But, even if these attacks work .001% of the time, we will still need tools like these for higher assurance work.
That being said, I would never use this one, because OP is using AI slop everywhere, so I assume the product is totally vibed, and offers little in the way of new insights into the problem space.
Around that kernel: 23 gated tools, a UID-separated worker for delegated code, MCP servers confined to that worker from an operator-owned registry (no marketplace, no third-party code in the agent process), a hash-chained audit log, Ed25519-signed updates verified before anything unpacks, and a read-only live dashboard that has no approve button, by design.
Numbers the CI enforces on every page of the site: 2063 tests, 179/179 adversarial cases, 645 kernel lines, 0 inbound ports. The site has a browser reimplementation of the policy kernel you can poke at without installing anything, a replayed real session, and an honest comparison to OpenClaw and Hermes — including what Talos doesn't have (breadth; that's doctrine, not backlog).
Happy to answer anything — especially the parts where the design is wrong.
Site: https://talos-agent.ch — Source (MIT): https://github.com/talos-kernel/talos