Talos (talos-kernel/Talos) is an MCP server listed on the M8ven Trust Index. It scores 45 out of 100, grade D. No publisher has claimed this listing.

D
Warning
45/100

Talos

Self-hosted AI agent for terminal and Telegram, with Claude/Codex workers, live activity and a deterministic permission kernel.

Warning. Serious findings were identified. Review the full report before connecting. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.

How we verified

⚡ Live Monitored: not connected

Verified is a snapshot. Live keeps it current, and builds your track record.

⚡ Connect GitHub → continuous verification on every pushwhy connect →

Who stands behind it

talos-kernel

Source: github_repo_search

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →

Install from

The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.

// key findings
🚨
Reads files from sensitive locations
Touches: {os.path.realpath(HOME)}/.ssh/id_ed25519, /etc/talos/model.env, /etc/talos-computer-agent.env
🔐
You'll be asked for 2 credentials: TALOS_AGENT_CONSULT_TOKEN, TELEGRAM_BOT_TOKEN
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// environment variables
To run this server yourself, you supply these values. They go in your own MCP client configuration and stay on your machine. The secret label means the value is sensitive, not that the server mishandles it.
configTALOS_DISTILL
configTALOS_DEBUG
configTALOS_RELEASE
configTALOS_REMOTE_HOSTS
configTALOS_COMPUTER_AUTOAPPROVE
configTALOS_COMPUTER_SOCKET
configTALOS_COMPUTER_DESKTOP
configTALOS_MODEL_WORKER_ENV
🔐 secretTALOS_AGENT_CONSULT_TOKEN
🔐 secretTELEGRAM_BOT_TOKEN
configTALOS_SANDBOX_ALLOW_UNCONFINEDuntil the operator overrides it on purpose (=1).
configTALOS_CLAUDE_WORKER_SOCKET
configTALOS_APP_SIGN_IDENTITY
configHERMES_HOME
configTALOS_SANDBOX
configSSL_CERT_FILE
configREQUESTS_CA_BUNDLE
configTALOS_WEB_ALLOW_HTTP
configTALOS_WEB_ALLOWED_ADDRESSESare not settings but policy:
configTALOS_CLAUDE_WORKER_BIN
configTALOS_SECRETS_ENVuser of the machine. And TALOS_ALLOWED_PRINCIPALS, ,
configTALOS_SHELL_NEEDS_HUMAN
configTELEGRAM_BOT_USERNAME
configTALOS_ALLOWED_PRINCIPALSuser of the machine. And , TALOS_SECRETS_ENV,
configTALOS_ALLOWED_USER_IDS
configTALOS_SKILLS_DIRS
configTALOS_VAULT_DIR
configTALOS_QMD_BIN
configTALOS_HERMES_BIN
configTALOS_HERMES_PROVIDER_CATALOG
configTALOS_HERMES_MODELS
configTALOS_MODEL_PROVIDER
configTALOS_MODEL
configTALOS_MODEL_WORKER
configTALOS_STATUS_STYLEWith =expressive, Telegram keeps one live activity card with
configTALOS_OWNER_LABEL
configTALOS_CLAUDE_WORKER_ROOT
configTALOS_COMPUTER_ROOT
configTALOS_REMOTE_READONLY_AUTOAPPROVE
configTALOS_CLAUDE_BIN
configTALOS_TIDY_WORK_TRAIL
configTERM
configTALOS_PREFIX
configTALOS_BASE
configDEMO_PROVIDER
configDEMO_MODEL
configTALOS_COMPUTER_OWNER_SHA256
configTALOS_COMPUTER_VIEW_URL
configTALOS_COMPUTER_VIEW_KEY_FILE
// quality suggestions

Tools detected

No tools extracted — insufficient content to verify at Tier 2

No access to sensitive paths

Reads sensitive paths: {os.path.realpath(HOME)}/.ssh/id_ed25519, /etc/talos/model.env, /etc/talos-computer-agent.env

Remove reads of sensitive system paths. If you genuinely need them, document why in the README.

Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.

// full audit trail
The findings above are the summary. The full trail, every check we ran, each deduction, the network hosts observed and the dependency advisories, goes to verified publishers, along with an alert whenever a new one lands. Verified publishers can also review each finding and dispute it in one click. Publisher corrections have sharpened several of our checks this month, because the maintainer knows the codebase better than any scanner.
// improvement guidance — verified publishers only
We have 1 concrete improvement we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Verified](https://m8ven.ai/badge/mcp/talos-kernel/talos?variant=verified)](https://m8ven.ai/mcp/talos-kernel/talos)
Shows verification status without the grade. Want the grade badge instead? Remove ?variant=verified from the URL.
commit: 1c2b5432598bbb4f8bd89d63c5895c327ba923c2
code hash: 764274348237a47b119257442a85b6d6b0605585ba81d415114afb52df279620
view raw JSON →
Check MCPs from inside your assistant
Tool Check · MCP

Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.

https://m8ven.ai/api/mcp/tool-check
check_toolsearch_toolscompare_toolsrecommend_alternativescheck_publisherreport_concern
How to add it →Free · no account needed · works in any MCP client