Rocuronium

glass.kagerouv1.3.0更新於 Oct 6, 2026

Drive macOS apps without taking the cursor: read, click, type, scroll, each with evidence.

已驗證STDIO僅桌面Developer ToolsBrowser Automation

概覽

AI 產生的概覽

讓助理在不佔用使用者游標的情況下觀察並操作 macOS 應用程式:讀取文字、點擊、輸入、捲動、拖曳。

功能
一個選單列常駐程式加上命令列工具,把 macOS 控制動作以同名同參數的 MCP 工具暴露出來。觀察類工具包括 status、apps、windows、find、read、wait、screenshot 和 activity;操作類工具包括 type、click、key、shortcut、menu、scroll、launch 和 activate;游標類工具為 move 和 drag;plan 可執行帶守衛的多步驟流程;display 和 park 使用虛擬顯示器做隔離。多數動作透過輔助使用介面與逐程序投遞的事件完成,每次都會回傳 confirmed、noEffect 或 unverifiable 的判定。
適用情境
當助理需要在使用者自己的機器上操作原生 macOS 應用程式時值得安裝,例如讀取應用程式文字、點擊按鈕、輸入內容或執行多步驟介面流程,同時使用者可以繼續自己的工作。它僅支援 macOS 桌面環境,不適用於無頭伺服器或非 Mac 環境。
執行需求
需要 Apple 晶片上的 macOS 26.5 或更新版本,以已簽章並公證的應用程式或透過 Homebrew 安裝。常駐程式需要在系統設定中授予「輔助使用」(必要)和「螢幕錄製」(用於截圖與 OCR)權限。MCP 伺服器透過 stdio 在本機執行;未宣告任何帳號、API 金鑰或環境變數。
安裝前請注意
此伺服器可以讀取螢幕內容與應用程式文字,並能點擊、輸入、執行快速鍵、啟動應用程式以及移動真實游標,因此可能變更或刪除目標應用程式中的資料。硬體游標操作需要明確旗標,且在有人在场、螢幕鎖定或目標被其他視窗遮住時會被拒絕。全域緊急停止可中止一切操作,且只有選單列按鈕才能恢復。視覺模型會視需要下載。

安裝

在 SourceWeft 中

  1. 開啟 儀表板中的 Rocuronium,將其新增到工作區。
  2. 為需要使用其工具的對話啟用該服務。

Desktop only,透過 STDIO。 STDIO 服務會啟動本機處理程序,因此需要 SourceWeft 桌面主機。

其他 MCP 客戶端

參照 儲存庫 中的啟動說明。

README

[Rocuronium icon]

rocuronium

Drive this Mac without taking the cursor.

[Download Rocuronium for Mac]
A signed, notarized disk image · free and open source (MIT)

A menu bar daemon that lets an AI agent see and operate macOS — read text, click buttons, type, scroll, drag, draw — while the human keeps their cursor, their focus, and a kill switch. Every action returns evidence of what observably happened, because accessibility APIs routinely lie about success.

[The presence overlay while an agent asks to move the cursor: the jellyfish escort, the approve/decline prompt answered by holding Y or N, and the bezel narrating the action with the take-over shortcut]

A cursor-taking action while someone is at the machine: the jellyfish marks where the agent is, the prompt waits for a one-second hold on Y or N, and the bezel narrates the action with the shortcut that halts everything.

What makes it different

Ghost input. Most actions are delivered through accessibility and per-process posted events — no cursor movement, no focus change, invisible to the person at the keyboard. The agent works beside you, not instead of you.

Evidence, not return codes. Every action is verified: text is read back after writing, pixels are compared before and after, window counts are checked, process exits are detected. The reply says confirmed, noEffect, or unverifiable — and noEffect (the API said "success" but nothing changed) is the most important one.

The human is never locked out. Cursor-taking actions show a presence overlay — a jellyfish escorting the cursor, a bezel narrating what's happening. Touch the mouse and the gesture yields. Press Ctrl+Option+Shift+Escape and everything stops within one sample (~8 ms). Resume is a button in the menu bar and nothing else — the agent cannot un-halt itself.

A virtual display for isolation. Park a window onto an invisible headless display, work on it there with full hardware input (no occlusion, no screen real estate), put it back. The display exists only while a lease holds it and sweeps every window home on teardown.

Sequence plans. Execute multi-step flows as one daemon-side operation — click, wait for the dialog, type, verify the field — with postcondition guards between steps and failure policies (abort, continue, pause-for-human, fallback). No round-trips between steps means the world can't change mid-sequence.

Diff perception. Read an app's text for a fraction of a screenshot's cost; pass the observation token back and get only what changed — elements appeared, vanished, values moved. Screenshots diff the same way: changed-region crops instead of the whole frame, scroll detection with revealed-edge strips.

Vision when the tree lies. About a sixth of Mac apps expose no usable accessibility tree. A three-tier cascade covers them: accessibility first, then a local UI-element detector — a 5.4 MB CoreML YOLOv11n, ~8 ms per window — plus OCR to turn an icon toolbar into addressable boxes, then a local VLM for the rest. read --ocr and find --ocr return the parsed rows, and groundedBy on every row says which tier answered.

Install

bash
brew install kageroumado/tap/rocuronium

Or download the DMG of the latest release.

Requires macOS 26.5 or later on Apple silicon; tested on macOS 26 and 27.

Grant Accessibility (required) and Screen Recording (for screenshots and scroll --until-text OCR) in System Settings > Privacy & Security.

Quick start

bash
rocuronium status                          # is the daemon running, what can I seerocuronium read --app TextEdit             # dump the app's text via accessibilityrocuronium click --app Safari --label Done # click a button without touching the cursorrocuronium type --app Notes --text "hello" # type into the focused fieldrocuronium shortcut --app Notes --keys cmd+c  # copy the selection (real clipboard, with a verdict)rocuronium screenshot --app Finder         # capture a window (occlusion-proof)
rocuronium mcp                             # start the MCP server (stdio)

MCP

Add to your Claude Code config:

json
{  "mcpServers": {    "rocuronium": {      "command": "/Applications/Rocuronium.app/Contents/Resources/rocuronium",      "args": ["mcp"]    }  }}

All verbs are exposed as MCP tools with the same names and arguments.

Commands

Verbs
Observestatus diag apps windows find read wait screenshot activity
Acttype click key shortcut menu scroll statusitem launch activate
Cursormove drag (hardware — takes the real cursor, presence-gated)
Orchestrateplan (multi-step with guards)
Isolatedisplay (virtual display lease) park (move window to it)
Metabusy (hold the presence overlay up while working) demo (practice window) request-capture mcp

One coordinate frame everywhere: points, origin at the top-left of the main display. rocuronium --help lists every flag; each MCP tool carries its own contract in its description.

Safety model

Two invariants hold for every action:

  1. The cursor is never taken without opt-in. Ghost delivery (accessibility writes, per-process posted events) is the default. Hardware input — the path that moves the real cursor — requires an explicit flag and is refused while a human is present, while the screen is locked, or while another window covers the target.

  2. Every action returns evidence. The three verdicts (confirmed / noEffect / unverifiable) are the contract. The system exists because AXSetValue reports success on WebKit while changing nothing, AXPerformAction reports success on background menus that were never validated, and posted wheel events are silently ignored by every modern toolkit.

The emergency stop (Ctrl+Option+Shift+Escape) halts everything within one cursor sample. Resume is a button in the menu bar popover — no socket command can clear the halt.

Stack

Swift 6.2 with strict concurrency and @MainActor isolation by default. A menu-bar app that holds the Accessibility grant, plus a dependency-free CLI that speaks to it over a Unix-domain socket. The CLI is also the MCP server.

Apple frameworks

  • Accessibility (ApplicationServices) — reading trees, AXPress/AXSetValue delivery
  • CoreGraphics / CGEvent — per-process posted events (ghost input) and cursor paths
  • ScreenCaptureKit — occlusion-proof window captures and region diffs
  • Vision — on-device OCR (the scroll --until-text and --ocr paths)
  • CoreML — the UI-element detector runs on the Neural Engine (.cpuAndNeuralEngine)
  • SwiftUI + AppKit — menu-bar popover and the presence overlay
  • Carbon / IOKit / Synchronization — the ⌃⌥⇧⎋ global kill switch, the virtual display, the lock-free cursor-sampling thread

Swift packages

Vision models

Interface

Documentation

  • .claude/skills/rocuronium — the agent's operator guide as a Claude Code skill: SKILL.md plus a reference/ folder (the reply contract, targeting, acting, vision, plans, presence, isolation). It ships inside the app and the CLI: rocuronium guide prints it (or one reference, rocuronium guide acting), rocuronium guide --install copies it to ~/.claude/skills/rocuronium, and the menu-bar popover offers the same install when the copy there is missing or out of date.
  • rocuronium --help — every command and flag.
  • Each MCP tool carries its own contract in its description.
  • CLAUDE.md — architecture and invariants for working on the code.

License

MIT

來源:README.md,提交 7247b48

工具

0
工具後設資料尚未被收錄。

版本歷史

1
  1. v1.3.0最新Oct 6, 2026