Tools
Browser and desktop automation through machine_use, and Webtop shell through agent-core’s execute.
machine-core contributes the machine_use tool under the
schema-first tool contract. Shell execution is supplied
through its authenticated Webtop connector and called using agent-core's execute.
Both operations act inside the selected per-project Webtop container.
| Entry point | Feature gate | What it does |
|---|---|---|
machine_use | machine.read, with machine.drive for drive actions | Browser and desktop automation: unchanged 22-action enum and chromium | desktop target |
execute with a Webtop source URI | core.execute + the entry feature exec.machine + the source's own exec policy on the cwd, then source scope and machine lifecycle authority | Shell inside the selected machine |
machine_use
machine_use is a single tool that dispatches on an action enum (22 values)
and a target (chromium — the CDP-attached browser, the default — or
desktop — the full XFCE session). Its declared baseline gate is
machine.read; drive-class actions escalate to machine.drive inside the
handler, because the required feature depends on the action argument and so
cannot be expressed as a static declarative gate (x-neuralis.requires
declares the baseline plus an escalations hint).
The full action catalogue — navigation, input, capture, recording, reads,
desktop ops, and the batch composite — plus the per-action gating split, the
recording caps, and the vision/video content-block translation are documented
in depth on the machine_use tool.
Webtop shell through execute
Use execute({ command: "pwd", cwd: "<source>:///config" }), replacing <source>
with the actual registered Webtop slug. A source root selects /; no explicit connector
URI means the ordinary project-directory default, not automatic machine selection.
exec.machine is the entry this connector DECLARES, checked by the platform before the provider is reached; the source's own path policy then decides whether that caller may start a command in that directory. The provider enforces current source scope and machine lifecycle authority.
The container sandbox and network isolation remain the execution boundary; the command-head
denylist is cosmetic friction. See Webtop shell
for timeout, environment and Stop semantics.
The former machine_exec callable has no alias. Update custom tool/hosted selections deliberately:
execute also exposes app/host shell and skill activation, so lists are not broadened automatically.
For an existing machine with no source, an authorized source manager can attach a webtop
source at the same project and slug without replacing its container or profile. Shell permission
alone does not grant source-creation authority.
Audit trail
Every machine_use call records its action, target, session key and caller identity;
Webtop shell records the command and caller in the provider's audit trail.