Skip to content

Add first-class browser computer use with live session viewing #17

Description

@ElbertePlinio

Goal

Make PickLab a production-ready, provider-neutral computer-use runtime: agents can launch an isolated headed browser, combine visual and semantic control, watch the session live, inspect replayable evidence, and hand control to a human without exposing the real desktop.

Product decisions

  • Xvfb remains the only display server in v1. Xephyr is out.
  • picklab watch opens a host-side VNC viewer against the isolated display. Observation is server-enforced read-only.
  • A browser session is one record owning private Xvfb and Chrome legs.
  • Chrome uses an ephemeral profile, scrubbed environment, loopback CDP with port 0, and DevToolsActivePort readback.
  • The official Chrome DevTools MCP is reached through a framing-aware PickLab relay, not reimplemented.
  • Evidence is append-only and renders as a static HTML filmstrip.
  • Human control uses an atomic lease plus short-lived agent permits. No control state is stored authoritatively in session JSON.
  • Android viewing/takeover, persistent browser profiles, Firefox/WebKit, uid sandboxing, and remote multi-user viewing are out of scope for v1.
  • No feature flag: each PR preserves current defaults and is independently releasable.

Security posture

Browser/CDP processes still run as the invoking user. V1 is for authorized, trusted development and QA — not hostile-page isolation. VNC and CDP bind loopback only, browser profiles are ephemeral, Chrome receives a scrubbed environment, process groups are verified and killed before profile deletion, and secrets/capability URLs are excluded from persisted diagnostics. SECURITY.md must document the residual same-UID/local-process risk before #18 closes.

PR plan

Dependency order

PR 1 -> PR 3 --------------------------┐
PR 2 -> PR 5 -> PR 6 -> PR 7 ---------+-> PR 8 -> PR 9
PR 4 ----------------------------------┘

PR 1 and PR 2 may proceed independently. PR 4 is also independent, but must land before the final computer-use claim. Shared CLI/MCP session wiring is serialized to keep reviews clean.

Production acceptance

  • A coding agent configures PickLab once and can recreate browser sessions without MCP config edits.
  • Visual desktop tools and semantic DevTools tools operate on the same isolated headed Chrome.
  • picklab watch can attach to an already-running session; closing the viewer never stops or corrupts it.
  • Normal viewing is read-only. watch --control prevents PickLab-managed agent input after human acquisition completes.
  • Sensitive typed values, cookies, headers, bodies, query tokens, JWTs, OTPs, and CDP websocket capabilities never enter persisted evidence.
  • Screenshot pixels are explicitly not claimed to be redactable; automatic capture is suppressed around sensitive inputs.
  • Two concurrent browser sessions have distinct displays, profiles, and CDP ports.
  • Destroy/reap leaves no Chrome process-group members or ephemeral profile data.
  • Hosted CI passes typecheck, tests, coverage, and build without silent prerequisite skips.
  • Before closing: attach one real watch recording and one pause → control → return → resume recording.

Current status: In progress
Next: PR 1 and PR 2 foundation slices.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions