Skip to content

Releases: KernelErr/CatPaw

CatPaw v0.2.1

Choose a tag to compare

@github-actions github-actions released this 11 Oct 06:58

Pages load faster. A profile of real sites (catpaw fetch --js --profile, new) showed their time going to waiting for the network one
thing at a time, not to their scripts:

  • The imports of a module load side by side, as a browser loads a module
    graph; they were fetched one after another, each waiting its turn. An
    import map's bare specifiers are started ahead too, and
    <link rel="modulepreload"> is honoured.
  • A frame's document loads off the page's thread, as a browser loads
    one: the page's scripts, timers and other frames run meanwhile, and the
    page waits for it as for a request of its own, under the settle
    policy's rules (a frame on an ignored host never holds an action up, a
    slow third party's for three seconds at most). The page used to fetch
    each frame's document in turn before going on, a frame that did not
    answer costing up to eight seconds a redirect hop. A frame that opens
    now runs before its parent's clock moves on, so its load fires where
    a browser's would, before the parent's later timers.
  • The external scripts a document names are fetched before the parser
    reaches them, as a browser's preload scanner has them: a script the
    parser waits for no longer holds up the ones after it.
  • catpaw fetch --js --profile tells where a page's time went: the event
    loop's steps by kind, scripts by source (compiling apart from running),
    parsing, rendering, and the waits for the network.

On the sites measured, the time waiting for the network fell by a third
to a half (github.com 13 s to 6–8 s on a quiet network, techcrunch.com
35 s to 16–17 s, figma.com 19 s to 13 s, crates.io 6.5 s to 4.4 s).
Network latency sets the rest: on these sites the scripts themselves
took 0.3–3 s a page, with a few heavy ones (an obfuscated bot check that
runs for the whole 10 s script budget) as the exceptions.

Install

macOS (Apple silicon) and Linux (x86_64, aarch64):

curl -fsSL https://catpaw.sh/install.sh | sh

Windows (PowerShell):

irm https://catpaw.sh/install.ps1 | iex

The scripts download the archive for your system from this release and
check it against SHA256SUMS. Or download an archive below, check it
(sha256sum -c SHA256SUMS --ignore-missing), and put catpaw on your
PATH. Then connect it to your agent:

catpaw setup claude-code

Intel Macs and other systems: cargo install catpaw (Rust 1.91 or
later) builds it, see the README.

CatPaw v0.2.0

Choose a tag to compare

@github-actions github-actions released this 11 Oct 02:22

From an agent's report of using CatPaw on a NAS:

  • Downloads are saved to disk as they arrive, in ~/Downloads/CatPaw by
    default: no longer kept in memory and cut off at the response limit,
    so large files work. The navigation answers at once with where the file
    goes, wait({"for":"download"}) waits until it is saved, and the
    download view of read says how far it is.
  • settings, a new tool: shows CatPaw's settings and changes them, the
    user approving each change, which is saved in settings.json next to
    the approval key: downloadDir, and localAddress, the address the
    hand-off and approval pages listen on when the user's browser is on
    another machine (they listened on 127.0.0.1 only). --download-dir,
    --local-address and --settings-file set them from the command line.
  • The agent can take a hand-off back (handoff with end: true) when the
    user cannot reach the page or will not finish, what they typed staying
    masked; and a tab with the user can be closed.
  • Switching tabs shows what changed since the agent last saw the tab
    (snapshot: "full" or "none" for the rest), not the whole page.
  • Clicks go through what does not take the pointer: a box with
    pointer-events: none (a decorative overlay over a button) or
    visibility: hidden is not hit, its children may be; clicks no longer
    stop at "covered by" such a box.

The library crates' public types changed (responses carry a saved file,
requests a download), hence 0.2.0.

Install

macOS (Apple silicon) and Linux (x86_64, aarch64):

curl -fsSL https://catpaw.sh/install.sh | sh

Windows (PowerShell):

irm https://catpaw.sh/install.ps1 | iex

The scripts download the archive for your system from this release and
check it against SHA256SUMS. Or download an archive below, check it
(sha256sum -c SHA256SUMS --ignore-missing), and put catpaw on your
PATH. Then connect it to your agent:

catpaw setup claude-code

Intel Macs and other systems: cargo install catpaw (Rust 1.91 or
later) builds it, see the README.

CatPaw v0.1.1

Choose a tag to compare

@github-actions github-actions released this 10 Oct 19:21
  • Proxies from the environment: without --proxy, CatPaw reads
    https_proxy, http_proxy, all_proxy and no_proxy as curl does
    (localhost and loopback addresses always go direct, as in Chrome), and
    --proxy direct ignores them. An MCP host passes its environment on to
    catpaw mcp, so a registered server follows the user's proxy settings.
  • On crates.io: cargo install catpaw builds it. Boa and stylo_taffy, with
    the fixes CatPaw needs, are published as catpaw-boa-ast,
    catpaw-boa-parser, catpaw-boa-engine and catpaw-stylo-taffy.
  • Rust 1.91 or later builds it (Boa 0.22 needs 1.91; 0.1.0 said 1.89).
  • The install scripts take --dry-run (-DryRun), and
    https://catpaw.sh/install.md lets an agent install CatPaw for its user,
    with their yes.

Install

macOS (Apple silicon) and Linux (x86_64, aarch64):

curl -fsSL https://catpaw.sh/install.sh | sh

Windows (PowerShell):

irm https://catpaw.sh/install.ps1 | iex

The scripts download the archive for your system from this release and
check it against SHA256SUMS. Or download an archive below, check it
(sha256sum -c SHA256SUMS --ignore-missing), and put catpaw on your
PATH. Then connect it to your agent:

catpaw setup claude-code

Intel Macs and other systems build from source: see the README.

CatPaw v0.1.0

Choose a tag to compare

@github-actions github-actions released this 10 Oct 16:45

The first preview: a browser an agent drives over MCP, with the user
asked before anything is sent on their behalf. The tools and their
results may still change before 1.0. What does not work as a browser's
would yet is listed in Known gaps.

Binaries for Linux (x86_64, aarch64), macOS on Apple silicon and Windows
(x86_64); Intel Macs build from source.

For agents

  • catpaw mcp --stdio serves fifteen tools: navigate, snapshot,
    click, type, fill, press, select, act, wait, read,
    screenshot, evaluate, tabs, logs and handoff (and, on
    request, session for checkpoints). catpaw setup claude-code,
    codex or cursor registers it with a host.
  • Snapshots in a compact text form with refs that are never reused; an
    action answers with what happened and what changed, once the page has
    settled, and a page that did not settle says what it waits on.
  • Confirmations: a form posted, a file uploaded (and, under --policy strict, script sending data to another site, and evaluate) waits
    for the user. A host with MCP elicitation asks in its own prompt;
    otherwise CatPaw opens an approval page in the user's browser.
  • Hand-off: the user takes over a tab in their own browser (a login, a
    check meant for people), and the agent gets it back with what they
    typed masked.
  • A flight journal of every call, profiles that keep cookies and
    storage between sessions, checkpoints, and traffic recorded to HAR and
    replayed byte for byte.

The engine

  • HTTP/1.1 and HTTP/2 over rustls, cookies, proxies, private addresses
    refused by default, and Web Bot Auth request signing for deployers with
    their own key.
  • HTML parsing, style by Stylo, JavaScript by Boa with bindings generated
    from Web IDL, an event loop with virtual time, frames, popups, workers,
    WebSocket, storage, Web Crypto and Canvas 2D.
  • Shadow trees styled and shown as they render: their own and adopted
    style sheets, slots, and document rules kept out of them.
  • Media elements that play nothing and say so, no plugins and no PDF
    viewer; :has() and :nth-child(… of …) selectors; RegExp.$1 and the
    other legacy static properties of RegExp; Intl.DateTimeFormat
    formatToParts, and dates with the whole year and 2-digit padding as
    asked for.
  • Date.parse takes 2026/10/10 15:51:46+00:00, 2026-10-10 15:51:46 UTC
    and its own toString() back; a stack overflow is a RangeError script
    can catch, as in browsers.
  • The modules a module imports load side by side, as a browser loads a
    module graph: x.com's 590 modules took 100 seconds one by one, now 10.
  • Layout by Taffy and Parley when something asks for geometry, and
    screenshots by tiny-skia.
  • web-platform-tests run in CI against recorded expectations.

Identity

CatPaw says what it is: its User-Agent is CatPaw/0.1.0 (+https://catpaw.sh/bot), and it ships no fingerprint impersonation and
no CAPTCHA solving.

Install

macOS (Apple silicon) and Linux (x86_64, aarch64):

curl -fsSL https://catpaw.sh/install.sh | sh

Windows (PowerShell):

irm https://catpaw.sh/install.ps1 | iex

The scripts download the archive for your system from this release and
check it against SHA256SUMS. Or download an archive below, check it
(sha256sum -c SHA256SUMS --ignore-missing), and put catpaw on your
PATH. Then connect it to your agent:

catpaw setup claude-code

Intel Macs and other systems build from source: see the README.