v0.6.3 更新说明(自 v0.6.2 以来 / Changelog since v0.6.2)
仍提供两种安装包,按需下载:
browser-copilot-0.6.3-ocr.zip—— 完整版:内置本地 OCR(Tesseract.js),工作流 OCR 识别算子、离线验证码识别开箱即用。browser-copilot-0.6.3-no-ocr.zip—— 精简版(约小 98%):不含 OCR 引擎与语言模型,其余功能完全一致;OCR 算子置灰不可用,图片文字仍可通过视觉模型识别(设置 → 图片识别模型)。Two packages ship as usual: the full build with local OCR (Tesseract.js)
and a ~98% smaller lite build without it. Everything except local OCR is
identical.
✨ v0.6.3
这一版的主线是把"智能体"做成一个真正可被拆出去用的对象:内置代理可编辑、可见、可派发,
可分配到不同窗口互不串台;工作流的密钥处理也彻底从"明文嵌进工作流"改成"运行时按需拉取",
更符合安全直觉。顺带把工作流编辑器的体感、SEO 站点、定时任务那条"看起来没启动"的暗坑一并收掉。
🤖 内置智能体(Agents)
- 派发后端 —— 新增
Agent类型(区别于Skill:智能体是可执行、可派发的活跃单元,技能仍是注入式说明),内置 6 个代理(1 个 supervisor + search / writing / ops / workflow / analysis 五个 specialist),每个代理有自己的AGENT.md、import/export、后台命令。 delegate_to_agent工具 —— 父代理的确认 / 作用域内,调用一个隔离的子代理循环(独立的会话 id / 历史、白名单工具、≤1200 字摘要 + 产物引用),并设有三道硬关:拒绝轻量任务不烧 LLM、每轮最多 4 次派发、每个 (agent, task) 最多重试 1 次。派发对侧边栏对话是默认开启的,但非交互式运行保持单代理。- 侧边栏新增「代理」标签页(紧跟技能之后)—— 与技能同构的卡片 / 对话框:编辑名字、派发提示、角色、领域、工具白名单、关联技能、派发开关、轮次上限、指令;支持拖拽导入 / JSON 导出;内置代理默认只读,提供"复制为我的"。
- 内置代理可编辑 + 一键还原 —— 内置代理不再只读:编辑后保留
id与"内置"标记,但带真实的updatedAt(升级时 seeder 用id优先匹配,所以改过名字的内置代理也能挺过升级)。新增agents.reset命令与Restore default按钮,把代理写回出厂版本(updatedAt: 0)。 - 多窗口代理隔离 —— 多个 coding agent 通过本地 MCP 桥接时不再共用一个目标窗口:MCP 通道按
agentName → windowId多对多绑定(schema v6),每个 worker 还有"本次会话 agentId → windowId"映射处理重命名;未分配且已有绑定的连接发来 tool/prompt 会被拒绝(双语可操作错误),ping/tools.list保持开放。pin_tab与目标标签页缓存按窗口隔离;新增 worker 命令agent.windows.list与agent.bindings.set。 - 内置代理 i18n —— 名字、提示、指令都随用户语言切换;用户改过的内置代理显示自定义内容。
🔐 工作流密钥:运行时按需拉取
- 密钥不再嵌进工作流 —— 从对话历史生成工作流时,
get_secret算子现在发的是get-secret块(运行时拉取凭据 → 存到变量),后续forms块引用该变量;密文值再也不会以明文形式落进工作流定义。凭据更新后无需重发工作流,下一次运行自动拿到新值。 get-secret块改成下拉选择 —— 编辑面板、目录数据、executor 全部重塑为「凭据 · 字段」对(credential="<id>::<field>"编码,executor 端再拆回两半),用户从已存储的密钥里选,不再手敲 id。storage.blockDataFromArgs在历史回放时也吐新格式,老工作流走向后兼容的回退链。MV3 service worker 里把动态await import()换成静态引用,顺手修掉window is not defined崩。- i18n 配套 ——
BLOCK_FORM_STRINGS加上凭据字段名、"加载中 / 暂无凭据"占位文案、运行时解析的提示。
🖱️ 工作流编辑器体感
- 左键拖动 = 平移画布;按住空格 = 框选 —— 通过
[data-pan-mode]切换光标样式,符合流程图工具的肌肉记忆。 - 未保存保护 —— 关闭 / 刷新弹窗前若有未保存改动,弹原生
beforeunload确认。 - 生成节点用自然语言描述 —— 从聊天生成的工作流里,JavaScript 节点标题由"代码首行"换成作用短语(点击、填表、React 兼容赋值、跳转、本地存储、网络请求、派发事件、滚动等),按特异性排序,每节点上限若干条以保持可读;有现成注释就优先用注释。
🛠️ 修复
- 定时工作流不再"看起来没启动" —— 同一个任务过去会记成两条 run(
runTask一条、executeWorkflow一条),步骤只落到隐藏的那条,UI 只能看到两条 info log。executeWorkflow接受reuseRun,调度调用方已开的 run 步骤直接写进去、结束与清理交由调用方收尾;同时把 storage key 下的写入串行化(recordFinishedRun/addRun/saveTask不会再相互覆盖),把硬编码的"Starting agent task…"换成按 task 种类来的文案,run 的source改用追踪值(之前一边写schedule、一边写manual)。 pnpm dev/pnpm build/pnpm package恢复可用 —— 之前被指到未入库的scripts/vite.mjs包装,现在直接调用vite。
🌐 SEO 与官网
- 扩展各页 SEO 补全 —— meta description、favicon 链接、
lang属性统一、清单加short_name/author/homepage_url、package.json加仓库 / bugs / author / keywords。 - 双语官网与 GitHub Pages 自动发布 —— 新建
website/落地页(含完整 SEO meta、Open Graph、Twitter Card、JSON-LD 结构化数据),通过.github/workflows/pages.yml自动部署。 - README 加 Shields 徽章。
📚 文档
- MCP 多窗口代理分配 —— 新增"按代理绑定浏览器窗口"小节,说明隔离语义、按窗口的
pin_tab、未分配连接的拒绝行为、BROWSER_COPILOT_AGENT_NAME消歧字段,并在 WS 协议表里补齐agentId/agentName字段。
English summary
v0.6.3 — the theme is making "agents" a first-class object you can edit, see, delegate to and isolate per window, and moving workflow secrets out of the workflow body and into a runtime lookup.
- Built-in agents: a new
Agenttype distinct fromSkill(active, delegatable execution unit) ships with six built-ins (one supervisor + five specialists), per-agentAGENT.mdpersistence, import/export and background handlers. The newdelegate_to_agenttool runs an isolated sub-agent loop (own namespaced conversation id, whitelisted tools, ≤1200-char summary + artifact references) under the parent's confirm/scope, with three hard gates (small-task refusal costing no LLM, ≤4 delegations per turn, ≤1 retry per (agent, task)). Delegation is opt-in for panel turns; unattended runs stay single-agent. - Agents tab in the side panel, mirroring the skills pattern: edit name / delegation hint / role / domain / tool whitelist / linked skills / delegation flag / round cap / instructions, drag-and-drop import + JSON export; built-ins are read-only with a "duplicate as mine" action.
- Built-ins are editable now: edits keep the
idand the built-in marker under a realupdatedAt, and the seeder matches byidfirst so a renamed built-in survives upgrade. A newagents.resetcommand and a Restore default button write the shipped version back (updatedAt: 0). - Multi-window isolation: the local MCP bridge now binds
agentName → windowId(N:N, schema v6) instead of sharing one global target window; an unassigned connection is refused with an actionable bilingual error once any binding exists, whileping/tools.liststay open.pin_taband the resolved-tab cache are scoped per window, and two new worker commands (agent.windows.list,agent.bindings.set) replace the global selection with a per-window assignment surface. - Built-in agent i18n for display name, hint and instructions; user-edited built-ins show their custom content.
- Secrets are no longer embedded in workflows: when a workflow is generated from chat history,
get_secretactions now emit aget-secretblock that fetches the credential at runtime and stores it in a variable, with a downstreamformsblock that references it. The value is never written into the workflow, so credential updates are picked up on the next run for free. get-secretblock becomes a dropdown: catalog data, edit form and executor all carry a(credential · field)pair fromlistPasswords()— no more typing raw ids. Older workflows keep working through a backward-compat fallback. Static imports in the executor fix thewindow is not definedcrash the MV3 service worker hit onawait import().- Workflow editor UX: left-drag pans the canvas; holding Space switches to rubber-band selection (cursor follows
[data-pan-mode]);beforeunloadguards unsaved changes; generated JavaScript nodes are now described by their effects (click, fill, React-compatible value set, navigation, storage, network, event dispatch, scroll, …) instead of by their first code line, with specificity-ordered phrases and a per-node cap. - Scheduled workflows no longer "look unstarted":
executeWorkflowacceptsreuseRunso the task runner's run is the one steps land on; per-storage-key write serialisation preventsrecordFinishedRun/addRun/saveTaskfrom losing each other; the per-kind opening line replaces the hardcoded "Starting agent task…"; the run'ssourceis read from the tracked value so both halves stay in the same history section. - Build fix:
pnpm dev/pnpm build/pnpm packageare restored by pointing scripts directly atvite(the previous wrapper was never committed). - SEO & landing page: meta description / favicon /
langunified across extension HTML,short_name/author/homepage_urladded to the manifest, repository / bugs / author / keywords added topackage.json, Shields badges in both READMEs, and a bilingualwebsite/landing page (full SEO meta + Open Graph + Twitter Card + JSON-LD) auto-deployed by.github/workflows/pages.yml. - Docs: an MCP setup section now covers multi-window agent binding, isolation semantics,
BROWSER_COPILOT_AGENT_NAMEdisambiguation, and theagentId/agentNameidentity fields in the WS protocol table.
Full changelog: v0.6.2...v0.6.3
What's Changed
- Feat/local agent window isolation by @dcc123456 in #17
Full Changelog: v0.6.2...v0.6.3