Skip to content

Releases: kageroumado/rocuronium

Rocuronium 1.2

Choose a tag to compare

@kageroumado kageroumado released this 19 Sep 21:53
b2c7810

A polish release for macOS 27.

  • The popover's Settings, Demo Stage, and Quit buttons are round again: macOS 27 draws the system's glass buttons as wide capsules. All three share one height and sit the same distance from the popover's side and bottom edges.

Rocuronium 1.1

Choose a tag to compare

@kageroumado kageroumado released this 18 Sep 19:47
4dd3daa

Three new verbs, plus safety and presence fixes.

New verbs

  • map — an ASCII layout of an app's interactable elements, each numbered where it sits, with a {n, role, label, frame} legend and a token. Reads the layout as text (no vision tokens, works behind a locked screen). click --box N --token <t> clicks a numbered element after a live window-freshness check.
  • window — native fullscreen (--fullscreen on|off), --minimize/--unminimize, and --zoom. Ghost: no cursor, no focus change; read-back verdict; presence-gated like resize.
  • space — real Mission Control Spaces: list (read-only), switch (gated like activate), and move a window to another Space.

Fixes

  • No longer segfaults when inspecting Rocuronium's own windows — same-process accessibility reads now run on the main thread, as writes already did.
  • busy --note is now the human-visible reason, shown as the presence-overlay headline with the current action beneath it.

Rocuronium 1.0

Choose a tag to compare

@kageroumado kageroumado released this 09 Sep 08:49
f4b67d3

First public release.

Rocuronium is a menu bar daemon that lets an AI agent see and operate macOS without taking the cursor or changing the frontmost app. Every action returns evidence of what observably happened — confirmed, noEffect, or unverifiable — because accessibility APIs routinely report success while doing nothing.

In this release

  • Ghost input: accessibility writes and per-process posted events, verified by read-back, pixel delta, window count, and process exit. Hardware input is opt-in per call.
  • Presence and safety: a presence overlay narrates cursor-taking work, on-screen consent when a human is present, and ⌃⌥⇧⎋ halts the engine within one sample. Resume is a button in the menu bar only.
  • Diff perception: read and screenshot return an observation token; pass it back as --since to get only what changed.
  • Vision when the tree lies: a local UI-element detector plus OCR, and an optional local VLM, for apps with no usable accessibility tree.
  • Virtual display isolation: park a window on a headless display, work on it with full hardware input, put it back.
  • Sequence plans: multi-step flows with postcondition guards and failure policies, run daemon-side.
  • MCP server (rocuronium mcp) exposing every verb as a typed tool, and the agent skill baked into the binary (rocuronium guide, rocuronium guide --install).
  • Trust boundary: the socket accepts only the embedded CLI and the app by signature, the one helper it spawns is signature-checked before every spawn, model weights are pinned and verified file by file, and credential surfaces (login window, SecurityAgent, screen saver) are refused as targets.

Requires macOS 26.5 or later on Apple silicon. Grant Accessibility (required) and Screen Recording (for screenshots and OCR).