Independent use will determine whether Hands provides reliable and safely constrainable OS-level Windows and real-Chrome control for coding agents.
state: expiredheat: lowuncertainty: highconvergesscott: mediumcomputer-use agent-harnesses agentic-security
What is this?
Hands is presented as a Rust MCP/CLI tool that lets coding agents observe and control the Windows desktop, including clicking in real Chrome. The supplied material claims OS-level containment through Microsoft Execution Container and debugging through DAP, but the snippets do not identify its creator or independently establish Hands’ reliability, Chrome support, or safety; an early commit explicitly said “No Chrome,” suggesting that capability was added later. Independent use and evaluation therefore remain necessary to determine whether its current controls are dependable and safely constrainable.
Why it matters to Scott
Hands’ claimed pairing of MCP-based observation/action with OS-level containment converges with Scott’s “hands and eyes” and SiloOS position that capable agents need structural boundaries, not protocol-level trust. If independently validated, its Windows and real-Chrome control could extend Scott’s MCP and disposable-Windows work; currently the thin evidence and unverified safety claims limit it to an evaluation target rather than a changed conclusion.
ip:source.mcp-as-the-tool-belt-standard-giving-ai-agents-hands-and-eyes-ebookip:framework.siloosdev:project.fde-bidev:technology.proxmox-veradar:agent-desktop-accessibility-automationradar:concept.computer-useradar:concept.agent-securityradar:concept.agent-harnesses
queries asked of Scott's wikis
- Windows computer-use harnesses for coding agents
- OS-level containment versus tool permission controls
- real-browser automation versus browser APIs
- computer-use reliability and verification loops
- agent desktop-control threat models
- MCP tools for GUI observation and action
Measured heat
no measured readings yet — the hourly heat pass fills this in
How the heat travelled
no chain yet — the hourly chain pass fills this in
Evidence (2) — ⭐ canonical anchor
Interpretation history
2026-08-25T02:26:55Z
No independent use or safety evaluation emerged within the monitoring window; the small score increase is discovery without validation. Hands remains an unverified prototype, but this episode no longer merits active tracking absent a substantive update.
2026-08-23T01:28:38Z
No independent use, implementation evidence, or safety evaluation has appeared; Hands remains a first-party prototype whose reliability and containment claims are unverified. The unchanged, minimal discussion lowers near-term attention without changing the evaluation target.
2026-08-23T01:27:12Z
grounded: converges/medium — Hands’ claimed pairing of MCP-based observation/action with OS-level containment converges with Scott’s “hands and eyes” and SiloOS position that capable agents
2026-08-23T01:25:09Z
origin walked (codex/luna, conf 0.98): anchor hn.story.49405405 -> echo.github.30a3bdcfda by Ryan (Ryan-AI-Studios)
2026-08-23T01:23:48Z
case created — The first-party Show HN describes a concrete Rust MCP/CLI artifact for screenshot, UI Automation, input, and real-browser control.
Decision trace
- 08-25 12:26expireNo independent use or safety evaluation emerged within the monitoring window; the small score increase is discovery without validation. Hands remains an unverified prototype, but this episode no longe
- 08-25 12:26alert_silentThe only delta is a minor engagement increase with no comments, independent testing, or product change, so there is nothing consequential to surface.
- 08-25 12:26alert_routeThe only delta is a minor engagement increase with no comments, independent testing, or product change, so there is nothing consequential to surface.
- 08-23 11:28repriceNo independent use, implementation evidence, or safety evaluation has appeared; Hands remains a first-party prototype whose reliability and containment claims are unverified. The unchanged, minimal di
- 08-23 11:28alert_silentThis reobservation adds no consequential delta beyond the already-known prototype release, so it can wait for independent testing or a substantive product update.
- 08-23 11:28alert_routeThis reobservation adds no consequential delta beyond the already-known prototype release, so it can wait for independent testing or a substantive product update.
- 08-23 11:27alert_silentA first-party prototype now exists, but the evidence is limited to the author’s description and repository history, with no independent reliability or containment results. It explicitly is not a sandb
- 08-23 11:27surface_candidateA first-party prototype now exists, but the evidence is limited to the author’s description and repository history, with no independent reliability or containment results. It explicitly is not a sandb
- 08-23 11:27alert_routeA first-party prototype now exists, but the evidence is limited to the author’s description and repository history, with no independent reliability or containment results. It explicitly is not a sandb
- 08-23 11:27groundHands’ claimed pairing of MCP-based observation/action with OS-level containment converges with Scott’s “hands and eyes” and SiloOS position that capable agents need structural boundaries, not protoco
- 08-23 11:25promote_anchororigin walk conf 0.98
- 08-23 11:23createThe first-party Show HN describes a concrete Rust MCP/CLI artifact for screenshot, UI Automation, input, and real-browser control.