Skip to content
Back to skills

Jaw Desktop Control

ASecurity

Unified desktop + browser automation. Routes DOM targets to CDP (cli-jaw browser), desktop apps to Computer Use, hybrid combos to both. Codex desktop/CLI required for Computer Use; macOS is app-scoped and Windows is window-scoped.

  • 4 stars
  • 0 votes
  • 0 copies
  • 1 view
  • Added September 5, 2026
toolsgodocker

Works with

  • cursor
  • cli

Security analysis

A100/100

Pro scans all 6 files and shows the line behind each finding

Scanned September 22, 2026

npx -y skills add lidge-jun/cli-jaw-skills --skill jaw-desktop-control --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Jaw Desktop Control?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Jaw Desktop Control
[![Security: A β€” Skills Directory](https://www.skillsdirectory.com/api/skills/lidge-jun-jaw-desktop-control/badge)](https://www.skillsdirectory.com/skills/lidge-jun-jaw-desktop-control)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: jaw-desktop-control
description: "Unified desktop + browser automation. Routes DOM targets to CDP (cli-jaw browser), desktop apps to Computer Use, hybrid combos to both. Codex desktop/CLI required for Computer Use; macOS is app-scoped and Windows is window-scoped."
metadata:
  {
    "openclaw":
      {
        "emoji": "πŸ–₯️",
        "requires":
          { "bins": ["cli-jaw"], "system": ["Google Chrome"] },
        "install":
          [
            {
              "id": "brew-cliclick",
              "kind": "brew",
              "formula": "cliclick",
              "bins": ["cliclick"],
              "label": "Install cliclick (optional β€” pointer-action fallback)",
            },
          ],
      },
  }
---

# Desktop Control

Unified skill for all UI automation. Chooses between CDP and Computer Use based on the target, and reports meaningful actions with a `path=` + `action_class=` transcript.

> **This skill is already injected into your system prompt.** Do not run `sed`, `cat`, `head`, or `Read` to load it from disk. Guessing absolute paths like `/Users/*/.codex/skills/...` or `/Users/*/.cli-jaw-*/skills/...` wastes a turn and often targets a file that doesn't exist. If you need a specific reference file (e.g., `reference/computer-use.md`), use `cli-jaw skill read jaw-desktop-control <ref-name>`.

## When to use

Trigger on any request that touches a visible UI:

- **User message contains `$computer-use` or `/computer-use`** β†’ **skip routing analysis**, jump straight to [`reference/computer-use.md`](reference/computer-use.md). Explicit user opt-in. If Computer Use tools are not available, stop with `precondition failed: computer-use unavailable`.
- "open this URL / click this button / type in this field" β†’ read [`reference/cdp.md`](reference/cdp.md)
- "switch Chrome tab / open Finder / click System Settings" β†’ read [`reference/computer-use.md`](reference/computer-use.md)
- "click the thing inside this Canvas / WebGL / iframe" β†’ read [`reference/vision-click.md`](reference/vision-click.md)
- Not sure which path β†’ read [`reference/intent-routing.md`](reference/intent-routing.md) FIRST
- Want a real end-to-end example β†’ read [`reference/control-workflow.md`](reference/control-workflow.md)

## Absolute rules

1. **Announce the path before acting.** First line of every task must be `path=cdp`, `path=computer-use`, or `path=cdp+cu`.
2. **Computer Use always starts each assistant turn with a state read before interacting.** Re-read on stale warnings, after actions that change UI state, and whenever confidence drops.
3. **Every meaningful action records an `action_class`.** Classes: `state-read`, `element-action`, `value-injection`, `keyboard-action`, `pointer-action`, `pointer-action+vision`, `scroll-action`, `drag-action`, `secondary-action`.
4. **Never fall back silently.** If the required path is unavailable, stop and report which precondition failed.
5. **Never claim the cursor was visible.** Cursor overlay is best-effort in the current build.
6. **When uncertain, take a screenshot FIRST.** If you ever find yourself guessing β€” "is that tab 342 or 357?", "did the click actually land?", "is this the right page?" β€” **stop** and re-ground via the platform's state read (Computer Use) or `cli-jaw browser snapshot` (CDP). Never chain actions through uncertainty. Guessing indices or URLs leads to infinite correction loops. If two consecutive actions produced ambiguous state, the **next call must be a state-read**, not another action.

## Preconditions (Computer Use path)

- macOS or Windows. Linux, WSL, and Docker have no Computer Use host β€” use CDP there.
- **The tool surface belongs to the host and changes between versions β€” do not assume tool names.** Read [`reference/computer-use.md`](reference/computer-use.md) before the first call: it explains how to establish the surface from what is actually exposed, and why an enabled plugin is not proof its tools are callable.
- macOS Computer Use is app-scoped: select an app, then read its state. Windows is window-scoped: enumerate windows, then read one window's state.
- On Windows an enumeration that answers proves nothing about the connection, and an empty window list usually means the transport is not connected rather than that no windows are open.
- If packaged through cli-jaw, `/Applications/Jaw.app` and `/Applications/Codex Computer Use.app` may be required for TCC attribution. Missing app bundles are a setup issue, not a reason to silently switch paths.
- macOS: TCC Accessibility and AppleEvents must be granted to the controlling app.
- Windows: the Codex desktop app must be running in the logged-on session β€” it creates the named pipe. A locked screen is fine; logged out is not.

## Transcript format (standard)

CDP action:

```
path=cdp
url=https://example.com
action=click e3
result=ok
```

Computer Use action:

```
path=computer-use
app=Google Chrome
action_class=element-action
action=click(element_index=730)
stale_warning=no
result=ok
```

Hybrid (lookup via CDP, action via Computer Use):

```
path=cdp+cu
lookup=cli-jaw browser snapshot β†’ bbox of "Play"
action_class=pointer-action
action=click(x=812, y=514)
result=ok
```

## Related skills

- `browser` β€” CDP command reference (this skill supersedes its coverage).
- `screen-capture` β€” generic macOS screenshot / webcam / video recording (unchanged).
- `vision-click` β€” **no longer auto-active**. Absorbed as a tactic in `reference/vision-click.md`. If you need the low-level recipe (NDJSON parsing, DPR correction), run `cli-jaw skill install vision-click`.

## Common failures and the only correct responses

| Symptom | Correct report |
|---|---|
| "I don't see a cursor" | `cursor overlay is best-effort in the current build β€” action=click(...) succeeded; visible cursor not guaranteed` |
| CDP server not running | `precondition failed: cli-jaw serve not running. Start with 'jaw serve' and retry.` |
| Computer Use tools missing | `precondition failed: computer-use unavailable` |
| cli-jaw CU app missing in packaged install | `precondition failed: /Applications/Codex Computer Use.app missing. Recover: jaw doctor --tcc --fix` |
| Stale warning on action | re-read state then retry; log `stale_warning=yes` in the transcript |
| Non-GUI task routed here | `needs boss follow-up: not GUI automation` |

Files in this skill

  • SKILL.md6.6 KB
  • reference/cdp.md2.5 KB
  • reference/computer-use.md10.6 KB
  • reference/control-workflow.md4.8 KB
  • reference/intent-routing.md3.6 KB
  • reference/vision-click.md3.5 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…