Rule 14: model.provider MUST be 'harness' (custom_providers[0].name), NOT 'custom'.
When provider: custom, Hermes falls through to generic resolution path that
ignores key_env, producing 'no-key-required' → HTTP 401.
audit-hermes-config.py: encodes all 14 contract rules as automated checks.
Run before and after any Hermes config change.
Root cause: WAL #1471 (2026-07-19 Mumuni 401 incident)