Dark Mode for your agent.
give ur agent a private crypto address and tool use
Agent Boost gives Hermes fresh wallet addresses and shielded Sepolia payments. You set spending limits and review the exact payment before submission. Runs locally. Powered by Kohaku.
Wallet: research preview. Private search and private inference: coming soon.
Sepolia testnet only. Unaudited research software. Use disposable test funds; never send mainnet assets or real value.
Get started · Payment walkthrough · Future work · Privacy boundaries · All docs
- Kohaku integration: research preview. Wallet setup, fresh addresses, shielding, and private Sepolia test payments are implemented through Kohaku. See the architecture.
- MCP/policy framework: research preview. Hermes connects through MCP; spending limits, expiry, approval rules, and duplicate-execution protection are enforced in code. See the integration and capability contract.
- Anonymous inference: next, coming soon. We plan to support the draft Attested Confidential Inference (ACI) standard for attested confidential execution and ZK API usage credits for anonymous paid access.
- Private search: after anonymous inference, coming soon. Planned work draws on the Tiptoe paper and our private-re-search research and prototypes. We plan to extend the same ZK API usage credits approach to anonymous paid search.
You need a working Hermes install, Git, Node.js 22+, and npm. The wallet preview supports macOS (Apple silicon and Intel) and Ubuntu 24.04 ARM64.
git clone https://github.com/dmarzzz/agent-boost.git
cd agent-boost
make installRestart Hermes, then say:
Set up Agent Boost for me.
Hermes creates a wallet and shows a funding QR. Send the requested Sepolia test
ETH, then tell Hermes you sent it. Agent Boost shields 0.1 Sepolia ETH through
Kohaku and reports when the private balance is ready.
Next, ask for a payment:
Show me my wallets as a tree.
Hermes prints one live, address-free map using friendly wallet names. Public balances, every named private balance, and any wallet-controlled public change left by a private operation stay nested beneath their saved parent wallet. Active balances are refreshed; inactive balances are clearly marked last known.
Create a private balance called savings under agent-boost, then fund it with 0.1 Sepolia ETH from main.
Private balances are durable named pockets, not chat-only labels. You can add more than one beneath a wallet, fund one from its parent main account, or move a whole supported private denomination from one sibling pocket into another. Creation and funding each get their own chat preview and approval; a later clause never runs silently across a confirmation boundary. Creating a second wallet gives it its own independent set of pockets and policies, all restored when that wallet is loaded again.
Load my old wallet.
One task-level call resolves the wording against saved profiles. If exactly one inactive profile fits, Hermes shows its switch preview; if several fit, it asks which friendly name to load. Replying with just that name opens its switch preview. After approval, the same flow restores that wallet's durable setup and returns the fresh bounded-authority preview. Granting authority still requires its own later chat confirmation. You can create, adopt, archive, and switch among local Sepolia wallets without entering a seed, password, key, path, or internal wallet ID.
Send 0.02 Sepolia ETH privately to 0x2222…2222.
Use your intended recipient's full address. Hermes shows the amount and recipient for approval before submission. The walkthrough covers funding, permissions, payment status, and starting a new demo wallet. See installation details for paths, pins, and troubleshooting.
| Capability | Status | What you get |
|---|---|---|
| Wallet addresses + private payments | Research preview | Fresh Ethereum accounts and shielded Sepolia test payments through Kohaku. |
| Private search | Coming soon | An upcoming search capability. |
| Private inference | Coming soon | An upcoming path for selected subproblems to run on attested confidential compute. |
Also available: covered HTTPS reads through Shade Tree
After Grove enrollment, Hermes can fetch one public HTTPS resource through Shade Tree over Tor, with no direct fallback. Say:
Send a regular public transfer of 0.02 Sepolia ETH to 0x2222…2222.
Hermes uses the selected main account by default. If you explicitly say “from the savings public change,” it instead uses spendable public value nested under that private balance. It reserves gas, shows the exact public-transfer source, executes and verifies it in one task-level call, and never substitutes the private route. Regular and private sends share the same testnet delegation envelope. Your next chat reply—“yes,” “send it,” or ✅—confirms the shown plan; there is no separate interface or plan ID for you to operate.
Fetch https://example.com/data.json through covered egress.
This applies to that explicit request. It is separate from the upcoming private search product and does not reroute the whole agent session. Supported on macOS Apple silicon and Ubuntu 24.04 ARM64; the current Shade Tree binary is not available for Intel Macs. See covered egress.
The full walkthrough, including the security policy and evals, is in docs/DEMO.md. The MCP tools behind these conversations are documented in docs/TOOLS.md.
Hermes handles the conversation. Agent Boost is the local service that:
- reads current balances and readiness;
- checks spending limits and prepares the exact payment;
- requests approval before submission;
- tracks submission status and prevents duplicate execution;
- keeps signing material out of the model conversation.
Kohaku handles wallet cryptography and signing. Agent Boost communicates with Hermes through MCP. Wallet RPC runs over Tor with no direct-network fallback.
The design rule is simple: a better model should improve the conversation; balances and payment rules belong in code. Read the architecture and product philosophy.
flowchart TB
U[User] <-->|conversation and verbal approval| H[Hermes]
H <-->|MCP over stdio| A[Agent Boost sidecar]
A -->|loopback-only funding page| UI[QR onboarding UI]
A -->|bounded argv + random loopback RPC URL| K[Kohaku CLI]
A -->|fixed-origin JSON-RPC| T[Embedded Tor / Arti]
K -->|JSON-RPC via authenticated relay| T
K -->|supported protocol HTTP via its Tor client| E[(Sepolia + protocol services)]
T -->|HTTPS JSON-RPC through Tor| E
A -->|explicit HTTPS GET or HEAD| S[Shade Tree authenticated Proxy]
S -->|embedded Arti + RLN-proved CONNECT| W[(Public HTTPS destination)]
O[Event operator] -->|scan QR and fund| E
A -->|address, balances, policy, status| H
classDef person fill:#f1f1df,stroke:#536047,color:#17210f,stroke-width:2px;
classDef core fill:#11180c,stroke:#b9ff1d,color:#f1f1df,stroke-width:3px;
classDef route fill:#dff5a3,stroke:#536047,color:#17210f,stroke-width:2px;
classDef external fill:#fbfbef,stroke:#8b9580,color:#17210f,stroke-width:2px;
class U,H,O person;
class A core;
class UI,K,T,S route;
class E,W external;
The preview improves privacy within specific operations. It does not promise anonymity or make the whole Hermes session private.
- On-chain activity: initial funding is public. Shielding reduces direct linkability, but timing, amounts, and the small testnet anonymity set can still correlate activity.
- Network scope: wallet RPC uses Tor; the provider still sees RPC methods and payloads. Shade Tree covers explicit HTTPS reads after enrollment. Model-provider, browser, and other process traffic remain outside that scope.
- Local custody: keys stay out of prompts and tool results. Hermes and Agent Boost run as the same OS user, so a privileged local process can still access wallet files. This is not a hardware custody boundary.
- Approval: confirmation is mediated by Hermes. It is not independent authentication against a compromised agent.
Read the full privacy claims and threat model. Report vulnerabilities through Security.
| Read | For |
|---|---|
| Tools | MCP tools, inputs, and results |
| Architecture | Components and state machines |
| Capability contract | Guarantees and result envelopes |
| Configuration | Settings and defaults |
| All docs | Full documentation index |
npm ci
npm run check
npm test
npm run buildSee Contributing for conventions and the test layout.
Released under the MIT License.
The wallet preview remains unaudited research software. The license grants permission to use the code; it does not make the software safe for mainnet assets or real value.
