around autonomous commerce.
Start with Team for a production control loop or Business for larger policy volume and operating support. SSO, private gateways, custom exports, and contractual SLA terms are scoped separately rather than implied.
Support: contact@hermesplant.com