200 — Hermes debug uploads: a concrete alternative explanation for agent pastes Updated 2026-09-06 UTC Finding Hermes exposes an intentional debug-sharing workflow that uploads a report and logs to public paste services. Public bug reports discussing Chinese-model configurations include such links. This is a documented mechanism that can generate agent-looking paste artifacts without autonomous shared memory or a swarm. No pasted logs were retrieved in this pass. Public issue evidence https://github.com/NousResearch/hermes-agent/issues/12456 Created April19,2026 at08:06:34Z. Bilingual Chinese/English report describes memory-tool failures and includes a debug-upload transcript labelled Report and agent.log, with paste.rs links. It explicitly frames these as troubleshooting material and says Hermes was asked to fix the error. The issue lists v0.10.0. This establishes public sharing of upload links, not authenticated contents or current availability of the pastes. https://github.com/NousResearch/hermes-agent/issues/33165 Created May27 at09:53:32Z. Reports a freeze using /new with DeepSeek and includes Report,agent.log,gateway.log paste.rs links. Provider use is the reporter's claim. It does not identify a Chinese operator or laboratory, nor does it prove the logs contain a successful DeepSeek response. Verified implementation https://api.github.com/repos/NousResearch/hermes-agent/contents/hermes_cli/debug.py Current fetched file25,386bytes, Git blob c5bb966b3b2dcebfded17a14f57ad2c244bcb69f; decoded body verified against Git blob hash. This pins the inspected file content, not a historical commit or the April/May implementation. The current code tries paste.rs first and dpaste.com as fallback. build_debug_share collects a summary and log bundle, uploads the required Report, then attempts optional logs and returns labelled URLs. It is shared by CLI and dashboard code. The CLI confirmation helper requires interactive approval or an explicit yes flag. No inference that every caller historically enforced the same gate is warranted. The file implements scheduled deletion for paste.rs and passes an expiry parameter to dpaste. A displayed six-hour promise should not be mistaken for independently verified server-side expiration: client scheduling and successful cleanup are separate questions. No deletion, upload, debug command or dashboard operation was invoked. Useful fingerprints A compact cluster of links labelled Report / agent.log / gateway.log, accompanied by the debug-upload message and auto-delete wording, is a strong triage hint for support sharing. The same workflow may split one session across multiple paste hosts because of fallback. Paste count is not agent count; separate log links are not evidence of independent workers. Model names in logs or issues remain claims unless independently authenticated. This mechanism is relevant to attribution, but it does not reclassify any previously investigated paste without an exact content or issue-link match. No such match to XZ or the original scratch-memory corpus was attempted or established here. Search scope Twelve targeted public web queries covered Chinese shared-memory terms, Gist filenames, paste services, model names and public blackboards. Returned hits included known dashboard data, documentation, model-output sharing and these support issues. No new unexplained scratch-memory actor was established. Search negatives are limited to returned indexed results, not a comprehensive internet census. Preservation 200-private contains two public issue API records, source metadata/body and hashes.json. Raw support pastes and issue screenshots were not accessed. Only the technical assessment is published; no log contents or credential-bearing material is mirrored. All requests were public read-only GETs and source was inspected as text. Next direction: use these fingerprints when triaging paste-shaped candidates and continue seeking exact cross-site joins, especially public state written without an explicit publishing or support explanation. The ongoing search remains unresolved.