#!/usr/bin/env bash # Guard: hermes-agent/ is a read-only research reference and must NEVER be # committed, pushed, or shipped. This fails the commit/CI if any path under # hermes-agent/ is staged. # # Usage: # - pre-commit hook: scripts/guard_hermes_agent.sh --staged # - CI / manual: scripts/guard_hermes_agent.sh --staged # # Exit 0 = clean, exit 1 = hermes-agent/ paths detected. set -euo pipefail MODE="${1:---staged}" if [[ "$MODE" == "--staged" ]]; then # Every path currently in the index. Using `git ls-files --cached` (rather # than `git diff --cached`) makes this robust on the very first commit, # where no HEAD exists yet and `git diff --cached` is unreliable. We never # want hermes-agent/ in the index at all, so blocking on its presence is # both correct and safe. mapfile -t BAD < <(git ls-files --cached | grep -E '^hermes-agent/' || true) else # Fallback: any tracked file under hermes-agent/. mapfile -t BAD < <(git ls-files | grep -E '^hermes-agent/' || true) fi if [[ ${#BAD[@]} -gt 0 ]]; then echo "ERROR: the following hermes-agent/ paths are staged. This directory is a" >&2 echo "read-only research reference and must NEVER be committed (see .gitignore" >&2 echo "and docs/00-overview.md 'Disclaimers'). Unstage them with:" >&2 echo " git restore --staged " >&2 printf ' %s\n' "${BAD[@]}" >&2 exit 1 fi exit 0