Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 2 additions & 1 deletion CHANGELOG.md
Original file line number Diff line number Diff line change
@@ -1,8 +1,9 @@
# Changelog

## Unreleased
- Made `browser_handoff` a nonblocking coordination marker. It persists the active handoff and completion condition, focuses the declared tab, and returns immediately without pausing browser observations or mutations; explicit **Pause agents** remains available when the page must stay unobservable.
- Replaced blocking human handoffs with task-owned attention notices. Agents can request, inspect, resolve, or dismiss a notice without popup acknowledgement; open notices do not block ordinary commands or task cleanup. Legacy handoffs migrate without restoring a lock, and stale notice IDs cannot clear newer requests. Explicit Pause, ownership, sensitive-field restrictions, and configured Commit review remain independent.
- Enabled YOLO mode for new and legacy default state so recognizable consequential controls execute in the original `browser_act` call. Turning YOLO mode off restores staged Commit review. Task ownership, origin policy, revision checks, credential isolation, and all other Standard boundaries remain enforced.
- Preserved existing permissive-mode settings and managed 1Password defaults during the notice cutover, including GUI-host executable discovery and legacy created-tab provenance sanitization.
- Replaced the Chrome Bridge v1 runtime with the AgentTab 2.0 release candidate: a Rust production host over OS-native local IPC, nine task-scoped Standard methods, explicit resumable capabilities, a developer-only tenth method, TypeScript and Python SDKs, MCP and OMP adapters, a transactional installer, and a minimal extension. Consequential controls now use a two-party Commit flow: `browser_act` stages an exact effect, the popup approves the durable review record without executing it, and the requesting task must consume its private one-use token through `browser_commit`.
- Added explicit `browser_finish` lifecycle finalization across Core RPC, the extension, TypeScript and Python SDKs, CLI, MCP, OMP, and Pi. Automatic cleanup tracks tab provenance, closes task-created tabs, retains adopted tabs, ungroups retained tabs, and releases ownership; popup policy can require confirmation or retain all tabs, while active handoff, Commit review, and in-flight work defer cleanup without destroying resumability.
- Fixed OMP adapter compatibility with providers that reject top-level union tool schemas. `browser_open` and `browser_snapshot` now expose provider-compatible object schemas while retaining strict runtime validation for their mode-specific parameters.
Expand Down
10 changes: 5 additions & 5 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@

> Give an agent a tab, not the keys to your browser.

AgentTab lets an agent work in your existing signed-in Chrome profile without giving it unrestricted control of the profile. Each connection receives a task-owned browser workspace. The agent can create tabs, inspect and act in those tabs, wait for page state, and ask for help. The built-in 1Password broker is available by default and can fill a matching login or one-time code without exposing its value to the agent; passkeys, security keys, CAPTCHA, payment secrets, account recovery, and unsupported verification remain **Your Turn**. Recognizable consequential actions execute directly by default, while the popup can enable a staged **Commit** review when desired.
AgentTab lets an agent work in your existing signed-in Chrome profile without giving it unrestricted control of the profile. Each connection receives a task-owned browser workspace. The agent can create tabs, inspect and act in those tabs, wait for page state, and ask for help. The built-in 1Password broker is available by default and can fill a matching login or one-time code without exposing its value to the agent; passkeys, security keys, CAPTCHA, payment secrets, account recovery, and unsupported verification raise a **Needs your attention** notice. Recognizable consequential actions execute directly by default; turning YOLO mode off in the popup stages them for **Commit** review instead.

## Release status

Expand All @@ -24,7 +24,7 @@ The command has no path, token, or shell-specific argument and is suitable for P

1. An agent calls `browser_open` with `mode: "create"`. AgentTab creates a background tab for that task and returns its task, tab, window, page-revision, and automation-route identifiers. `placement: "new_window"` may create the task's first tab in a separate unfocused normal window.
2. On a normal web origin, the agent calls `browser_snapshot`, works from revisioned accessibility references, then calls `browser_act` with the expected page revision. It cannot act on unrelated tabs.
3. On an ordinary sign-in page with at most three origin-matching Login items, the agent can request a short-lived opaque token and ask the host to fill named field refs through the local `op` command. Credential values travel only from `op` to the host and extension, never through Core RPC or the adapter. Owner-only policy can disable or constrain this broker. Every other human-only input uses `browser_handoff`, which focuses that tab and records a durable completion condition while browser automation remains available.
3. On an ordinary sign-in page with at most three origin-matching Login items, the agent can request a short-lived opaque token and ask the host to fill named field refs through the local `op` command. Credential values travel only from `op` to the host and extension, never through Core RPC or the adapter. Owner-only policy can disable or constrain this broker. Every other human-only input uses `browser_handoff`, which posts a **Needs your attention** notice for that tab, tells the user in chat, and later verifies the page itself before resolving or dismissing the notice. Nothing pauses and no tab is focused automatically.
4. Recognized send, publish, purchase, delete, upload, authorization, and permission-grant controls execute in the original `browser_act` call by default. Turn off YOLO mode in the popup to require Commit review instead. In review mode, AgentTab stages the control, shows its effect in the popup, requires human approval, and then accepts the one-use token through `browser_commit`.
5. The task can list only its own tabs with `browser_tabs`. A separate client gets a separate task unless it proves its durable resume capability.
6. When browser work is complete, the agent calls `browser_finish`. Automatic cleanup closes tabs created by the task, preserves tabs adopted from the user's existing browser state, ungroups retained tabs, and releases task ownership. The popup setting can instead require confirmation or retain every tab.
Expand All @@ -36,7 +36,7 @@ Commit is a two-party, best-effort semantic barrier, not proof that a page has n
## Trust contract

- **Task ownership is an execution and coordination boundary, not profile isolation.** AgentTab can use the signed-in session in the browser profile, but Standard mode does not expose raw cookies, storage, passwords, arbitrary JavaScript, raw CDP, coordinate actions, network interception, or a generic browser-global mutation API. Its one window-level operation creates an unfocused normal window for the first tab of an otherwise empty task.
- **Your Turn is the only routine focus transition.** Routine task work stays in task-owned tabs. Handoff focuses the declared tab and records a durable completion condition without globally pausing browser work. This permissive default does not guarantee an observation blackout while the user types; prefer `browser_credentials` for ordinary sign-in fields because its values never enter AgentTab RPC or audit data.
- **Attention requests never take over.** Routine task work stays in task-owned tabs, and a handoff request never focuses a tab or pauses work; the popup's Open tab is the only routine focus transition and requires the user's click. Human-only input stays out of agent requests because the human types it directly in Chrome.
- **Consequential actions run directly by default; Commit review is available.** YOLO mode skips the staging step but not task ownership, origin policy, expected page revisions, restricted-origin routing, credential isolation, or action validation. Turning YOLO mode off binds each staged action to its task, tab, page revision, element fingerprint, effect, and short expiry. Popup approval records consent but does not execute it; the agent must call `browser_commit`.
- **Local by default.** Policy, task state, audit records, and IPC stay on the machine. AgentTab has no telemetry. See [Telemetry](docs/telemetry.md) and [Security](docs/security.md).

Expand All @@ -51,7 +51,7 @@ Standard mode exposes exactly nine tools:
| `browser_act` | Run typed actions against one task tab and expected page revision. Restricted-origin task tabs retain only navigation, history, reload, and close actions. |
| `browser_wait` | Wait for load, URL, text, selector, network-idle, or task-attributed download conditions supported by the tab's route. |
| `browser_tabs` | List only tabs owned by the current task, including each tab's automation route. |
| `browser_handoff` | Give the user control for human-only input. |
| `browser_handoff` | Post a non-blocking attention notice asking the user to complete human-only input, then verify the page and resolve or dismiss it by notice ID. |
| `browser_commit` | Execute one staged consequential action. |
| `browser_credentials` | Prepare and fill an origin-matching 1Password login through opaque, short-lived host tokens. Available by default when the local `op` CLI is usable; owner-only policy can disable or constrain it. |
| `browser_finish` | Finish the task, apply its cleanup policy, return closed and retained tab receipts, and release ownership. |
Expand Down Expand Up @@ -82,7 +82,7 @@ flowchart LR
D --> E[Chrome Native Messaging]
E --> F[AgentTab extension]
F --> G[Task-owned tabs in signed-in Chrome]
G -. Your Turn .-> H[Human]
G -. Needs your attention .-> H[Human]
```

The extension maintains the Native Messaging relationship with the one Rust host. Local adapters use per-user IPC: a user-owned Unix socket on macOS and Linux, or a current-user named pipe on Windows. Standard mode has no port, bearer token, or manual JSON protocol. The separate `agenttab proxy` command is an advanced, loopback-only bridge that deliberately requires a local token file. It is not part of normal setup. [Commands](docs/commands.md) documents its limits.
Expand Down
14 changes: 7 additions & 7 deletions docs/adr/0001-agenttab-runtime.md
Original file line number Diff line number Diff line change
Expand Up @@ -24,15 +24,15 @@ The default experience uses the user's existing Chrome profile and creates a tas

A task workspace is visible in Chrome. Task-owned tabs are grouped for display, but the group is not an authorization boundary.

### Your Turn
### Attention notices

**Your Turn** is the human-only input boundary. AgentTab MUST hand control to the user for passkeys, security keys, CAPTCHA, payment secrets, account recovery, unsupported verification, and any credential workflow that returns `needs_user`. The managed 1Password broker is available by default and MAY fill an origin-matching Login item through the private host-to-extension path, but MUST NOT expose the value to an agent or submit the form. Owner-only policy MAY disable or constrain the broker.
**Needs your attention** is the human-only input boundary. AgentTab MUST route passkeys, security keys, CAPTCHA, payment secrets, account recovery, unsupported verification, and any credential workflow that returns `needs_user` to an advisory attention notice. The managed 1Password broker is available by default and MAY fill an origin-matching Login item through the private host-to-extension path, but MUST NOT expose the value to an agent or submit the form. Owner-only policy MAY disable or constrain the broker.

An active handoff MUST be a durable coordination marker, not an implicit automation pause. AgentTab MUST persist the handoff and completion condition before focusing the declared tab, then keep browser requests eligible. Product and security copy MUST state that handoff does not guarantee an observation blackout and MUST direct ordinary username, password, and one-time-code entry through `browser_credentials`. Explicit **Pause agents** remains the owner-controlled confidentiality boundary.
*Amended 2026-09-07:* Notices are non-blocking display metadata. A request MUST NOT pause the scheduler, gate command admission, focus a tab, activate a window, or open the popup; no global observation blackout or host handoff admission state exists. The agent asks the user in chat, the user reports back, and the agent MUST verify the page itself before resolving or dismissing the notice by ID. AgentTab MUST NOT capture human keystrokes, and no tool result may report the user's work as completed on creation. Only the user's explicit popup Open tab action may focus the noticed tab.

### Commit

**Commit** is a best-effort semantic review barrier for recognizable consequential controls, including send, publish, purchase, delete, upload, authorization, and permission grants.
**Commit** is an optional, best-effort semantic review barrier for recognizable consequential controls, including send, publish, purchase, delete, upload, authorization, and permission grants.

Every Standard-mode mutation MUST pass through one extension-side `prepare -> classify -> revalidate -> execute` choke point. YOLO mode is enabled by default, so recognizable consequential actions execute in the original mutation. When the user turns YOLO mode off, a recognizable consequential action is staged before any side effect. Its token is bound to the task, tab, effect class, exact element fingerprint, document revision, event, preview, and a five-minute expiry. The extension popup MUST send only an opaque review handle. Human approval MUST durably mark the corresponding stage approved without consuming it or dispatching the browser action. Only a later agent `browser_commit` carrying the private staged token may consume and execute the approved stage. Execution MUST reject an unapproved, changed, expired, foreign, or used stage, revalidate the target, and dispatch at most once.

Expand Down Expand Up @@ -92,9 +92,9 @@ MCP, OMP, CLI, TypeScript, and Python are adapters over Core RPC. They are not a
8. `browser_credentials`
9. `browser_finish`

`browser_credentials` is disabled by managed policy unless explicitly enabled. It MUST derive the page origin and task ownership in the host, enforce a candidate and attempt limit no greater than three, use one-use short-lived tokens, and keep credential values out of Core RPC, adapters, responses, and audit output.
`browser_credentials` is enabled by default. Managed policy MAY disable or constrain it. It MUST derive the page origin and task ownership in the host, enforce a candidate and attempt limit no greater than three, use one-use short-lived tokens, and keep credential values out of Core RPC, adapters, responses, and audit output.

`browser_finish` applies the task's cleanup policy, closes task-created tabs unless retained, preserves adopted tabs by default, ungroups retained tabs, and releases task ownership. Active handoff, staged Commit review, or another in-flight task operation MUST defer finalization rather than destroy resumability.
`browser_finish` applies the task's cleanup policy, closes task-created tabs unless retained, preserves adopted tabs by default, ungroups retained tabs, and releases task ownership while clearing that task's open notices. Staged Commit review or another in-flight task operation MUST defer finalization rather than destroy resumability; an open attention notice MUST NOT defer it.

`browser_developer` is the tenth tool and is absent unless Developer mode is enabled.

Expand All @@ -116,7 +116,7 @@ Ownership can be granted only by:

Adoption MUST be visible. It groups the active tab and shows a brief non-blocking indicator. If grouping fails, creation or adoption rolls back with `outcome: "not_started"`. AgentTab MUST NOT retain invisible ownership with `groupId: null`.

Dedicated-window eligibility MUST be derived from the persisted task record, never from a caller-supplied ownership claim. `placement: "new_window"` MUST fail after the task owns a tab, MUST reject foreground creation, and MUST roll back the created tab if visible grouping fails. Standard mode MUST NOT expose generic focus, resize, move, state-change, or close-window operations. `browser_handoff` remains the sole normal focus transition.
Dedicated-window eligibility MUST be derived from the persisted task record, never from a caller-supplied ownership claim. `placement: "new_window"` MUST fail after the task owns a tab, MUST reject foreground creation, and MUST roll back the created tab if visible grouping fails. Standard mode MUST NOT expose generic focus, resize, move, state-change, or close-window operations. No routine operation focuses a tab; the popup's explicit Open tab action on an attention notice is the sole normal focus transition.

Tab groups are display-only. Manual grouping never grants ownership. Ungrouping or moving a tab out of its task group immediately revokes ownership, cancels queued mutations, and notifies the host.

Expand Down
2 changes: 1 addition & 1 deletion docs/benchmarks.md
Original file line number Diff line number Diff line change
Expand Up @@ -27,7 +27,7 @@ When comparing another surface, run the same scenario, user-visible success crit

Do not convert security barriers into speed-only scores. If measuring Commit, record classification result, stage creation, human review delay as a separate interval, revalidation outcome, and execution or refusal. Never Commit a real consequential action only to collect a timing number.

If measuring handoff, record only safe lifecycle timestamps such as request accepted, marker active, completion acknowledged, and marker cleared. Do not record keys, secrets, page contents, screenshots, or human input.
If measuring handoff, record only safe notice lifecycle timestamps such as request accepted, notice opened, reminder expiry, and resolve or dismiss observed. Do not record keys, secrets, page contents, screenshots, or human input.

## Publishing a result

Expand Down
2 changes: 1 addition & 1 deletion docs/commands.md
Original file line number Diff line number Diff line change
Expand Up @@ -55,7 +55,7 @@ The current source contains the stable Ed25519 verification public key, but no m
agenttab status
```

Connects to local AgentTab IPC and prints the Core `agenttab.status` result as JSON. The status response reports the host lifecycle state, protocol version, whether a handoff is active, and the current connection's task identifier when one exists.
Connects to local AgentTab IPC and prints the Core `agenttab.status` result as JSON. The status response reports the host lifecycle state, protocol version, and the current connection's task identifier when one exists.

Use this only after the extension and native host are installed. It does not start a browser, create a task, use a port, or authenticate with a token.

Expand Down
Loading
Loading