Skip to content
Hacker News front page

Talos: an AI agent that puts a deterministic permission kernel between the model and the shell

Show HN: Talos – An AI agent with a permission kernel between model and shell

Talos gives Claude a real shell but routes every tool call through a deterministic security kernel first. Each action is authorized individually, bound to its exact arguments, valid once, and expires in 30 seconds. All 23 tools declare their effect: reads run freely, writes are split into reversible and irreversible, and exec defaults to sandboxed. The post states it defends against model mistakes and tool-output injection, not a malicious model. Currently v0.15.1-alpha under MIT, with 2,063 unit tests and 179 adversarial cases that run on every install.

Why it matters: Talos gives Claude a real shell with a deterministic security kernel — per-action authorization, parameter-bound, one-shot, 30-second expiry. 23 tools classified by impact, execution sandboxed by default. Backed by 2063 unit tests and 179 adversarial cases, so it's not a conce...

Read the original ↗Export Markdown