The Archive · CLI
Changelog
What changed in each version of TALOS CLI, newest first, from the changelog of the release in force.
Changelog of TALOS CLI 0.5.2
What changed in each version of TALOS CLI, as its changelog says — read from the npm package of 0.5.2. Newest first; every published version is listed on Versions.
Released Oct 9, 2026 · On npm
- Long sessions no longer stop after one minute of waiting for the model. With a long conversation (about 365,000 tokens in the stress test) Z.AI took more than a minute to start answering whenever its cache missed, and TALOS gave up after exactly 60 seconds with “The provider stopped before TALOS could tell whether the request finished”, every time. TALOS now waits up to 10 minutes for the first answer, like Claude Code, Codex and the official OpenAI and Anthropic libraries, and up to 30 if you set it (
talos provider configure <id> --timeout <seconds>). The 60 seconds TALOS had saved by itself are read as the new default; a time you chose stays. - When the model has not started answering, TALOS tries again by itself, up to 3 times, and says so. The line shows “Retrying · attempt 1 of 3 · no response”. Nothing is resent when part of an answer or a tool call already arrived, or when the connection broke after the request was sent. If all 3 fail, TALOS says the provider did not start answering in time, how many times it resent the request, and what to do (/compact for a very long conversation, a longer
--timeout). - Changing only a provider’s address keeps the time you chose. It used to go back to the default.
model effortreaches the model on Z.AI’s Anthropic port. Withzai-anthropic:glm-5.3-flash,talos model effort maxwas saved but-pwarned “not affirmed” and sent no reasoning setting. The levels Z.AI documents for that port (low, high, max) now count for its listed models, and the request carries them.- The agents pill says “1 agent”. It said “← 1 agents”.
Security
Section titled “Security”- The permission to use the network in one command is asked only where the network is really closed. A host that does not close the network no longer offers it to the model or asks you about it. And “allow shell for this session” no longer opens the network without asking: a command that asks for the network is still asked, outside Full access.
Changed
Section titled “Changed”- The guard against going round in circles counts a repeated command too. The same successful command with the same output, repeated, used to reset the count and was never stopped; now only a new change (a new write or command, or a different result) starts the count again. At the 5th identical call you are asked, as before.
talos doctorsays when another talos in PATH hides this one. It lists every talos in PATH with its version, and if an older one comes first (sotalosruns the old one) or a newer one is hidden behind it, thepathcheck fails with both folders and the command that fixes it (npm i -g talos-code@<version> --prefix "<folder>").- Claude Haiku 5.5 (
anthropic:claude-haiku-5-5) is in the built-in model list.
Released Oct 9, 2026 · On npm
Security
Section titled “Security”- Read-only git commands that write or run a program now ask first.
git diff,git logandgit showwith--output=<file>write that file,git grep -O <program>starts the program andgit diff --ext-diffruns the configured diff program; TALOS counted them as read-only and ran them without asking, in every mode that lets reads through. They are no longer read-only. - More secret file names are protected.
secrets.json,secrets.yaml,secrets.yml,secrets.toml,.secrets,credentials.jsonand service-account keys (*service-account*.json) now count as secrets like.env: reading one asks first, and searches leave them out and say how many.secrets.example.jsonand similar stay public. - An untrusted project’s rules no longer look applied. In a project you have not trusted,
talos config permissions dry-rundecided with the project’s own rules andtalos config listshowed them as effective, while no turn can start there.config list,get,originsand the dry-run now leave the project’s file out and say “N project rules not applied: this project is not trusted (talos project trust)”; once trusted, they show it as before.
- Z.AI uses your GLM Coding Plan. Z.AI bills the plan only on its own address, and TALOS always called the pay-as-you-go one: with a plan and no balance every request failed with “no credit”. TALOS now tries the Z.AI addresses with your key (the plan first, then the balance; China too), uses the one that answers and remembers it for that key. If Z.AI says the credit is finished in the middle of a task, TALOS tries the other addresses once, says “Z.AI said there is no credit on the pay-as-you-go balance: TALOS switched to the GLM Coding Plan and goes on”, and goes on. An address you set with
talos provider configure zai --endpointis always used as it is. - An empty balance is called an empty balance. Z.AI answers it with HTTP 429, and TALOS said “The model provider is limiting requests; TALOS retried… wait a moment”: nothing had been retried, and waiting does not help. It now says the account has no credit left and to add credit or pick another model. A real 429 still says rate limiting.
- A session killed in the middle of a turn resumes. After a crash, a power cut or the system closing TALOS for low memory,
--resumestopped with “This conversation no longer matches its saved context”. The resumed session now continues from the tool calls and results that turn had already completed, and keeps a note of what it cannot prove finished (a call with no result, an answer cut short). A session already broken this way resumes too. --output-format stream-json(protocol v1) reports every tool’s result. Only shell commands reported anything aftertool.started(their output, astool.completedwithdelta); a read, an edit or a search had no result event. Every tool call now ends with onetool.completedcarryingcontent,status(completed,failed,cancelled,unknown) and, for a command,exitCode. The shell’s output chunks are unchanged.- An answer cut by the model’s output limit is continued. It used to end the turn with “generation stopped without an answer”. TALOS now says “The answer hit the model’s output limit: TALOS asked the model to continue (1 of 3)” and the answer goes on, up to 3 times in a row; past that the turn ends with its own reason (
OUTPUT_LIMIT) and what to do. - A provider that stops sending in the middle of an answer is noticed in 5 minutes, not 30. Once an answer has started, 5 minutes with no text, reasoning or tool call (the provider’s “still working” pings do not count) end that request: with text already shown, TALOS asks the model to continue; with nothing shown, it resends the request as before. Before the first word nothing changes, so a long local prompt is not cut.
TALOS_STREAM_IDLE_MSchanges the 5 minutes (0turns it off). - A right click pastes again. With the mouse on, the terminal hands the right button to TALOS, which did nothing with it. TALOS now reads the clipboard and pastes it where a paste goes; several lines fold into
[Pasted text #N +X lines]as usual. - Shift+Tab changes the permission mode at once, even while TALOS works. On the way through plan mode it said “Change permission mode failed: That conversation is busy saving”. The new mode now applies to the next action at once; the part that only a new turn can use (plan mode’s planning tool) starts with the next turn. No message.
git -C <folder> statusandfindstrrun without asking, like the other reads.git -C,--no-optional-locksand--no-pagerbefore a read-only git command, andfindstr(unless/F:,/G:or/D:name files or folders), were asked for. The folder after-Cis still checked against the project like any path.- GLM 5.3 Flash through OpenRouter calls its tools again. OpenRouter sent
z-ai/glm-5.3-flashto one of its providers (OpenInference) that answers without calling tools: the model wrote the call as text, or said it had no write tool, and stopped. Measured with the same requests: that provider failed every time, Z.AI and DeepInfra did not. TALOS now leaves that provider out for this model by default. talos provider configure <id> --endpoint <url>saves the address again. It answered “The provider settings are not valid” for every provider, whatever the address. A--timeoutalone keeps the address in use.- A turn that changed many files no longer writes them all on its checkpoint row. The row names three files and counts the rest (“+31 more”);
/undostill lists every file.
Changed
Section titled “Changed”- The shell’s network follows the permission mode. In Full access a command reaches the network (an install, a fetch, a push) and its result says “network allowed”. In the other modes the network stays closed; when a command failed because of it, the model can ask to run it again with the network, which shows a card “… with network access” with only “Allow once” and “Deny”: no rule or earlier yes opens it. In
-p, with nobody to ask, it stays closed (NETWORK_NEEDS_PERSON). Only the network opens: the rest of the sandbox stays. - A model that goes round in circles is noticed. When the model calls the same tool with the same arguments and gets the same result again, with nothing changed in between, it now gets a note instead of the same result; at the 5th time TALOS asks you whether to let it go on (in Full access too). “No”, or
-pwhere nobody can answer, ends the turn with the reason. A write or a command that worked counts as progress and starts the count again. - Hooks and MCP servers in
.talos/hooks.jsonand.talos/mcp.jsoncan be trusted. TALOS read them, listed them and then refused to trust them (HOOK_RESOURCE_NOT_FOUND), so they never ran; only the older file names worked. - The conversation looks like the approved design. Your message is a highlighted row that starts with
›, the answer follows without a “TALOS” label, reasoning is one row (▸ Thought for 4s click to read), and a turn’s tool calls fold into two rows:● Read 2 files, searched 1 patternand● edited 1 file, ran 1 command(a click orctrl+oopens them). A call that failed, was denied or waits for you keeps its own row. While a call runs its row says which one. - “Jump to bottom” sits at the bottom of the conversation, centred. It was drawn on the first row, at the right.
- Every row of a turn stands two cells in, like the answer: notices, errors and the calls that keep their own row.
- The frame around it too. The header is
TALOS <folder> · <branch>; the composer has rounded corners and says what typing does now (“Ask TALOS, / for commands, @ for files”, or “Type to queue a message” while TALOS works); the footer is the permission mode and its key, and from 100 columns a second row with the model, the provider check, the tokens, the context and the folder. “full access” and “no sandbox” stay in the first row at every width.
- Excluded providers on OpenRouter, from the model and from the command line. The model can list the downstream providers OpenRouter must not use, and ask to exclude one or allow it again; that shows a card with what changes (before → after) and waits for your yes, once each time. You can do the same with
talos provider exclusions,talos provider exclude <name>andtalos provider allow <name>(--model <id>for one model). In-pthe model can only read the list.glm-5.3-flashleaves out OpenInference by default, where it did not call tools. - A hand pointer over what a click opens, in terminals that support it (kitty, Ghostty, foot). Windows Terminal does not support changing the pointer, so there nothing changes.
- OpenRouter routing per model.
models.<id>.providerRoutingin your configuration sets which OpenRouter providers serve a model:only,ignore,order,quantizations(fp8,bf16, …),requireParameters,allowFallbacks,sort. An entry you write replaces TALOS’s default for that model;providerRouting: {}removes it. A repository cannot set it.
Released Oct 8, 2026 · On npm
--helpon every command family.talos provider --help,talos session -hand so on print the usage of that family and its operations (they answered “Unknown option: –help” before, andtalos provider --helpa provider failure). A missing provider id (talos provider loginwith nothing after it) now says so instead of “The model provider returned an error”.talos diagnostic bundle --session <id|last>adds the conversation of one session to the bundle (opt-in). The default bundle is unchanged and holds no prompt or file content. With--session, the session’s events are included after keys, tokens, PEM blocks, environment secret values and the paths of your home folder and this project are masked; other paths, names, code, file contents and anything typed or answered are NOT masked, and the command says so. If the conversation cannot be proved free of the environment’s secret values, nothing is exported (DIAGNOSTIC_REDACTION_FAILED). The file is bounded (16 MiB; the first event and the most recent ones are kept, with a visible gap marker).
- Claude models: the reasoning level can be chosen, and it reaches Anthropic. The levels (
low…max) are read from the provider’s live model list (capabilities.effort) instead of being missing, so/effort,/modeland a configuredreasoningEffortwork on Claude 5.x. The chosen level is sent by name;xhighon a 4.6-class model, which the API refuses, is sent asmax(the same level under its other name, as everywhere else in TALOS); a resumed Claude 5.1+ session no longer gets stuck on a thinking block whose conversation prefix changed (the API is asked to drop the stale block). A tool call without arguments now resumes correctly on native Anthropic sessions. - A secret file inside the project is asked about again (security). Reading
.env(or any file TALOS treats as holding keys) inside the project, or a read-only command such ascat .env, was approved without asking anyone: the built-in rule “reads inside the project are fine” answered before TALOS looked at the secret. Intalos -pthe question was answered yes by itself and the file reached the model. Now only a rule you wrote for it, or you, can allow it; a mode (acceptEdits,bypassPermissions,auto) never does, and without a person (-p,dontAsk) it is refused with the reason. - Running a command in the background no longer makes TALOS distrust its own project. The output of a background command is kept in
.talos/processi-sfondo/, and that log counted as a project resource: the folder’s trust dropped, and the nexttalos --resumeortalos -pin the project failed withPROJECT_TRUST_INVALIDATEDuntil it was trusted again. Logs TALOS writes there are now left out; everything TALOS reads from.talos/(hooks, MCP servers, plugins, skills) still counts. - A configured reasoning effort is applied at start for models only the provider’s live list describes, waiting for that list at most 5 seconds instead of dropping the effort.
talos -pends even when the model left a command running in the background. The run used to finish its answer and then never exit, held open by the live command. Now the end of a headless run (last turn, failure,--timeout, Ctrl+C) stops the background commands of the session and of its delegated agents, and says which ones with their output files: aBACKGROUND_COMMANDS_STOPPEDwarning before the final event, andbackgroundStoppedin the--jsonresult (v1 and v2). A command whose exit TALOS did not see within 3 s is reported as such. Inside WSL the stop ends the command and its plain children; a Linux process the command detached (setsid,nohup, a server that daemonizes) can survive, and the warning says so.- The search tool never shows a secret file (security).
cercasearched hidden files too, and in a project where.env,id_ed25519,secrets.jsonor a.pemwere not git-ignored it returned their matching lines — keys included — to the model and the provider, with no question asked, while reading those files asks. Secret files are now left out of search results (lines, names and counts), the result says how many were left out, and reading one still asks first..envrcis now treated as a secret file too. - A link to a secret file asks like the file itself (security). Reading
config.txtwhen it is a symbolic link or a junction to.envwas judged by the link’s name; now the real file is checked. - A mouse or focus report that arrives in two pieces is waited for longer. An incomplete report is held 100 ms (it was 30 ms) before it is handed to the input as text, so a second piece that comes a little late is still put back together; a lone Esc is still never held.
- A secret file named before shell syntax is still recognised (for example
cat ~/.ssh/id_rsa*()). - A wildcard on the name of a secret file now asks like the name itself.
cat .e?v,cat .en*,cat ./.e*v,cat .en[v],cat .en{v,}andcat cert.p?mprint.envor a key file in a real shell, and TALOS did not ask: it judged the text of the command, and the shell expands the wildcard afterwards. Braces and* ? [..]patterns (with the extended@(..)forms) are now expanded against the real files of the working folder, and the question names the file the shell would read. A pattern it cannot explore (a folder that does not open, too many folders) asks. Not covered, and the command text says so for the same reason as before:eval, acdbefore the pattern, a variable that holds the whole name. On Windows the star also matches a file that starts with a dot (cmd and PowerShell do), so a bare*next to a.envasks there and does not on Linux or macOS. - Quotes and substitutions that rebuild a secret name now ask too.
cat .e""nv,cat ".e"nv,cat .e\nv,cat .e"n"v,cat $'\x2eenv'andtype .e^nv(cmd) all read.env, and so doescat .e${X}nvwhenXis empty: the command is now read the way the shell reads it after removing quotes and escapes, and a variable or$(..)inside a name counts as “anything”. The commands inside$(..)and backticks are checked as commands. Looking for the files behind a wildcard stops after 100 ms and asks instead of holding TALOS up, and only folders are opened for the middle of a pattern. - The dev log wrote synchronously per record with
existsSync+statSyncon every event, so a replayed history (thousands ofraw_eventrows) paid the filesystem tax line by line and pushed the resume past the 2 s threshold. The logger now serialises+redacts and queues pre-built lines (memory capped ~512 KiB) and flushes a batch per chunk — oneappendFileSyncper chunk, never per record — with flush-on-exit via theprocess.on('exit')hook, the uncaughtExceptionMonitor andcloseDevelopmentLoggingon every exit path; rotation is by size (internal counter, zero stats per record) and by time (new stamp, same.part-Nconvention), tunable viaTALOS_CLI_DEV_LOG_MAX_BYTES/_ROTATE_MS/_FLUSH_MS. Measured 52.1× on the replay flood (36,652 ms → 703.9 ms for 9,600 records, zero rows lost). Known declared windows: rows buffered at the moment of a signal arriving before the handlers are installed, or of SIGKILL/SIGQUIT, are lost; on a failed append the size counter may lag the real file (chunk dropped, never re-queued — logging never breaks TALOS). - While history replays,
runtime.raw_eventandui.runtime_eventdevelopment-log records are gated (replaying()on the controller, fail-open) and a singleruntime.replay.summary {sessionId, rawEvents}lands in the finally of attach — symmetric with live runs, sincehandleCheckpointRawconsumes nothing before the gate.
Known issues (to be fixed in 0.5.1)
Section titled “Known issues (to be fixed in 0.5.1)”- A session whose TALOS process is killed in the middle of a turn (a crash, a power cut, the system closing it for low memory) cannot be resumed:
--resumefails withCTX_HISTORY_DIVERGED. The session’s files are kept. - A provider stream that stays silent and is then closed by the provider ends the turn with the code of a stop (
fermato) instead of a provider error, and is not retried. - In
--output-format stream-jsonwith protocol v1, only shell commands report their output; the other tools have atool.startedand no result event. Protocol v2 (--protocol v2) reports every tool’s result.
Released Oct 1, 2026 · On npm
npm i -g talos-code@0.4.0, or talos update to see it.
Sub-agents now work in the background while you keep talking to TALOS, and TALOS runs on the same kernel as the TALOS desktop app.
- Background sub-agents. A delegated agent no longer holds the main agent’s turn: the main agent answers at once, the agent works on, and when it ends TALOS answers its result in a new turn. The result is shown as an agent row (“◆ Agent finished · <task>”, three lines of its summary, the rest with the transcript’s expand), never as your message.
/agents(also/subagents, and Alt+A): the agents of this session with what each one is doing (its last three steps).xor Ctrl+X stops the selected one;/agents stop <n|id|all>and/agents show <n|id>name them.- The status line says “2 agents working” while only agents work, and “· 2 agents in background” while TALOS works too.
- Leaving with agents at work asks first.
/exitoffers: wait for them and exit by itself once TALOS has answered their results, stop them and exit, or stay. The first Ctrl+C says how many agents an exit stops. talos -pwaits for its agents and the turn that answers them, and prints both answers. Ctrl+C, the timeout or a failed turn stop the agents still working.agentsin the configuration (user or project-user file):maxConcurrent(1–32, default 10),maxDepth(1–4, default 2),model(provider:model) andreasoningEffortfor the agents. A repository’s.talos-clicannot set them: they are ignored with a notice, likereasoningEffort.- When an agent’s work woke TALOS, the desktop notification says which agent finished; the terminal’s progress indicator stays on while agents work.
Changed
Section titled “Changed”- TALOS uses the kernel of the TALOS desktop app (one kernel for both): long outputs are cut in the middle with the total kept, retries follow the provider’s own wait, read rows show the file’s real line count, Linux symbolic links on a Windows drive are explained instead of reported as a denied permission, and a WSL command declares its user.
- Answers wrapped in a
```markdownfence are drawn as Markdown, and---is a rule. - A search row says “2+ results” when the scan was not complete (a file that could not be read, a Linux link, a time or size limit), instead of a count that read as final.
- Git submodules and nested repositories no longer block the tools; their files are covered by
/undo, their Git history is not, and that is said. - A local provider without a key (for example Ollama) that answers HTTP 401 or 403 is no longer reported as a refused key: TALOS says to check the endpoint or the server’s permissions.
- A key benched after repeated provider errors (no provider for the model, a timeout, the network) now says to wait or choose another model with
/model, instead of “add another key”, which would not help. - In a read-only session an artifact is no longer copied into the Library.
talos -p: Ctrl+C with TALOS idle ends at once.
Known limits
Section titled “Known limits”- macOS and Linux were not run; the private CI is blocked by Actions billing.
Verification
Section titled “Verification”- Typecheck and build pass. Unit: 2,084 tests, 2,080 pass, 4 skipped, 0 fail. Acceptance on the built CLI in a real pseudo-terminal: 297 of 297, including the new s39 (background agents:
/agents, stop,/exitwait,talos -p). Standalone package check: pass. - Tarball (2.4 MB, 508 files) installed with
npm install -gfrom an outside folder into an isolated prefix and profile in 13 s:talos --versionprints 0.4.0, andtalos doctor --jsonpasses every check (configuration, data and cache paths, git, keyring, kernel, project, MCP, hooks), asking only to choose a provider.
Released Sep 30, 2026 · On npm
npm i -g talos-code@0.3.3, or talos update to see it.
Reliability fixes: select and copy the conversation with the terminal’s own mouse selection again, see how long quick turns took, understand a paused compaction, and ask any subcommand for JSON.
Changed
Section titled “Changed”- Mouse tracking is now off by default, so dragging selects conversation text and right-click or Ctrl+C copies it, as in any terminal program. Wheel scrolling is still available: turn it on in
/configfor the current project (it applies from the next launch) or setui.mouse: true. With it on, hold Shift while dragging to select. A savedui.mouse: truekeeps working as before. - A turn that ends in under a second now shows its duration (“done 0.4s”). A resumed conversation no longer shows the time it took to replay a turn as if it were the turn’s own duration.
- The room kept for the answer (sent to the model as
max_tokens) is now the smaller of the model’s stated maximum and 32,000 tokens, never more than a quarter of the window, instead of the model’s whole stated maximum. Conversations get more room before compaction. Your ownmodels.<provider:model>.maxOutputTokensis kept as set; set it for answers longer than 32,000 tokens.
- Models whose provider states a maximum output close to the whole window (for example 943,717 of 1,048,576 tokens) no longer stop before the first request with “context window is too small”. If your own setting still leaves no room, TALOS uses its simple mode instead of refusing, and the error, where it can still appear, names the reserve.
/contextshows the reserve and where it comes from. - When compaction is paused after a refused summary,
/contextshows the error code, the number of attempts, the full date and time (UTC) of the next automatic try, and that/compacttries now and may call a billed model at a cost that is not estimated. The notice in the conversation shows the full date instead of only the hour, and the pause survives a restart until its deadline. --jsonafter a subcommand (for exampletalos config list --json,talos checkpoint list --json) selects JSON output, like--jsonbefore it. Anything after--is still passed through as written.
Known limits
Section titled “Known limits”- Tested on Windows 11 x64 with Node.js 24.18 or later in the 24 line; macOS/Linux and the native installer are not certified by these checks.
- Native mouse selection was checked with automated terminal tests and by hand in Windows Terminal (drag to select, right-click and Ctrl+C to copy, Ctrl+C without a selection still offers to exit); other terminals were not checked by hand.
- Compaction against a real Ollama server was not run; the compaction path was checked with an Ollama-shaped local test server.
- Unchanged from 0.3.2: the read tool describes binary files instead of passing images/audio; MCP non-text results and image budgets across long conversations need further work; long pastes can appear expanded in queued messages and resumed conversations.
- A local provider that answers 401/403 without a key can still suggest replacing a key; the fix is not in this release.
- An answer cut off because it reached the reserve is not yet announced as cut off.
Verification
Section titled “Verification”- CLI unit suite: 2,018 tests, 2,014 pass, 4 skip, zero failures. Complete terminal acceptance: 292/292 on an otherwise idle machine (two earlier runs under heavy parallel load each had one timing failure in the test harness, not reproduced alone; they are tracked as open).
- Installed package from the release tarball: standalone install from an empty prefix, fast-turn duration, compaction cooldown after restart, mouse off by default and on by opt-in,
--jsonafter a subcommand, no outbound traffic and no writes into the package. - The bundled kernel is the same as in 0.3.2 (kernel files copied from the same kernel commit).
- These are Windows filesystem/terminal checks with local scripted providers, not live cloud-model evaluations.
Released Sep 28, 2026 · On npm
npm i -g talos-code@0.3.2, or talos update to see it.
Display settings in the terminal, clearer permission changes, and safer file reads, with conversation recovery and workspace checkpoints preserved.
/configchanges response width, notifications, mouse-wheel scrolling and exit output. Settings are private to you in the current project. Response width updates immediately; the other settings apply on the next launch.- Focus-aware completion, failure and approval notifications, with fixed messages that contain no prompts, filenames or model answers. Supported terminals also receive running/error progress indicators.
Changed
Section titled “Changed”- Entering Full access requires an explicit confirmation. Changing permission mode also updates the current session, so the next turn follows the mode shown on screen.
- Turns without mutations avoid preparing a workspace checkpoint when no extensions are present. The checkpoint still precedes writes and delegated work; projects with extensions retain the earlier preparation for compatibility.
- File reads check a bounded binary sample before decoding. Text reads stop at 1 MiB, even without line breaks or when a file grows during the read, and disclose incomplete reads at the beginning of the result. Binary sizes come from the original file. Edit and checkpoint operations retain their full reads.
- A completed turn settles its saved conversation before follow-up operations such as compaction and resume use it.
- Fragmented UTF-8 input preserves accents, CJK and emoji. Mouse-report filtering no longer alters matching sequences inside bracketed paste or leaks incomplete report prefixes into the composer.
- Command completion opens when fast typing arrives in one input chunk, preserving the whole prefix. Bracketed paste retains its separate text behavior.
- Builds refresh the bundled kernel, preventing a package from silently using a stale copy.
Known limits
Section titled “Known limits”- Tested on Windows 11 x64 with Node.js 24.18 or later in the 24 line. macOS/Linux and the native installer are not certified by these checks.
- Native desktop notification delivery still needs physical checks; automated checks intercept delivery. Other terminal applications have not been verified on their target platforms.
- The read tool returns a description for binary files, not their image/audio content. MCP non-text results and image budgets across long conversations still need further work.
- Long pastes can still appear expanded in queued messages and resumed conversations. Mouse interaction is wheel-only.
- Compaction retry cooldowns and extension startup costs still need broader stress testing.
Verification
Section titled “Verification”- CLI unit suite: 1,998 tests, 1,994 pass, 4 skip, zero failures; complete terminal acceptance 292/292. Kernel suite: 603 pass, 1 skip; 12 bounded-read tests and five additional edge-case checks pass.
- The installed 0.3.2 candidate passes the bounded-read tests and real terminal flows through reading, command completion, restart and resume. Upgrade from published 0.3.1, real write, checkpoint undo, rollback and redo pass.
- Four independent mutations of the read limit, sample, byte count and tool dispatch are detected by the tests.
- The command-input regression and the test fixture’s distinction between terminal controls and frames each detect an isolated reintroduction of the defect.
- These are Windows filesystem/terminal checks with local scripted providers, not live cloud-model evaluations. The broader backend suite retains three pre-existing documentation/test-inventory failures.
Released Sep 27, 2026 · On npm
npm i -g talos-code@0.3.1, or talos update to see it.
- A conversation no longer gets stuck after a failed turn. When a turn failed after its tools had answered (a context compaction that could not finish, for example), every later turn stopped with “This conversation no longer matches its saved context”. The conversation now goes on from what was saved, results of the tools included.
- Reading an image or any other binary file no longer pours its bytes into the conversation. The model is told the file is binary, with its type and size, and that it was not read. Before, five screenshots put megabytes of unreadable text into the context, and the compaction that followed could not succeed.
- The mouse, on by default in the full-screen view: the wheel scrolls the conversation, three rows a step. Hold Shift to select text as usual.
ui.mouse: falsein the settings turns it off. TALOS switches the mouse off when it leaves.
Known limits
Section titled “Known limits”- Tested on Windows 11 x64 only; Node.js 24 (24.18 or later in the 24 line).
- A conversation that was already stuck before this version stays stuck: start a new one.
- Clicks do nothing yet.
- A message sent while TALOS works (queued) and the messages of a resumed conversation still show a paste whole.
Verification
Section titled “Verification”- CLI unit suite: 1921 tests, 1916 pass, 4 skip, the one failure a test that read a file before its save ended (fixed). Acceptance on the built CLI in a synthetic terminal: 269/269, the mouse and a failed turn included.
Released Sep 27, 2026 · On npm
npm i -g talos-code@0.3.0, or talos update to see it.
A cleaner screen: long pastes, runs of file reads and the model’s thinking now take one line each, and a batch of display defects found by recording every screen in a synthetic terminal is fixed.
- A short welcome before the first message: the folder, the model, one example and four keys.
- The resume list names each conversation by its first message instead of its id (your own
/renamestill wins; the id stays searchable). - A one-line preview while the model thinks, with reasoning collapsed: the last sentence so far, then “Thought for N s · Ctrl+T shows”. Off with reduced motion.
Changed
Section titled “Changed”- Long pastes: over 800 characters or more than 2 line breaks, a paste shows as
[Pasted text #N +X lines](before: 20 lines or 4,096 characters). The model still receives all of it. The placeholder is one block: Backspace removes it whole, and pasting the same text again right after it expands it (“paste again to expand”). Your message in the conversation shows the placeholder, not the whole paste. - Consecutive file reads, searches and folder listings are one line — “Searched for 2 patterns, read 3 files, listed 1 folder · Ctrl+O shows”. Writes, commands and anything that failed or needs you keep their own line.
- Agents in the footer only while a subagent works, and the list follows it live; the finished ones leave it (they stay in the conversation and in Alt+A). The main line counts the turn, not the session.
- Tables are drawn with box lines; wrapped list items keep their text aligned.
- The whole screen takes the theme’s background, borders included, and dim text reads at 4.5:1 or better in every theme.
- A long command output says “… +N earlier lines” above the lines it shows, and the path of the full output has a line of its own.
- Clearer words: the permission prompt says “no rule allows or blocks this, so TALOS asks”;
/statussays “6 calls so far” and “context window unknown”; an error ends with “see talos …”.
- Windows command output no longer shows a blank line between every two lines.
- A queue or reasoning line no longer loses its row when no agent is listed.
Known limits
Section titled “Known limits”- Tested on Windows 11 x64 only; Node.js 24 (24.18 or later in the 24 line).
- A message sent while TALOS works (queued) and the messages of a resumed conversation still show a paste whole.
- After a quick search turn, “done” may show without its duration.
Verification
Section titled “Verification”- CLI unit suite: 1913 tests, 1909 pass, 4 skip, 0 fail. Acceptance on the built CLI in a synthetic terminal: 263/263.
- Every screen recorded in a synthetic terminal at 60, 100 and 120 columns, with a colour audit (WCAG contrast on the painted background) and no network traffic.
Released Sep 27, 2026 · On npm
npm i -g talos-code@0.2.2, or talos update to see it.
How TALOS compares
Section titled “How TALOS compares”Same turns for every agent, on the same machine, against a local stand-in model that answers at once (so what is measured is the agent itself, not a model): a git repository of 6,000 files, the median of 3 runs, the whole run in seconds. Lower is better.
| Turn | TALOS 0.2.0 | TALOS 0.2.2 | Pi 0.84 | OpenCode 1.18 |
|---|---|---|---|---|
| No tool (start, one answer, exit) | 2.62 | 1.13 | 1.23 | 2.69 |
| Six file reads in one answer | 2.41 | 1.10 | 1.23 | 3.34 |
| Four project searches in one answer | 14.04 | 1.32 | 1.59 | 3.61 |
| Three shell commands in one answer | 6.98 | 3.81 | 1.94 | 4.17 |
TALOS is now faster than Pi and OpenCode at starting a turn, reading and searching. Shell commands are still slower by choice: they run one at a time, each in a Windows sandbox, because the safety check of each command depends on what the previous ones did. Measured on Windows 11 with scripts/bench-harness.ts, which anyone can run again.
Changed
Section titled “Changed”- Faster turns again. The
/undosnapshot looks at the files of a folder together instead of one by one: a turn in a folder of 6,000 files went from 1.8 s to 1.25 s (1.4 s to 1.28 s in a git repository), on par with Pi. - Long sessions no longer slow down at every tool result: the context archive is written once per tool exchange instead of after every result, and is no longer read back whole at every write. At 1,350 messages, a turn with six tools spends 24 ms on it instead of 160 ms.
- A search asked in the same answer AFTER a file write could miss what that write had just changed (0.2.1: the searches of one answer started together, before the write). Only the searches before any other tool start together now.
- Stopping a turn also stops a search that is still walking the project when ripgrep is not available.
Known limits
Section titled “Known limits”- Tested on Windows 11 x64 only; Node.js 24 (24.18 or later in the 24 line).
- Shell commands run one at a time, each in its sandbox: the safety check of each command depends on what the previous ones did.
Verification
Section titled “Verification”- Hermetic bench (
scripts/bench-harness.ts, a git repository of 6,000 files, local fake provider): a turn with no tool 1.13 s (Pi 1.23, OpenCode 2.69, Codex 0.50); six reads 1.10 s (Pi 1.23, Codex 1.98, OpenCode 3.34); four searches 1.32 s (Pi 1.59, Codex 1.71, OpenCode 3.61). - CLI unit suite: 1879 tests, 1875 pass, 4 skip, 0 fail. Acceptance on the built CLI in a synthetic terminal: 263/263. The package proof (
scripts/prove-standalone.ts): 16/16 ontalos-code-0.2.2.tgz.
Released Sep 26, 2026 · On npm
npm i -g talos-code@0.2.1, or talos update to see it.
Changed
Section titled “Changed”- Faster turns in large folders. The workspace snapshot that makes
/undopossible no longer reads, rewrites and syncs every file at every turn: a file that has not changed since the last turn reuses what was stored. A turn in a plain folder of 6,000 files went from 39 s to 1.8 s, and from 2.6 s to 1.4 s in a git repository of the same size. What/undocovers is unchanged. - Faster and complete project search.
cercaruns ripgrep, shipped inside the package for your platform (no download), and each match now comes with its line:path:line:text. Four searches over 6,000 files took 9.3 s; now about 0.2 s. Before, a search stopped after reading 5,000 files and could miss matches in a bigger project. Several searches asked in the same answer run together. Without ripgrep, the previous search still works.
Known limits
Section titled “Known limits”- Tested on Windows 11 x64 only; Node.js 24 (24.18 or later in the 24 line).
- Shell commands still run one at a time, each in its sandbox; a start of about one second remains.
Verification
Section titled “Verification”- Measured on a hermetic bench (
scripts/bench-harness.ts): a local fake provider, no network, TALOS against Pi, Codex and OpenCode on the same turns. - CLI unit suite: 1876 tests, 1872 pass, 4 skip, 0 fail. Acceptance on the built CLI in a synthetic terminal: 263/263.
- The package proof (
scripts/prove-standalone.ts), 16/16 ontalos-code-0.2.1.tgz(1.76 MB); the installed package resolves its own ripgrep.
Released Sep 26, 2026 · On npm
npm i -g talos-code@0.2.0, or talos update to see it from 0.1.0.
- Watch a sub-agent live: Alt+A, then Enter on an agent, and its own transcript takes the main view as it streams, read-only. Esc goes back to your session without stopping the turn; an agent that finishes stays on screen as done. While agents work, the status line says “Alt+A to watch”.
- A guided setup on the first launch: trust this folder, then a provider (a local engine that runs comes first), its key or local engine, and a model, one window at a time with “Step N of 4”; Esc skips, and only what is missing is asked. It ends with “Ready” and the model.
/setuportalos setupruns it again. - Sign in to OpenRouter without pasting a key: choose OpenRouter, then “Sign in with OpenRouter (browser)”. TALOS opens the browser and waits on 127.0.0.1; on another machine, paste the code OpenRouter shows. Also
talos provider login openrouter(--pastefor the code). The key that comes back is tested and saved like a pasted one.
Changed
Section titled “Changed”- Forge is the default theme. A theme you chose stays yours.
- A sub-agent that needed your approval (a command, a write) used to wait forever with nothing on screen. Its approval now opens like any other and says it comes from the agent and its task; the answer goes to that agent.
- While delegated sub-agents work, the status line says how many agents are working instead of “thinking” with a running clock; any tool that runs silently without asking is shown as running.
- Changing the theme with
/themeno longer throws the conversation away. Crossing the colourlessmonotheme used to restart the whole screen and lose the session. - A turn interrupted while a tool was about to run no longer breaks the session: resuming it used to fail at every turn with
CTX_HISTORY_DIVERGED. A session already broken that way now says so in plain words and offers/fork, which continues the conversation in a new session.
Known limits
Section titled “Known limits”- Tested on Windows 11 x64 only; Node.js 24 (24.18 or later in the 24 line).
- Context compaction with a local Ollama model is not yet verified end to end.
- A local provider that answers 401/403 without needing a key can be set aside as if its key were wrong.
- The OpenRouter sign-in is tested against a stand-in for OpenRouter; the exchange with the real service follows its published contract.
Verification
Section titled “Verification”- CLI unit suite on the release tree: 1870 tests, 1866 pass, 4 skip, 0 fail. Acceptance on the built CLI in a synthetic terminal: 263/263.
- The package proof (
scripts/prove-standalone.ts), 16/16 ontalos-code-0.2.0.tgz(1.76 MB, 407 files): installed into an empty prefix outside the repository, hermetic profile, fake provider on 127.0.0.1; every loaded module resolved inside the package; nothing written inside the package; no stale build output; no outbound request.
Released Sep 25, 2026 · On npm
The first public release: npm i -g talos-code, then talos.
- An interactive terminal screen and a headless mode (
talos -p,--json,--output-format stream-json) on the TALOS kernel, the same one the desktop runs, carried inside the package: it reads no file of a TALOS checkout. - Providers from the TALOS registry (OpenAI, Anthropic, Google Gemini, DeepSeek, OpenRouter, Mistral, Groq, xAI and more) and local engines with no key (Ollama, LM Studio, llama.cpp). Keys are typed in hidden input and kept in the operating system’s credential store; a key already in the environment is used only after you agree once.
- Per-tool permissions (allow, ask, deny) with six modes, project trust for hooks, MCP servers, plugins and commands.
/undorestores the files a turn changed, from checkpoints kept outside the repository and outside Git.- Sessions:
/resume,/fork, export and import (an imported session never runs anything by itself), prompt history. - Context: with a known window of 64k tokens or more, compaction at half of it, said on screen; after a summary the model did not write properly, automatic compaction pauses (60 s, 5 min, 15 min) and says so, while
/compactruns at once. /themewith ten accents,/helpby group,/status,/retry,/copy,@file completion that respects.gitignore,Ctrl+Rhistory search.talos updateasks the npm registry whether a newer version exists and prints the npm command; it changes nothing.talos doctorand a redactedtalos diagnostic bundle. No telemetry.
Known limits
Section titled “Known limits”- Tested on Windows 11 x64 only; Node.js 24 (24.18 or later in the 24 line).
- Context compaction with a local Ollama model is not yet verified end to end.
- A local provider that answers 401/403 without needing a key can be set aside as if its key were wrong.
Verification
Section titled “Verification”- CLI unit suite on the released tree: 1839 tests, 1835 pass, 4 skip, 0 fail. Acceptance on the built CLI in a synthetic terminal: 246/247 on the aligned kernel (the one red is a known idle-frame flake).
- The package proof (
scripts/prove-standalone.ts), 16/16 on the tarball itself: installed into an empty prefix outside the repository, hermetic profile, fake provider on 127.0.0.1; every loaded module resolved inside the package; nothing written inside the package; no stale build output. - Installed from the registry after publication:
talos --versionanswered0.1.0,talos update --checkanswered up to date.