Skip to content

Rocuronium 1.0

Choose a tag to compare

@kageroumado kageroumado released this 09 Sep 08:49
f4b67d3

First public release.

Rocuronium is a menu bar daemon that lets an AI agent see and operate macOS without taking the cursor or changing the frontmost app. Every action returns evidence of what observably happened — confirmed, noEffect, or unverifiable — because accessibility APIs routinely report success while doing nothing.

In this release

  • Ghost input: accessibility writes and per-process posted events, verified by read-back, pixel delta, window count, and process exit. Hardware input is opt-in per call.
  • Presence and safety: a presence overlay narrates cursor-taking work, on-screen consent when a human is present, and ⌃⌥⇧⎋ halts the engine within one sample. Resume is a button in the menu bar only.
  • Diff perception: read and screenshot return an observation token; pass it back as --since to get only what changed.
  • Vision when the tree lies: a local UI-element detector plus OCR, and an optional local VLM, for apps with no usable accessibility tree.
  • Virtual display isolation: park a window on a headless display, work on it with full hardware input, put it back.
  • Sequence plans: multi-step flows with postcondition guards and failure policies, run daemon-side.
  • MCP server (rocuronium mcp) exposing every verb as a typed tool, and the agent skill baked into the binary (rocuronium guide, rocuronium guide --install).
  • Trust boundary: the socket accepts only the embedded CLI and the app by signature, the one helper it spawns is signature-checked before every spawn, model weights are pinned and verified file by file, and credential surfaces (login window, SecurityAgent, screen saver) are refused as targets.

Requires macOS 26.5 or later on Apple silicon. Grant Accessibility (required) and Screen Recording (for screenshots and OCR).