How Hermes Agent handles this
Hermes Agent runs continuously, so you start from whatever you left running: a note that a site needs attention, or a plain request. You ask it to raise the score on the magazine site. Hermes lists your sites, picks magazine, and calls optimize_site with dry_run on. The preview returns the plan and changes nothing. Ask Hermes to read the plan back in order and tell you the level, and to check list_modules so it knows what the site has before it proposes anything.
When you tell it to apply, the real pass applies each setting one at a time, checks the page after every change, and undoes anything that breaks it, taking up to two minutes per site. You get the applied list, the undone list with reasons, and the unfixable list. If the site has the Pro Critical CSS module, Hermes can generate critical CSS next and purge the cache afterwards. Without that module, generate_critical_css answers with an error, so ask about modules first.
Hermes cron is where it can help between sessions: the gateway runs each job in a fresh session, and nobody can answer a prompt during one. Use it for reading, not writing. A weekly job that reads get_score_history and leaves you a short note about regressions is safe to leave alone. A weekly optimize_site is not, because nobody reads the plan, and a connection token with Read-only everywhere on would refuse it anyway, since the Hub counts it as a write. After any applied pass, the Hub tells the agent to check verify_urls, and you should open them in a browser too.
Set up Hermes Agent once
Already connected? Skip to the prompts. Alternatives and troubleshooting are on the Hermes Agent guide.
1Put your sites in xSpeed Hub
Sign in at app.xspeedcache.com with Google or email; the Hub is free and has no site cap. Then connect each WordPress site from its own dashboard: click Connect Hub in the xSpeed Cache top bar, then Connect via xSpeed Hub. Each site needs the free xSpeed Cache plugin.
2Add xSpeed Hub to config.yaml
Add this entry under mcp_servers. auth: oauth tells Hermes to handle discovery, dynamic client registration, PKCE and token refresh itself. If you edit the file from inside a running session, Hermes reloads its MCP connections with a 30 second timeout, which is too short for a browser sign-in, so finish the entry and then run the login in the next step.
mcp_servers:
xspeedhub:
url: "https://app.xspeedcache.com/xspeed/mcp"
auth: oauth 3Sign in with hermes mcp login
Run this once. Hermes prints an authorization URL, opens your browser where it can, and waits for the callback on a local loopback port. Sign in to xSpeed Hub and approve. There is no token to paste; Hermes caches the credentials it receives under ~/.hermes/mcp-tokens. On a remote host, paste the redirect URL back into the terminal when Hermes asks, or forward the callback port over SSH.
hermes mcp login xspeedhub hermes mcp test xspeedhub
Full Hermes Agent setup, sign-in options and FAQ
Before you send a prompt that changes something
Reads change nothing on your sites, though contact_support emails xSpeed support. Writes run once your connection allows them, so your client's approval prompt and a read-only connection (the token's Read-only everywhere switch, or a Viewer sign-in) are the gates that matter. A Hermes server entry has a trust setting. The default, full, adds no approval prompt for that server's tools, and the approvals setting covers dangerous shell commands, not MCP tools. Set trust: untrusted on the xspeedhub entry and Hermes asks before every call to a tool that lacks a readOnlyHint of true. The Hub does not mark its tools that way, so with untrusted every Hub call asks, reads included. To remove writes instead of prompting, set tools.include on the entry to the read tools; the filter takes globs and include wins over exclude. The Hub itself has no confirmation step.
What do I ask?
Three prompts written for Hermes Agent. More for this job are below.
Use xSpeed Hub to preview an optimization for the magazine site at the standard level. Check which modules it has first.
Each Friday, read the stored PageSpeed history for every site from xSpeed Hub and leave me a note on any drop. Read only.
With xSpeed Hub, apply the plan to magazine, then generate critical CSS if the module is there and purge afterwards. Ask me first.
What happens, step by step
optimize_site is the Hub tool for "make my site faster". It measures the site, applies the recommended xSpeed settings one at a time, checks the page still renders after each change, undoes anything that breaks it, and reports what it applied, what it undid and what it could not fix. It reaches caching and asset delivery only. Page weight, images hosted on another domain and heavy video are outside it, and the report says so instead of claiming a win.
01
See where the site stands
The agent reads get_score_history for the last stored scores and list_modules for which modules exist on that site and what state they are in. Neither changes anything.
02
Preview with dry_run
optimize_site with dry_run: true returns the plan: each change and its tier, what would be skipped (already on, or needing a higher aggressiveness) and what it cannot fix. Nothing is applied. The tool description tells the agent to prefer this before the first real run on a site you have not optimized before.
03
Apply it
optimize_site without dry_run applies the plan. aggressiveness is safe (removals and server-side changes only), standard (the default) or aggressive, which includes settings known to break some themes and should be opted into deliberately. A run can take up to about 2 minutes per site.
04
Look at the site afterwards
When changes were applied, the result carries verify_urls and a note. The site checks its own HTML and reverts anything that breaks it, but it cannot run JavaScript, so verified: true does not prove the page works in a browser. The Hub tells the agent to open those URLs and check the page renders and the console is clean, or to tell you which URLs to check.
05
Reach for a number only if you named one
target_score (1 to 100, Pro sites only) turns one pass into repeated rounds toward that score, up to max_rounds, with 3 as the most per site. Each round is a real PageSpeed measurement and up to about 2 minutes. The result says why it stopped, and diminishing returns means what is left is outside what caching can reach.
06
Critical CSS on Pro sites
generate_critical_css generates above-the-fold CSS so the first screen can paint without waiting for the full stylesheets. It needs the Pro Critical CSS module on that site, and the site answers with an unknown-tool error without it. Pages are rebuilt with it on their next build, so the agent purges the cache afterwards.
Reference
| Main tool | optimize_site (write): measure, apply one setting at a time, verify, undo what breaks, re-measure |
|---|---|
| Preview | dry_run: true returns the plan and changes nothing |
| aggressiveness | safe, standard (default) or aggressive |
| Every site at once | site: "all" or a list of handles, one result per site, sites run one after another; the Hub's confirm-once instruction does not name optimize_site, so your client's prompt is the gate |
| Time | Up to about 2 minutes per site |
| target_score | 1 to 100; needs Pro on the site; without it the site runs one pass and says so |
| max_rounds | Up to 3 per site; only sent along with target_score; 12 rounds in total per call |
| Wide fan-out with a target | Each site gets fewer rounds, and the result carries a note saying so |
| Result fields | applied, skipped, reverted, unfixable, score, verified, rounds; verify_urls after a run that changed something |
| Already tuned site | Returns "everything is already on" plus what it cannot fix; that is an answer, not a failure |
| Critical CSS | generate_critical_css (write), Pro Critical CSS module required; purge_cache afterwards |
| Read-only connection | optimize_site and generate_critical_css are refused; dry_run is still a write call, so it is refused too. Applies to the connection token with Read-only everywhere on and to a Viewer sign-in, not to other OAuth sign-ins |
Rules worth keeping
- Run dry_run first. optimize_site changes live site settings as soon as your connection allows writes. The tool description tells the agent to preview first on a site that has not been optimized, but that is guidance, so your client's approval prompt and a read-only connection (the connection token with Read-only everywhere on, or a Viewer sign-in) are the real gates.
- Keep aggressive for a deliberate choice. It includes settings known to break some themes, and the agent should say so before using it.
- After a run that changed something, open the pages in verify_urls. The HTML checks cannot run JavaScript, so a page can pass them and still be broken in a browser. Do not call a run safe because verified is true.
- Relay the unfixable list. When a site is already tuned, the honest answer is that caching is done and the rest is page weight, hotlinked images or DOM size. The agent should not retry the tool or claim a gain it did not make.
- Only ask for target_score when you want the site driven to a number. Each round costs a real PageSpeed measurement, and a plain "make it faster" is one pass.
Good to know with Hermes Agent
Use Hermes cron for read checks only. A scheduled get_score_history can leave you a note on a drop, but a scheduled optimize_site runs without anyone reading the plan or opening the verify URLs afterward, and the Hub runs it as soon as the connection allows writes. Hermes adds no prompt for a server marked trust full, which is the default, so the preview and the real pass run unasked. Set trust to untrusted on the xspeedhub entry and Hermes asks before every Hub call, reads included, because the Hub does not mark its tools read-only. Or list only the read tools under tools include. Give automations a connection token with Read-only everywhere on if you can, and keep the real pass for a conversation where you can see the plan and check the pages.
More prompts for this job
They work in any client connected to xSpeed Hub.
Ask xSpeed Hub to preview what optimize_site would change on shop with a safe pass. Do not apply anything.
Use xSpeed Hub to optimize the blog site with the standard pass, then give me the pages to check by hand.
With xSpeed Hub, get docs to a mobile PageSpeed score of 90 if you can, and tell me why it stopped if it does not get there.
Use xSpeed Hub to show me what optimize_site would do on every site, as a dry run, and list which sites have the most left to change.
Use xSpeed Hub to generate critical CSS for shop, then purge the cache so the pages are rebuilt with it.
With xSpeed Hub, optimize shop, then compare the new PageSpeed score with the last stored one.
Using xSpeed Hub, what could optimize_site not fix on the shop site?
Frequently asked questions
Keep going
Raise the PageSpeed score with other agents
More with Hermes Agent
Documentation
- How to generate Critical CSS
- Performance recommendations
- How to run a speed test
- Free vs Pro: what is included
- How to write prompts for xSpeed Hub
- Hermes Agent + xSpeed
- Every AI agent that works with xSpeed
From the blog