The Archive · Android reference

Powers and consent

What the assistant of TALOS for Android may do on its own, when it asks you first, and what it can never be allowed to do without asking.

Reference for TALOS for Android 0.1.40 generated from the source of the release · released

Before a tool runs, TALOS decides — in the app, never in the model — whether it may run, must ask you, or must not run. Three things decide it: the powers you allow, the risk of the tool, and what the conversation has already seen.

Every tool declares the powers it needs. In Settings → Agent Tools you give each power one of three answers; “Ask me every time” is the default for all of them.

readRead your things
Reading your things: the Library, notes, tasks, memory, the calendar, the phone’s state. 22 tools.
writeCreate or change things
Creating or changing something: on this phone, in your records, or in the world (a switch, an alarm, a vibration). 51 tools.
outboundSend anything off this device
Sending something off this device: to the network, to another app, to a person — or out loud, through the speaker. 14 tools.

execute — Running code. Part of the vocabulary, not yet declared by any tool: until one does, the setting is not shown.

allow Always allow
The tools that need this power run without asking.
ask Ask me every timedefault
Each use asks you first, on a card in the chat. The default for every power.
deny Never allow
The tools that need this power never run; the model is told your settings refuse it.

A tool that needs two powers asks if either one asks, and does not run if either one is refused.

When a tool must ask, a card shows what it is about to do, with its arguments. “Allow” runs this call and saves nothing. “Always allow” saves a grant for this tool on this device: from then on it runs without asking, until you revoke it in Settings → Agent Tools. “Don’t allow” stops it; the model is told you declined. “Decide later” leaves the card for later.

When the model asks for several such steps at once, and one of them cannot be undone or together they reach R2, TALOS shows them as one plan: you can take steps out, then approve the rest at once. An R4 step is never part of a plan; it keeps its own card. How long an approval holds is set in Settings → Agent Tools → Approval duration: “This message”, or “The conversation, while trusted”, which ends as soon as pages or documents from outside come into it.

R04 tools
Touches nothing of yours: the clock, the state of the phone, the models installed. library_file_origintime_nowlocal_models_statusdevice_status
R34 tools
A heavy step: a message to a real person, a file sent out, who may see the Library. library_context_policy_updatedevice_notification_replyapp_azioneinvia_file
R41 tool
Takes the phone in hand: private data, untrusted content and a way out, all in one tool. device_screen_drive
read-only 14 tools
Changes nothing.
reversible 42 tools
Can be undone: edited again, switched back, deleted.
compensable 2 tools
Cannot be undone, but another action can make up for it.
irreversible 13 tools
Cannot be undone: there is no bin, or the world has already seen it.

Three marks of each tool say what it brings into the conversation and what it can let out:

private data readsPrivateData
Reads something of yours: files, notes, memory, the calendar, where you are, the screen.
untrusted content readsUntrustedContent
Brings in text someone else wrote — a page, a document, a notification — which may carry instructions.
leaves the phone canTransmit
Can send something off the phone: to the network, to another app, to a person, or aloud.

The conversation remembers whether private data and untrusted content have already come in. Two rules follow, checked before every call:

  • Effective risk. A tool that can let something out climbs one level of risk if untrusted content has already come in, and one more if private data has, up to R4. A search after reading a web page and your notes is not the same search as on an empty conversation.
  • The trifecta. When private data and untrusted content have both come in, and the next tool can let something out, TALOS asks you — even for a tool you set to always allow, save the exceptions below — and the card says why. It asks rather than refuses, so the protection is never worth switching off.

“Always allow” is not offered when the card is forced by the trifecta or by a tool that always asks, nor when the effective risk is R4 and the tool writes (the card says why). Three tools are exceptions, decided one by one where asking every time would make the tool useless: for them the choice is always offered and, once made, holds — web_search, device_screen_drive, app_azione.

The model is told why, in a result with one of these codes, so that it can tell you the truth instead of guessing:

CodeMeaning
TALOS_TOOL_DISABLED The tool is switched off in Settings → Agent Tools.
TALOS_TOOL_ARGUMENTS_INVALID The arguments did not match the tool’s parameters; nothing was asked or run.
TALOS_TOOL_DENIED_BY_POLICY A power the tool needs is set to “Never allow”.
TALOS_TOOL_DECLINED You answered “Don’t allow” on the card.
TALOS_TOOL_PREMISE_ABSENT What the tool acts on is not there (the torch is already off, the file does not exist): nothing was asked or changed.
TALOS_TOOL_PREMISE_UNKNOWN For a tool that must be sure of its target, TALOS could not check it: not run.
TALOS_TOOL_AWAITING_AUTHORIZATION The card has not been answered yet. This is not a refusal; the model should say the request is pending.
TALOS_TOOL_POSTCONDITION_FAILED The tool ran, and the check after it shows the change did not happen.
TALOS_TOOL_EFFECT_UNKNOWN The tool ran, and TALOS cannot tell whether the change happened: the model must not claim it did.
TALOS_DB_KEY_LOCKED The app is locked: its storage cannot be read until you unlock it.

A tool the security catalog does not list — a forged tool among them — is checked against the cautious default: R3, irreversible, private data, untrusted content, leaves the phone.

Type to search the guides.