
Rocuronium
glass.kagerouv1.3.0更新于 Oct 6, 2026
Drive macOS apps without taking the cursor: read, click, type, scroll, each with evidence.
概览
让助手在不占用用户光标的情况下观察并操作 macOS 应用:读取文本、点击、输入、滚动、拖拽。
- 功能
- 一个菜单栏守护进程加命令行工具,把 macOS 控制动作以同名同参数的 MCP 工具暴露出来。观察类工具包括 status、apps、windows、find、read、wait、screenshot 和 activity;操作类工具包括 type、click、key、shortcut、menu、scroll、launch 和 activate;光标类工具为 move 和 drag;plan 可执行带守卫的多步流程;display 和 park 使用虚拟显示器做隔离。多数动作通过辅助功能接口和按进程投递的事件完成,每次都会返回 confirmed、noEffect 或 unverifiable 的判定。
- 适用场景
- 当助手需要在用户自己的机器上操作原生 macOS 应用时值得安装,例如读取应用文本、点击按钮、输入内容或执行多步界面流程,同时用户可以继续自己的工作。它仅支持 macOS 桌面环境,不适用于无头服务器或非 Mac 环境。
- 运行要求
- 需要 Apple 芯片上的 macOS 26.5 或更高版本,以已签名并公证的应用或通过 Homebrew 安装。守护进程需要在系统设置中授予“辅助功能”(必需)和“屏幕录制”(用于截图和 OCR)权限。MCP 服务器通过 stdio 在本地运行;未声明任何账号、API 密钥或环境变量。
安装
在 SourceWeft 中
- 打开 控制台中的 Rocuronium,将其添加到工作区。
- 为需要使用其工具的对话启用该服务。
Desktop only,通过 STDIO。 STDIO 服务会启动本地进程,因此需要 SourceWeft 桌面宿主。
其他 MCP 客户端
参照 仓库 中的启动说明。
README
rocuronium
Drive this Mac without taking the cursor.
[Download Rocuronium for Mac]
A signed, notarized disk image · free and open source (MIT)
A menu bar daemon that lets an AI agent see and operate macOS — read text, click buttons, type, scroll, drag, draw — while the human keeps their cursor, their focus, and a kill switch. Every action returns evidence of what observably happened, because accessibility APIs routinely lie about success.
[The presence overlay while an agent asks to move the cursor: the jellyfish escort, the approve/decline prompt answered by holding Y or N, and the bezel narrating the action with the take-over shortcut]A cursor-taking action while someone is at the machine: the jellyfish marks where the agent is, the prompt waits for a one-second hold on Y or N, and the bezel narrates the action with the shortcut that halts everything.
What makes it different
Ghost input. Most actions are delivered through accessibility and per-process posted events — no cursor movement, no focus change, invisible to the person at the keyboard. The agent works beside you, not instead of you.
Evidence, not return codes. Every action is verified: text is read back after writing,
pixels are compared before and after, window counts are checked, process exits are
detected. The reply says confirmed, noEffect, or unverifiable — and noEffect
(the API said "success" but nothing changed) is the most important one.
The human is never locked out. Cursor-taking actions show a presence overlay — a jellyfish escorting the cursor, a bezel narrating what's happening. Touch the mouse and the gesture yields. Press Ctrl+Option+Shift+Escape and everything stops within one sample (~8 ms). Resume is a button in the menu bar and nothing else — the agent cannot un-halt itself.
A virtual display for isolation. Park a window onto an invisible headless display, work on it there with full hardware input (no occlusion, no screen real estate), put it back. The display exists only while a lease holds it and sweeps every window home on teardown.
Sequence plans. Execute multi-step flows as one daemon-side operation — click, wait for the dialog, type, verify the field — with postcondition guards between steps and failure policies (abort, continue, pause-for-human, fallback). No round-trips between steps means the world can't change mid-sequence.
Diff perception. Read an app's text for a fraction of a screenshot's cost; pass the observation token back and get only what changed — elements appeared, vanished, values moved. Screenshots diff the same way: changed-region crops instead of the whole frame, scroll detection with revealed-edge strips.
Vision when the tree lies. About a sixth of Mac apps expose no usable accessibility
tree. A three-tier cascade covers them: accessibility first, then a local
UI-element detector — a
5.4 MB CoreML YOLOv11n, ~8 ms per window — plus OCR to turn an icon toolbar into
addressable boxes, then a local VLM for the rest. read --ocr and find --ocr return the
parsed rows, and groundedBy on every row says which tier answered.
Install
Or download the DMG of the latest release.
Requires macOS 26.5 or later on Apple silicon; tested on macOS 26 and 27.
Grant Accessibility (required) and Screen Recording (for screenshots and
scroll --until-text OCR) in System Settings > Privacy & Security.
Quick start
MCP
Add to your Claude Code config:
All verbs are exposed as MCP tools with the same names and arguments.
Commands
One coordinate frame everywhere: points, origin at the top-left of the main display.
rocuronium --help lists every flag; each MCP tool carries its own contract in its description.
Safety model
Two invariants hold for every action:
-
The cursor is never taken without opt-in. Ghost delivery (accessibility writes, per-process posted events) is the default. Hardware input — the path that moves the real cursor — requires an explicit flag and is refused while a human is present, while the screen is locked, or while another window covers the target.
-
Every action returns evidence. The three verdicts (
confirmed/noEffect/unverifiable) are the contract. The system exists becauseAXSetValuereports success on WebKit while changing nothing,AXPerformActionreports success on background menus that were never validated, and posted wheel events are silently ignored by every modern toolkit.
The emergency stop (Ctrl+Option+Shift+Escape) halts everything within one cursor sample. Resume is a button in the menu bar popover — no socket command can clear the halt.
Stack
Swift 6.2 with strict concurrency and @MainActor isolation by default. A menu-bar app
that holds the Accessibility grant, plus a dependency-free CLI that speaks to it over a
Unix-domain socket. The CLI is also the MCP server.
Apple frameworks
- Accessibility (ApplicationServices) — reading trees,
AXPress/AXSetValuedelivery - CoreGraphics / CGEvent — per-process posted events (ghost input) and cursor paths
- ScreenCaptureKit — occlusion-proof window captures and region diffs
- Vision — on-device OCR (the
scroll --until-textand--ocrpaths) - CoreML — the UI-element detector runs on the Neural Engine (
.cpuAndNeuralEngine) - SwiftUI + AppKit — menu-bar popover and the presence overlay
- Carbon / IOKit / Synchronization — the ⌃⌥⇧⎋ global kill switch, the virtual display, the lock-free cursor-sampling thread
Swift packages
- Propofol — the menu-bar popover UI kit
- mlx-swift + mlx-swift-lm — local VLM inference on Apple silicon
- swift-transformers — HuggingFace Hub model downloads and tokenizers
Vision models
- rocuronium-ui-detector — YOLOv11n trained with Ultralytics on GroundCUA (ServiceNow, Apache-2.0), exported to CoreML, hosted on HuggingFace (Apache-2.0)
- Holo 3.1 4B — GUI-grounding VLM, downloaded on demand and run through MLX
Interface
- Model Context Protocol — every verb exposed as an MCP tool with the same name and arguments
Documentation
.claude/skills/rocuronium— the agent's operator guide as a Claude Code skill:SKILL.mdplus areference/folder (the reply contract, targeting, acting, vision, plans, presence, isolation). It ships inside the app and the CLI:rocuronium guideprints it (or one reference,rocuronium guide acting),rocuronium guide --installcopies it to~/.claude/skills/rocuronium, and the menu-bar popover offers the same install when the copy there is missing or out of date.rocuronium --help— every command and flag.- Each MCP tool carries its own contract in its description.
CLAUDE.md— architecture and invariants for working on the code.
License
来源:README.md,提交 7247b48
工具
0版本历史
1- v1.3.0最新Oct 6, 2026


