复制下面这句话,粘贴给 Claude Code、Codex、Cursor 等 AI 编程工具,它会读取安装说明并在你确认后完成安装。
请阅读 https://ai.atlankj.com/install/asset/gh-computer-use-a83a7245a0a1 ,按照其中的说明把「computer-use」安装到你(当前 AI 工具)中。执行前先告诉我将运行的命令和写入的位置,等我确认。
查看 AI 将读取的安装说明正在读取 GitHub 原文…
内容来自 GitHub 原始文件,由原作者维护。在 GitHub 查看
You have a computer_use tool that drives the user's desktop in the
background — your actions do NOT move the user's cursor, steal
keyboard focus, or switch virtual desktops / Spaces. The user can keep
typing in their editor while you click around in a browser in another
window. This is the opposite of pyautogui-style automation.
Everything here works with any tool-capable model — Claude, GPT, Gemini, or an open model on a local OpenAI-compatible endpoint. There is no Anthropic-native schema to learn.
Hermes drives cua-driver under the hood.
This skill teaches the Hermes computer_use action vocabulary, which is
NOT the driver's raw MCP vocabulary. Call the actions documented below and
never the driver's tools by name: capture is a Hermes action that maps to
the driver's get_window_state; element=N is a Hermes argument that the
wrapper translates into the driver's element_token handle. If you see a
driver-side error mentioning snapshot_id, element_token, or "no reviewed
risk classification", you (or a stale description) called the raw driver
vocabulary — go back to the actions below.
Step 1 — Capture first. Almost every task starts with:
computer_use(action="capture", mode="som", app="<the app you're driving>")
Returns a screenshot plus an indexed element list like:
#1 AXButton 'Back' @ (12, 80, 28, 28) [Chrome]
#2 AXTextField 'Address bar' @ (80, 80, 900, 32) [Chrome]
#7 Link 'Sign In' @ (900, 420, 80, 24) [Chrome]
...
The #N index is the ONLY element handle you use. Behind it the wrapper
keeps this snapshot's opaque per-element token and sends it with every
element=N action, so a click on an index from a superseded snapshot is
refused explicitly (stale) instead of landing on the wrong control.
Re-capture after anything that changes the screen; indices do not survive it.
The role names match the host platform's accessibility framework
(AXButton on macOS, Button on Windows UIA, push button on Linux
AT-SPI) — treat them as labels, not as strict types.
Step 2 — Click by element index. This is the single most important habit:
computer_use(action="click", element=7)
Much more reliable than pixel coordinates for every model. Claude was trained on both; other models are often only reliable with indices.
Step 3 — Verify. After any state-changing action, re-capture. You can save a round-trip by asking for the post-action capture inline:
computer_use(action="click", element=7, capture_after=True)
mode | Returns | Best for |
|---|---|---|
som (default) | Screenshot + indexed element list | Vision models; preferred default |
vision | Plain screenshot, no elements | When you only need pixels (then click by coordinate=) |
ax | Element list only, no image | Text-only models, or when you don't need to see pixels |
Current drivers always return the screenshot AND the tree in one call;
mode decides what Hermes hands back to you, not what the driver does.
There is no numbered overlay burned into the screenshot — the index list is
the map; ground on both and cross-check (the tree lies on some surfaces).
No vision model? If your main model can't read images (or the provider
rejects image tool results), Hermes routes the screenshot through the
auxiliary vision model and you get a text description instead of pixels.
Configure auxiliary.vision in config.yaml to pick that model, or use
mode="ax" and drive by element index without a screenshot at all.
capture mode=som|vision|ax app=… (default: current app)
click element=N OR coordinate=[x, y] button=left|right|middle
double_click element=N OR coordinate=[x, y]
right_click element=N OR coordinate=[x, y]
middle_click element=N OR coordinate=[x, y]
drag from_element=N, to_element=M (or from/to_coordinate)
scroll direction=up|down|left|right amount=3 (ticks)
type text="…"
key keys="<save shortcut>" | "return" | "escape" | "<modifier>+t"
set_value element=N value="…" (selects/sliders without opening the menu)
wait seconds=0.5
list_apps
list_windows
focus_app app="<app name>" raise_window=false (default: don't raise)
All actions accept optional capture_after=True to get a follow-up
screenshot in the same tool call. All actions that target an element
accept modifiers=[…] for held keys.
The input actions (click, double_click, right_click, middle_click,
drag, scroll, type, key) also accept delivery_mode. The optional
bring_to_front=True request invokes a separately approved standalone focus
tool before foreground input; it is never an input-action property.
cua-driver delivers input in the background by default (no focus steal), but that is the first rung, not the only one. Every input action returns a structured verdict; read it and climb only when the driver tells you to.
Returned fields (present when the driver supports them):
effect: "confirmed" (driver read the result back — done), "unverifiable"
(delivered, but confirm it yourself by re-capturing), or "suspected_noop"
(ran but almost certainly did nothing).escalation: {recommended: "px" | "foreground", reason} — present
only when there's a next rung to try.code: a structured refusal like "background_unavailable",
"foreground_unsupported", or "stale" (re-capture, then retry by index).verified: true only on AX read-back.Walk it in order:
click(element=N). If effect:"confirmed",
you're done.effect:"unverifiable" means inspect a fresh
capture/state before any retry. Do this even when escalation.recommended
is present; it is advisory, not proof that successful input should repeat.effect:"suspected_noop" or a structured
refusal recommends "px" (or a degraded capture has no elements), click
by coordinate=[x,y] instead of element.effect:"suspected_noop",
code:"background_unavailable", or a verified pixel no-op,
re-issue the SAME action with delivery_mode="foreground". This briefly
raises the window and restores focus after; pair with bring_to_front=True
for a short sequence to avoid per-call flashes. It needs its own approval
(it's a visible focus change) and is only appropriate when the user isn't
actively working. Classic cases: Electron/Chromium consent dialogs (e.g.
tldraw offline's "Run Script"), DirectInput games, raw-input canvases.type reports ok
("Typed N characters into the focused widget", effect:"unverifiable")
but a fresh AX capture shows the text never arrived, and raw XTest fails
identically (proven live, Aug 2026 — it is the toolkit, not the driver;
the same foreground route works on kcalc/Chrome). After ONE such
verified-lost round trip, stop retrying input rungs: write the file with
terminal/file tools and let the editor reload it, or drive the app's
DBus/CLI interface. Never loop the ladder against a surface that
verifiably swallows synthetic input.computer_use(action="click", element=7)
# → {effect: "suspected_noop", escalation: {recommended: "foreground", ...}}
computer_use(action="click", element=7, delivery_mode="foreground")
# → {effect: "unverifiable", path: "x11_pixel_fg"} then re-capture to confirm
Escalate to foreground as a REACTION to a returned signal, never as a
prediction from the app being Electron/Chromium/GTK. A confirmed effect is
done and must not be duplicated. Different controls in
the same app behave differently. Do NOT silently retry the same rung, and do
NOT conclude "cua-driver can't drive this app" — climb the ladder. If
delivery_mode="foreground" returns code:"foreground_unsupported", the live
action schema lacks that property; choose another verified rung without
inferring support from the executable's reported version.
computer_use is desktop-only: it does not expose a typed route for browser
page content (no cua_browser_* actions). For reading or acting on a page's
DOM — navigation, clicking a link by text, typed input into a form field —
use the separate browser_navigate/browser_click/browser_type/browser_snapshot
tools (or browser_exec when the Browser Use CLI backend is active); their
own schemas document the current contract. Reserve computer_use for browser
chrome (the address bar, permission prompts, extension popups, native
dialogs) and anything else on screen that isn't page content.
Use the host's idiomatic modifier:
| Common action | macOS | Windows / Linux |
|---|---|---|
| Save | cmd+s | ctrl+s |
| New tab | cmd+t | ctrl+t |
| Close tab / window | cmd+w | ctrl+w |
| Copy / paste | cmd+c / cmd+v | ctrl+c / ctrl+v |
| Address bar | cmd+l | ctrl+l |
| App switcher | cmd+tab | alt+tab |
When in doubt, capture and look for menu hints, or ask the user which shortcut to use.
raise_window=True unless the user explicitly asked you
to bring a window to front. Input routing works without raising.app="Chrome") — less noisy, fewer
elements, doesn't leak other windows the user has open.Prefer element indices:
computer_use(action="drag", from_element=3, to_element=17)
For a rubber-band selection on empty canvas, use coordinates:
computer_use(action="drag",
from_coordinate=[100, 200],
to_coordinate=[400, 500])
Scroll the viewport under an element (most common):
computer_use(action="scroll", direction="down", amount=5, element=12)
Or at a specific point:
computer_use(action="scroll", direction="down", amount=3, coordinate=[500, 400])
list_apps returns running apps with bundle IDs / process names, PIDs,
and window counts. focus_app routes input to an app without raising
it. You rarely need to focus explicitly — passing app=... to
capture will target that app's frontmost window and every following
input action goes to that same window (input actions ignore app=).
When the user is on a messaging platform (Telegram, Discord, etc.) and
you took a screenshot they should see, save it somewhere durable and
use MEDIA:/absolute/path.png in your reply. cua-driver's screenshots
are PNG or JPEG bytes (mimeType is on the response); write them out
with write_file or the terminal (base64 -d).
On CLI, you can just describe what you see — the screenshot data stays in your conversation context.
type. You'll see an
error if the guard fires.| Symptom | Likely cause + remedy |
|---|---|
cua-driver not installed | Run hermes computer-use install, or hermes tools and enable Computer Use |
| Captures consistently return empty / "no on-screen window" | On Linux: DISPLAY may not be set (X11) or you're on pure Wayland — ask the user to run hermes computer-use doctor. On Windows: you may be in Session 0 (SSH session) instead of the interactive desktop — see the cua-driver WINDOWS.md deep-dive |
code:"stale" / "element_token is stale" | Indices belong to one snapshot. Re-capture, read the new indices, then act. Never reuse an index across a capture |
"bare element_index is not accepted" / snapshot_id_required | The driver saw a raw index without its token. This is a wrapper defect, not something you fix by passing snapshot_id (Hermes has no such argument). Re-capture once; if it repeats, tell the user to run hermes update and fall back to coordinate=[x, y] from the capture's bounds meanwhile |
"tool 'capture' has no reviewed risk classification" / Unknown tool | Something called the driver's MCP vocabulary directly (capture, screenshot, get_window_state, click with raw args). Only the computer_use(action=…) vocabulary in this file exists on the Hermes side |
| Click had no effect | Read the structured verdict. effect:"unverifiable" → fresh capture/state before retry, even with an escalation hint. effect:"suspected_noop" or a structured refusal → climb the recommended ladder: coordinate (px), then foreground. Browser chrome/native prompts remain native; page content is a separate toolset. Don't conclude the app is undrivable |
| Type text disappears into a terminal emulator | cua-driver detects terminals (Ghostty, iTerm2, Terminal.app, Windows Terminal, mintty, etc.) and routes through key-event synthesis — should "just work" on a recent cua-driver. If it doesn't, ask the user to run hermes computer-use doctor |
blocked pattern in type text | You tried to type a shell command matching the dangerous-pattern block list (curl ... | bash, sudo rm -rf, etc.). Break the command up or reconsider |
| says "could not be started … Access is denied" (Windows) |
computer_usebrowser_* tools — those use a
real headless Chromium and are more reliable than driving the user's
GUI browser. Reach for computer_use specifically when the task
needs the user's actual native apps (Finder/Explorer/Files, Mail/
Outlook/Thunderbird, native chat clients, Figma, Logic, games,
anything non-web).read_file / write_file / patch, not
type into an editor window.terminal, not type into Terminal.app /
Windows Terminal / gnome-terminal.Hermes intentionally keeps THIS skill focused on the Hermes-side
computer_use action vocabulary. The platform-specific deep dives
(macOS no-foreground contract, Windows UIA + Session 0, Linux AT-SPI +
X11/Wayland nuances, recording trajectory + video, browser-page
interaction, etc.) live in cua-driver's skill pack — same content the
cua-driver team ships and maintains for every other agent harness.
cua-driver skills install
links the pack into ~/.hermes/skills/cua-driver (Hermes is a detected
agent; cua-driver skills status shows the link state). You'll then have:
SKILL.md — the cross-platform core (snapshot invariant, no-
foreground contract, click dispatch, AX tree mechanics)MACOS.md — macOS specifics (no-foreground contract, AXMenuBar
navigation, SkyLight click dispatch, Apple Events JS bridge)WINDOWS.md — Windows specifics (UIA tree, UWP / ApplicationFrameHost
hosting, Session 0 isolation, autostart pattern for SSH)LINUX.md — Linux specifics (AT-SPI tree, X11 / Wayland, terminal
emulator detection)RECORDING.md — trajectory + video recording semanticsWEB_APPS.md — browser page interaction tipsTESTS.md — replay-by-trajectory workflowThose files describe the driver's OWN MCP tools (get_window_state,
element_token, snapshot_id, …). Read them for platform context; keep
calling the Hermes actions from this file — the wrapper does the translation.
hermes computer-use doctorThe Hermes venv interpreter can't execute a binary under C:\Program Files\WindowsApps; the tool itself may still work because the shell resolves another copy on PATH. Fix once: reinstall cua-driver with the upstream installer (lands under the user profile) or set HERMES_CUA_DRIVER_CMD to a copy outside WindowsApps. The same denial spams errors.log for any other WindowsApps binary Hermes spawns (e.g. bws.exe) |
| Anything else weird | First action: ask the user to run hermes computer-use doctor. It runs the cua-driver health_report MCP tool and prints a structured per-check matrix. Their output tells you (and them) exactly what's wrong |