HNHacker News
TopNewBestAskShowJobs

kurdman_007

7 karma · joined August 7, 2026

submissionscomments
kurdman_007··on Show HN: Talos – An AI agent with a permission kernel between model and shell
Thanks - that's exactly the bet. Instructions live in the context window, and anything in the context window can be argued with. The kernel can't be, because it isn't part of the conversation.
kurdman_007··on Show HN: Talos – An AI agent with a permission kernel between model and shell
Fair hit. I did lean on AI for the copy, and it shows - that's on me, and I'll rewrite the landing page in my own words. The engineering underneath is not vibed though: the policy kernel is ~645 lines you can read in one sitting, and every number on the site (2063 tests, 179/179 adversarial cases) is enforced by CI, not marketing. Judge the code, not my copywriting.
kurdman_007··on Show HN: Talos – An AI agent with a permission kernel between model and shell
Hi HN — maker here. I built Talos because I wanted to hand an agent a terminal without handing it my trust model. Every tool call (read, write, exec, delegate) passes a small deterministic kernel, ~645 lines of Python, that returns allow, needs-human or deny. Unattended runs can't ask, so needs-human becomes deny. The agent can never grant itself anything.

Around that kernel: 23 gated tools, a UID-separated worker for delegated code, MCP servers confined to that worker from an operator-owned registry (no marketplace, no third-party code in the agent process), a hash-chained audit log, Ed25519-signed updates verified before anything unpacks, and a read-only live dashboard that has no approve button, by design.

Numbers the CI enforces on every page of the site: 2063 tests, 179/179 adversarial cases, 645 kernel lines, 0 inbound ports. The site has a browser reimplementation of the policy kernel you can poke at without installing anything, a replayed real session, and an honest comparison to OpenClaw and Hermes — including what Talos doesn't have (breadth; that's doctrine, not backlog).

Happy to answer anything — especially the parts where the design is wrong.

Site: https://talos-agent.ch — Source (MIT): https://github.com/talos-kernel/talos