Hmbown / Hmbown/Codewhale

Computer-use plugin: live-install receipt + first look-act loop

Open
#5,856 4 comments 0 reactions 0 assignees View on GitHub
enhancement release-blocker tools
Dominant language
Rust
Stars
41k
Forks
3.6k
Avg merge
13h 59m
Merged PRs (30d)
299

Description

## Remaining Engine acceptance — triage 2026-09-07

The comments establish that this bundle is built in; a separate plugin-install ceremony is not the acceptance path for a build that already includes it.

- [ ] Discover the built-in bundle in the intended release build, review/trust/enable the exact bytes and connect through the existing Engine MCP path.
- [ ] Verify the selected tools are present for the actual model before inference and remain correctly discoverable after connection changes.
- [ ] Complete a real model-triggered observe–act–verify task with the chosen app/computer, required approval and observed final result.
- [ ] Retain the originating task's sanitized tool/approval/result receipt; direct stdio or tools/list success is not a model-loop receipt.
- [ ] Qualify cancellation, disconnect/reconnect and host permission failures without stale input replay.
- [ ] Keep host self-approval prevention explicit: Computer Use must not serve as a way to approve its own pending authorization.

Related: [plugin launch tracker](https://github.com/Hmbown/codewhale-cu-plugin/issues/8), [text-only/vision qualification](https://github.com/Hmbown/codewhale-cu-plugin/issues/13), [production desktop package](https://github.com/Hmbown/codewhale-apps/issues/513).

The older screenshot-failure diagnosis below was corrected in the existing comments; do not repeat it as a confirmed current TCC defect.

---

## Original scope and acceptance (preserved)

Draft PR #5855 holds the bundle (manifest, mcp.json stdio server, skill, /computer command). Remaining: install it in a release build via /plugin install, connect the MCP server, and run one real look-act-verify loop (screenshot, click, verify) with receipts. Server protocol (9/9), bundle validation, and live macOS screenshot already proven.

Contributor guide

Open the contributing guide

Research direction

Start by reviewing draft PR #5855 and the remaining acceptance checklist, then build the intended release and connect the bundled plugin through the existing Engine MCP path. Done means a real model-triggered observe–act–verify task has a sanitized tool, approval, and result receipt, with cancellation, reconnect, permission failures, and self-approval prevention qualified.

Written by the indexing model from the issue text.

Assessment

Tech stack
macos, rust
Domain
ai, backend-api-design, desktop, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Active
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.