The Archive · CLI · Concepts

Extensions

MCP servers, hooks, plugins, your own commands and forged tools — and why none of them runs before you trust it.

Checked on CLI 0.3.3

A newer version is out (CLI 0.5.2): some details may differ.

A project can teach TALOS new things. Each of them is code or instructions that came with the project, so each one is trusted explicitly before it runs — first the project, then the extension itself.

Extension What it is Manage it with
MCP server A program that offers tools over the Model Context Protocol. talos mcp · /mcp
Hook A command of yours that runs when something happens in a session. talos hook · /hooks
Plugin A package of commands, skills, hooks or MCP servers. talos plugin · /plugins
Custom command A Markdown file whose text becomes a prompt, with arguments {{arg1}}, {{arg2}}… In the interactive screen it is a slash command. talos command
Forged tool A tool TALOS built during a session, as a declarative package: validated, scanned and simulated before use. talos forge · /forge
  1. The project. talos project trust trusts the project and the current snapshot of its executable files; talos project status shows what is trusted and why. When those files change, the trust no longer covers them.
  2. The extension. Each MCP server, hook and plugin is trusted on its own, and can be untrusted at any time.

A hook or a plugin can also be quarantined: it is denied until released, and release does not restore trust. Installing a plugin does not make it run either: the project’s trust must cover the new package first. Every action an extension takes still goes through your permissions.

talos init prepares a project for TALOS: it creates .talos-cli/ with commands/, extensions/ and an empty config.json. See Add MCP servers, hooks and commands.

Type to search the guides.