The Archive · Desktop · Guides
Add skills, MCP servers, plugins and hooks
Extend TALOS Desktop from your project, read what each extension declares, and trust it only after.
Checked on Desktop 0.1.19
A newer version is out (Desktop 0.1.25): some details may differ.
A project can add four kinds of things to TALOS, each declared in a precise place of the project’s folder:
| Kind | Adds | Declared in |
|---|---|---|
| Skill | Instructions the agent loads when needed | the .talos/skills/ folder |
| MCP server | Tools provided by an external program | the .talos/mcp.json file |
| Plugin | Tools and hooks together | the .talos/plugins/ folder |
| Hook | A command that runs at a precise moment | the .talos/hooks.json file |
The older names — .harness-ui-skills/, .harness-ui-mcp.json, .harness-ui-plugins/, .harness-ui-hooks.json at the
root of the project — are still read, after the ones above.
A hook runs before a tool is used, after it, at the start of a session, or at its end. Every file, with its format, is on Project files; hooks in full are on Hooks.
Add one
Section titled “Add one”- Put the files in the project, in the places above.
- Open the inventory of extensions — Settings → Account, Doctor and backup lists Agents, Hooks, Skills, Plugins and MCP — and refresh it.
- Read what each one declares. For hooks, MCP servers and plugins, open the file in the project: the inventory of a hook says when it runs, not the command it will run, on purpose.
- Only then, mark it as trusted.
Being declared does not make an extension active: until you trust it, it waits for your trust. Skills are the exception — they are only instructions, and are available at once. A hook’s trust is recorded outside the project, with a fingerprint of its command: if the command changes, it must be trusted again. A project you clone cannot trust its own hooks.
For MCP servers, the inventory shows what is declared, not whether it answers.
If something goes wrong
Section titled “If something goes wrong”- An extension does not appear — the file or folder is not in the right place, or not in the folder of the open session.
- Trust not observed — the state was not read: refresh the inventory.
- A hook does not run — check that it is trusted, and that its event is the one you think.