@machine-core

Tools

Browser and desktop automation through machine_use, and Webtop shell through agent-core’s execute.

machine-core contributes the machine_use tool under the schema-first tool contract. Shell execution is supplied through its authenticated Webtop connector and called using agent-core's execute. Both operations act inside the selected per-project Webtop container.

Entry pointFeature gateWhat it does
machine_usemachine.read, with machine.drive for drive actionsBrowser and desktop automation: unchanged 22-action enum and chromium | desktop target
execute with a Webtop source URIcore.execute + the entry feature exec.machine + the source's own exec policy on the cwd, then source scope and machine lifecycle authorityShell inside the selected machine

machine_use

machine_use is a single tool that dispatches on an action enum (22 values) and a target (chromium — the CDP-attached browser, the default — or desktop — the full XFCE session). Its declared baseline gate is machine.read; drive-class actions escalate to machine.drive inside the handler, because the required feature depends on the action argument and so cannot be expressed as a static declarative gate (x-neuralis.requires declares the baseline plus an escalations hint).

The full action catalogue — navigation, input, capture, recording, reads, desktop ops, and the batch composite — plus the per-action gating split, the recording caps, and the vision/video content-block translation are documented in depth on the machine_use tool.

Webtop shell through execute

Use execute({ command: "pwd", cwd: "<source>:///config" }), replacing <source> with the actual registered Webtop slug. A source root selects /; no explicit connector URI means the ordinary project-directory default, not automatic machine selection.

exec.machine is the entry this connector DECLARES, checked by the platform before the provider is reached; the source's own path policy then decides whether that caller may start a command in that directory. The provider enforces current source scope and machine lifecycle authority. The container sandbox and network isolation remain the execution boundary; the command-head denylist is cosmetic friction. See Webtop shell for timeout, environment and Stop semantics.

The former machine_exec callable has no alias. Update custom tool/hosted selections deliberately: execute also exposes app/host shell and skill activation, so lists are not broadened automatically. For an existing machine with no source, an authorized source manager can attach a webtop source at the same project and slug without replacing its container or profile. Shell permission alone does not grant source-creation authority.

Audit trail

Every machine_use call records its action, target, session key and caller identity; Webtop shell records the command and caller in the provider's audit trail.

On this page