Release notes
The agent's terminal and browser stay honest
The agent's terminal and browser now report what is actually happening: the line it submits is the line the shell is holding, a password prompt is never typed into, and a browser still is never reused after the page has moved on.
Improved
- The agent's terminal checks the whole line before submitting, including anything you typed while you held it. If a key rewrote the line in a way it cannot see (history recall, cursor movement, completion), it asks before running it.
- A password prompt is never typed into. Ctrl-C stays available so the agent can back out instead of getting stuck.
- If you take the terminal back after the agent sent a line, it is told the line was sent so it does not send it twice.
- A terminal the agent opened in another chat no longer shows its banner in yours, and closing a terminal clears its state.
- Modifier shortcuts (⌘S, ⌘C, ⌘F) no longer pause the agent by taking the terminal back, and the find bar stays out of the way.
- A paused terminal shows a "hand this terminal back" bar.
- A remote terminal reports where the shell actually starts instead of a path it is not in.
Fixed
- A browser still captured before the last navigation is never reused, so a parked pane cannot show the previous page.
- Reading the page's DOM is gated like the console and network views, and typing into whatever the page has focused is treated as sensitive as a screenshot click.
- A browser control handoff applies in one step, gives up with a message if it never answers, and taking control always means you have it.
- Back and forward start disabled until the page says otherwise, and Escape reverts to the last committed address.
- The agent overlay stays out of the way while a question is on screen, and only a left-click takes the browser over.
- A bare element ref explains that it is missing its snapshot generation instead of being read as a selector.
- A pinch-zoomed page clamps clicks into the right box.