Rule of thumb the agent should follow: web task → browser-use; native app / canvas /
no-a11y UI → computer-use. Default to browser; fall back to computer when browser can’t reach it.
Both are off by default. Both flow through the same MCP client, approval gate, and tool-set pinning as any other MCP server. See MCP servers and the runtime security model.
Both presets are settings in
agents.json, shown below. In the browser, Studio →
Capabilities → MCP servers has a card for each preset that writes the same fields, and
monad mcp status reports the synthesized browser / computer server once enabled.
Screenshots reach the model
Any image an MCP tool returns (a screenshot) is surfaced to the model as a real image content part — never JSON-stringified into text. The raw bytes ride a side channel so a megabyte of base64 never lands in the persisted or text result. This is what makes both tracks usable.Browser use
Enable the Playwright MCP preset (Microsoft’s official server — accessibility-tree grounding, cross-browser, the de-facto default for agent web automation):browser MCP server (npx @playwright/mcp). Read-only tools are
auto-approved; mutating tools (navigate/click/type/evaluate) route through the gate.
Alternative servers. A user-defined mcpServers entry named browser takes precedence
over the preset, so you can point at any other server:
- chrome-devtools-mcp (Google, CDP) — best for Chrome debugging / performance traces / network inspection, or driving your real logged-in Chrome. Chrome-only; a good alternative, not a better default.
- Stagehand (Browserbase) — natural-language act/extract/observe, robust to layout drift.
- Browserbase — managed cloud browser (CDP-as-a-service).
Computer use
Computer-use drives your real desktop — that is the point, so it is not sandboxed. Enable it explicitly:computer MCP server. The default targets the cross-platform
AB498/computer-control-mcp (PyAutoGUI + OCR,
via uvx); override command/args to use another (e.g. MCPControl,
or a sandboxed/remote desktop like trycua / e2b desktop).
Security model: host-escape (the sanctioned exception)
Monad’s default posture is contain the agent. Computer-use can’t be contained — it moves the real mouse/keyboard — so it is treated as a host-escape capability, the same class ascode_execute running on the host. The exception is explicit and bounded, not silent:
- Read-only tools (screenshot, cursor, screen size, window list) are auto-approved.
- Mutating tools (click/type/drag/key/scroll) are tagged with the
host-controlgate key (trust.hostEscape: trueon the server). - The approval engine treats
host-controlas a class grant: one “control this computer for this session” approval covers all mutating actions (no per-click prompt), and it expires with the session. - A host-control allow can never persist beyond session scope — no permanent global/agent “always allow” — the daemon refuses to persist that grant. A deny at any scope always wins, so an operator can hard-disable it.
deny rule wins over any allow at every scope, so an
operator can carve dangerous actions out of the session grant. Recommended baseline in agents.json
(tool names track your chosen server; adjust to match):
Provider-native acceleration (optional)
A tool may declare a provider-native binding (ToolSpec.providerTool); when the active
provider matches, the adapter emits the provider’s built-in tool instead of a generic
function tool. For Claude this means the
trained computer_20250124/computer_20251124 tool. The portable generic path is the
fallback, so GPT/Gemini still work. Wiring a synthetic computer tool that maps the native
action set onto a chosen server’s tools is future work.