Show HN: Talos – An AI agent with a permission kernel between model and shell

Talos is an AI agent framework that introduces a deterministic security kernel between the LLM and the shell. It ensures that every tool call is authorized, sandboxed, and logged to prevent unauthorized system access.
Why it matters
It provides a critical security layer for autonomous AI agents, addressing the risks associated with giving LLMs direct access to system shells.
talos 0.15.1-alpha · deterministic gate · MIT
Verifiable enough that you can. A real shell, a confined Claude worker that builds, tests and browses for you, four chat channels. Every tool call passes a deterministic security kernel before it runs: each effect authorised individually, bound to its exact arguments, valid once, for thirty seconds.
subject acquired · the watcher of crete PolicyKernel.decide()
The real shell pipeline, running in this page: path floor → hardline → dangerous → effect . Type any shell command. Clean work runs, and every verdict is computed in front of you, with its reason. Nothing is sent anywhere.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in