The Archive · CLI reference
Permissions
How TALOS CLI decides whether an action runs, asks or is denied: modes, rules and their order.
Reference for TALOS CLI 0.3.3
TALOS CLI 0.5.2 is out; this page still describes 0.3.3 and updates with the next build.
Choose a mode with --permission-mode, the permissionMode setting, or in the interactive screen.
defaultManualdefault- Asks before every action no rule allows.
acceptEditsAccept edits- Also allows, without asking, file edits inside the project and simple file commands (
mkdir,touch,rm,rmdir,cp,mv) — never in protected folders. planPlan- Read only: writing files, editing, hooks, plugins and shell commands that change anything are denied.
autoAuto- A classifier decides for actions no rule covers: it allows, denies, or lets TALOS ask you. Never in protected folders.
dontAskDon't ask- Never asks: whatever would need your approval is denied.
bypassPermissionsFull access- Allows every action that would otherwise ask, when no rule names it.
Warning. Use it only in a disposable environment you can restore. Deny and ask rules, and the block on writing outside the project, still apply.
How a decision is made
Section titled “How a decision is made”- A write or an edit outside the project folder is denied.
- A
denyrule that matches denies. - In
planmode, writing, editing, hooks, plugins and shell commands that change anything are denied. - An action you allowed for this session is allowed.
- An
allowrule that matches allows. - An
askrule that matches always asks: no mode skips it. - Otherwise the mode decides:
acceptEdits,autoandbypassPermissionsmay allow (see Modes). - If nothing allowed it: in
dontAskmode, or when nothing can be asked (a headless run), it is denied. Otherwise TALOS asks you. - When TALOS asks, you can allow it once, for the session, or always (an
allowrule is written), or always deny it (adenyrule is written).
A rule is written Tool(pattern) on one line, e.g. Bash(npm test) or Edit(./src/**). It goes in permissions.allow, permissions.ask or permissions.deny of a settings file. A rule that cannot be read stops TALOS from starting, and says which one.
Bash: the pattern is a command, matched word by word. Bash(npm test) matches exactly npm test; Bash(npm run:*) matches every command that starts with npm run; Bash(*) matches any command. A command with &, |, ;, <, > or parentheses never matches a rule.
Read, Write, Edit: the pattern is a path relative to the project. * and ** match any characters (not spaces); ./** is anything inside the project; * alone is any path. A pattern that starts with . never matches a path outside the project.
Mcp: the pattern is server:operation, e.g. Mcp(github:*). TalosService: operation or resource:operation. The other tools match their operation or resource.
| Tool | What a rule on it covers |
|---|---|
Read | Reading a file. Pattern: a path. |
Write | Creating or overwriting a file. Pattern: a path. |
Edit | Changing a file. Pattern: a path. |
Bash | A shell command. Pattern: the command, or its first words followed by :*. |
WebFetch | Fetching a web page. Pattern: the address. |
Mcp | A tool of an MCP server. Pattern: server:operation. |
Hook | Running a hook. Pattern: the hook. |
Plugin | Running a plugin. Pattern: the plugin. |
TalosService | A TALOS service (memory, notes, tasks…). Pattern: operation or resource:operation. |
Try a rule without running anything: talos config permissions dry-run --tool Bash --command "npm test".
Protected folders
Section titled “Protected folders”The acceptEdits and auto modes never allow changes in these folders of the project: they always ask.
.git/.talos-cli/.github/.vscode/.idea/.husky/
File commands in acceptEdits
Section titled “File commands in acceptEdits”In acceptEdits mode these commands run without asking, with only these options, on paths inside the project:
| Command | Options it may carry |
|---|---|
mkdir | -p -v |
touch | -a -m -c |
rm | -r -R -f -rf -fr -d |
rmdir | -p |
cp | -r -R -f -n -p |
mv | -f -n |