Skip to main content
Monad lets the agent see and operate a GUI through off-the-shelf MCP servers — Monad ships no automation server of its own, it connects existing ones and applies its gate, tool-pinning, and image-passthrough on top. There are two distinct capabilities, on two tracks; pick by task: Rule of thumb the agent should follow: web task → browser-use; native app / canvas / no-a11y UI → computer-use. Default to browser; fall back to computer when browser can’t reach it. Both are off by default. Both flow through the same MCP client, approval gate, and tool-set pinning as any other MCP server. See MCP servers and the runtime security model. Both presets are settings in agents.json, shown below. In the browser, Studio → Capabilities → MCP servers has a card for each preset that writes the same fields, and monad mcp status reports the synthesized browser / computer server once enabled.

Screenshots reach the model

Any image an MCP tool returns (a screenshot) is surfaced to the model as a real image content part — never JSON-stringified into text. The raw bytes ride a side channel so a megabyte of base64 never lands in the persisted or text result. This is what makes both tracks usable.

Browser use

Enable the Playwright MCP preset (Microsoft’s official server — accessibility-tree grounding, cross-browser, the de-facto default for agent web automation):
The daemon synthesizes a browser MCP server (npx @playwright/mcp). Read-only tools are auto-approved; mutating tools (navigate/click/type/evaluate) route through the gate. Alternative servers. A user-defined mcpServers entry named browser takes precedence over the preset, so you can point at any other server:
  • chrome-devtools-mcp (Google, CDP) — best for Chrome debugging / performance traces / network inspection, or driving your real logged-in Chrome. Chrome-only; a good alternative, not a better default.
  • Stagehand (Browserbase) — natural-language act/extract/observe, robust to layout drift.
  • Browserbase — managed cloud browser (CDP-as-a-service).

Computer use

Computer-use drives your real desktop — that is the point, so it is not sandboxed. Enable it explicitly:
The daemon synthesizes a computer MCP server. The default targets the cross-platform AB498/computer-control-mcp (PyAutoGUI + OCR, via uvx); override command/args to use another (e.g. MCPControl, or a sandboxed/remote desktop like trycua / e2b desktop).

Security model: host-escape (the sanctioned exception)

Monad’s default posture is contain the agent. Computer-use can’t be contained — it moves the real mouse/keyboard — so it is treated as a host-escape capability, the same class as code_execute running on the host. The exception is explicit and bounded, not silent:
  • Read-only tools (screenshot, cursor, screen size, window list) are auto-approved.
  • Mutating tools (click/type/drag/key/scroll) are tagged with the host-control gate key (trust.hostEscape: true on the server).
  • The approval engine treats host-control as a class grant: one “control this computer for this session” approval covers all mutating actions (no per-click prompt), and it expires with the session.
  • A host-control allow can never persist beyond session scope — no permanent global/agent “always allow” — the daemon refuses to persist that grant. A deny at any scope always wins, so an operator can hard-disable it.
Compensating controls (since there’s no containment): the active grant is visible and revocable via the approvals panel. Never run computer-use unattended on untrusted content — on-screen text can prompt-inject the agent. High-stakes actions stay always-ask. A deny rule wins over any allow at every scope, so an operator can carve dangerous actions out of the session grant. Recommended baseline in agents.json (tool names track your chosen server; adjust to match):
Mirroring the computer-use MCP’s own rule: do not execute trades, place orders, or move money on the user’s behalf — keep those, and irreversible/destructive actions, on explicit per-action approval (or deny them outright and have the user perform them).

Provider-native acceleration (optional)

A tool may declare a provider-native binding (ToolSpec.providerTool); when the active provider matches, the adapter emits the provider’s built-in tool instead of a generic function tool. For Claude this means the trained computer_20250124/computer_20251124 tool. The portable generic path is the fallback, so GPT/Gemini still work. Wiring a synthetic computer tool that maps the native action set onto a chosen server’s tools is future work.