The Archive · CLI · Guides
Allow, ask or deny a tool
Write permission rules for the TALOS CLI, check what a rule would decide before you rely on it, and answer when TALOS asks.
Checked on CLI 0.3.3
A newer version is out (CLI 0.5.2): some details may differ.
How modes and rules fit together is explained in Permissions. Here is how to write the rules.
When TALOS asks
Section titled “When TALOS asks”The approval card offers, by number:
- Allow once;
- Allow for this session;
- Always allow — an
allowrule is written for that operation; - Deny, and the turn goes on;
- Always deny — a
denyrule is written (in the full review, opened withv).
Esc denies and stops the turn.
Write a rule
Section titled “Write a rule”Rules go in permissions.allow, permissions.ask or permissions.deny, one Tool(pattern) each:
talos config set permissions.allow '["Bash(npm test)", "Bash(npm run:*)", "Edit(./src/**)"]' --scope projecttalos config set permissions.deny '["Bash(rm:*)"]' --scope project-userproject— shared with whoever uses the project;project-user— yours, for this project, kept outside it;user— yours, for every project.
Rules from every scope are merged. The pattern of each tool — commands matched word by word, paths relative to the project — is on Rules.
Check a rule before you rely on it
Section titled “Check a rule before you rely on it”talos config permissions dry-run --tool Bash --command "npm run build"It says which rule would allow, ask or deny that action, without running it. talos config origins shows which
file each value comes from.