Show HN: Talos – An AI agent with a permission kernel between model and shell
talos-agent.ch
talos-agent.ch
Doubt you even read your own “645 line policy kernel.” Can you explain what that is and how it works in YOUR OWN words? If you paste Claude at us again we’re gonna know.
https://github.com/kamyar/ozm - Oberzugriffsmeister (“chief access master”)
Still some rough edges, and definitely not security audited. :)
In essence: All commands are routed through ozm, which has a per project and global allow list and block list.
Otherwise asks the user and does its best remembering what the user allowed to execute including debug/one off scripts that the agents write. If a previously allowed files was changed, it shows a diff of what changed since the last execution.
But, even if these attacks work .001% of the time, we will still need tools like these for higher assurance work.
That being said, I would never use this one, because OP is using AI slop everywhere, so I assume the product is totally vibed, and offers little in the way of new insights into the problem space.
Around that kernel: 23 gated tools, a UID-separated worker for delegated code, MCP servers confined to that worker from an operator-owned registry (no marketplace, no third-party code in the agent process), a hash-chained audit log, Ed25519-signed updates verified before anything unpacks, and a read-only live dashboard that has no approve button, by design.
Numbers the CI enforces on every page of the site: 2063 tests, 179/179 adversarial cases, 645 kernel lines, 0 inbound ports. The site has a browser reimplementation of the policy kernel you can poke at without installing anything, a replayed real session, and an honest comparison to OpenClaw and Hermes — including what Talos doesn't have (breadth; that's doctrine, not backlog).
Happy to answer anything — especially the parts where the design is wrong.
Site: https://talos-agent.ch — Source (MIT): https://github.com/talos-kernel/talos