Native permission setup
native-cua setup now opens a small native permission window inside the exact signed helper used by that installation's CLI and MCP. Opening the app directly also shows setup, with an explicit distinction when no agent is connected.
- Accessibility and Screen recording requests happen only after clicking Allow. Background startup and status checks never prompt or open setup.
- A nonactivating app tile beside System Settings can be dragged into a missing permission entry. The user approves access; the app never automates permission toggles or reads the TCC database.
- Live preflights show readable Allowed states. Restart helper rechecks safety, refuses an active command or capture, preserves grants, and invalidates old snapshots without retrying desktop actions.
- The installed driver now runs through LaunchServices, replacing inherited Terminal/Node permission ownership. A private, peer-bound bridge watches process lifetime so cancellation cannot leave an orphan recording.
Install
Requires an Apple Silicon Mac and Node.js 22+. Core controls/setup target macOS 14+; preview/recording require macOS 15+.
curl -fsSL https://raw.githubusercontent.com/R44VC0RP/native-cua/v0.4.0/install.sh | sh
"$HOME/.local/bin/native-cua" setupFor OpenCode 2:
opencode2 mcp add native_cua --global -- "$HOME/.local/bin/native-cua" mcpThen run the status tool through the MCP client. Previous Terminal/host grants do not replace granting access to Native CUA. Existing installation paths are never overwritten: review the old installation or select a fresh absolute --prefix.
The app is signed with Ryan Vogel's Developer ID, notarized by Apple, and stapled. The installer checks the checksum, pinned signer/bundle identity, and Gatekeeper's notarized assessment. It does not remove quarantine or change system security settings.
Verified
A new app permission identity began with all grants missing; the user granted them through macOS, and the actual app helper reported Accessibility, event posting, and screen capture granted. CLI and MCP resolved to the same process. Tests covered setup/restart, standalone launch/close, actual app control, screenshots, decoded silent H.264 recordings, restart refusal during capture, graceful EOF finalization, and forced bridge termination while recording. The notarized archive also installed into an isolated path containing spaces and an apostrophe, retained its signature after running, and refused an existing installation.
Verification was on Apple Silicon/macOS 27 beta, not a fresh OS installation. The guide was observed alongside Settings, but the manual drag-to-add gesture was not needed in this grant flow. Intel, Windows, and Linux remain unverified/unimplemented as documented. No microphone or Full Disk Access permission is requested.