Latest commit

History

1 Commit

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

HumanHands

An AI agent that operates a Mac the way a person does. It perceives the screen through the macOS Accessibility tree, decides the next move with Claude, and drives the real, visible cursor along a human-like path, typing with human cadence, instead of teleporting the pointer.

Built in 2026 as a personal project. Fully native Swift, macOS 14+, no Electron, no browser extension.

Why it exists

Surveying computer-use agents in 2026 showed an empty intersection: the real-OS agents teleported the pointer and had no concept of credentials; the tools with real secret vaults were browser-only; and the human-motion libraries had never been wired to an LLM. HumanHands is the glue between those three.

Three design calls

1. Perceive through the Accessibility tree, not screenshots. The AX tree is local, free and pixel-exact. The agent grounds every action in element geometry, so screen data never leaves the machine and the loop runs on a Claude subscription through the CLI (claude setup-token) at zero API cost. Vision is kept only as a concurrent fallback when the tree is missing or wrong.

2. Learn by compression, not gradients. A hosted model cannot be fine-tuned, and the agent kept stumbling on the same spots. After reading the agent-memory literature (Reflexion, ExpeL, Voyager, Agent Workflow Memory, Skyvern's learn-once-replay), the design became: distil each messy successful run into a clean reusable recipe plus its gotchas, inject that as guidance next time, and once a path proves stable graduate it into a deterministic macro that replays with no model calls and only wakes the model when the screen diverges. A traversed path compressed into a reflex.

3. Keep secrets structurally out of the model. Real credentials live in the Keychain and reach the model only as placeholder tokens that are substituted at the last instant, in the executor. A domain-verified gate refuses to type a secret unless the genuine site is confirmed. User-owned app and site allowlists bound what the agent can touch. TOTP generation, a redaction registry, a tripwire and a kill switch sit in the same ring.

Architecture

Ring-layered SwiftPM targets; every OS primitive sits behind a protocol so the logic rings test off-device.

RingTargetRole
0HHCorePure value types, no OS dependencies
0HHOSBridgeOS-touching primitives (CGEvent, AX, ScreenCaptureKit, Keychain) behind protocols
1HHExecutionHumanised executor: WindMouse paths, Fitts' law timing, typing cadence
1HHPerceptionPerception geometry, the single coordinate chokepoint
1HHSecretsVault, placeholder substitution, TOTP, redaction, tripwire
1HHSafetyDomain-verified site gate
2HHSitesPer-site profiles: allowlist + playbook
2HHAgentProvider abstraction and the perceive → decide → act loop
3HHRuntimeShared engine and structured event stream used by both front-ends
humanhandsCLI: preflight, capture, run
HumanHandsAppSwiftUI app: a window that runs a goal
HHTests135 pure-logic tests, run off-device

Build and run

swift build
swift test# 135 tests, no device access needed
Scripts/build-app.sh # builds and signs HumanHands.app into dist/# reasoning provider: either a Claude subscription token or an API key
claude setup-token &&export ANTHROPIC_AUTH_TOKEN='sk-ant-oat...'# orexport ANTHROPIC_API_KEY='sk-ant-api...'
.build/debug/humanhands preflight # checks Accessibility and Screen Recording permissions
.build/debug/humanhands run "open Safari and search for the TU/e library opening hours"

macOS will ask for Accessibility (and, for the vision fallback, Screen Recording) permission the first time. Nothing runs outside the allowlists you configure.

Status

Working personal tool, not a product. Things that are deliberately not here: cloud relays, telemetry, credential sync, anything that would move screen contents or secrets off the machine.

Author: Pulkit Chawla · linkedin.com/in/pulkitchawla11

About

An AI agent that operates a Mac the way a person does: Accessibility-tree perception, human-like cursor paths, Keychain-backed secrets that never reach the model. Native Swift.

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Latest commit

History

1 Commit

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

HumanHands

An AI agent that operates a Mac the way a person does. It perceives the screen through the macOS Accessibility tree, decides the next move with Claude, and drives the real, visible cursor along a human-like path, typing with human cadence, instead of teleporting the pointer.

Built in 2026 as a personal project. Fully native Swift, macOS 14+, no Electron, no browser extension.

Why it exists

Surveying computer-use agents in 2026 showed an empty intersection: the real-OS agents teleported the pointer and had no concept of credentials; the tools with real secret vaults were browser-only; and the human-motion libraries had never been wired to an LLM. HumanHands is the glue between those three.

Three design calls

1. Perceive through the Accessibility tree, not screenshots. The AX tree is local, free and pixel-exact. The agent grounds every action in element geometry, so screen data never leaves the machine and the loop runs on a Claude subscription through the CLI (claude setup-token) at zero API cost. Vision is kept only as a concurrent fallback when the tree is missing or wrong.

2. Learn by compression, not gradients. A hosted model cannot be fine-tuned, and the agent kept stumbling on the same spots. After reading the agent-memory literature (Reflexion, ExpeL, Voyager, Agent Workflow Memory, Skyvern's learn-once-replay), the design became: distil each messy successful run into a clean reusable recipe plus its gotchas, inject that as guidance next time, and once a path proves stable graduate it into a deterministic macro that replays with no model calls and only wakes the model when the screen diverges. A traversed path compressed into a reflex.

3. Keep secrets structurally out of the model. Real credentials live in the Keychain and reach the model only as placeholder tokens that are substituted at the last instant, in the executor. A domain-verified gate refuses to type a secret unless the genuine site is confirmed. User-owned app and site allowlists bound what the agent can touch. TOTP generation, a redaction registry, a tripwire and a kill switch sit in the same ring.

Architecture

Ring-layered SwiftPM targets; every OS primitive sits behind a protocol so the logic rings test off-device.

RingTargetRole
0HHCorePure value types, no OS dependencies
0HHOSBridgeOS-touching primitives (CGEvent, AX, ScreenCaptureKit, Keychain) behind protocols
1HHExecutionHumanised executor: WindMouse paths, Fitts' law timing, typing cadence
1HHPerceptionPerception geometry, the single coordinate chokepoint
1HHSecretsVault, placeholder substitution, TOTP, redaction, tripwire
1HHSafetyDomain-verified site gate
2HHSitesPer-site profiles: allowlist + playbook
2HHAgentProvider abstraction and the perceive → decide → act loop
3HHRuntimeShared engine and structured event stream used by both front-ends
humanhandsCLI: preflight, capture, run
HumanHandsAppSwiftUI app: a window that runs a goal
HHTests135 pure-logic tests, run off-device

Build and run

swift build
swift test# 135 tests, no device access needed
Scripts/build-app.sh # builds and signs HumanHands.app into dist/# reasoning provider: either a Claude subscription token or an API key
claude setup-token &&export ANTHROPIC_AUTH_TOKEN='sk-ant-oat...'# orexport ANTHROPIC_API_KEY='sk-ant-api...'
.build/debug/humanhands preflight # checks Accessibility and Screen Recording permissions
.build/debug/humanhands run "open Safari and search for the TU/e library opening hours"

macOS will ask for Accessibility (and, for the vision fallback, Screen Recording) permission the first time. Nothing runs outside the allowlists you configure.

Status

Working personal tool, not a product. Things that are deliberately not here: cloud relays, telemetry, credential sync, anything that would move screen contents or secrets off the machine.

Author: Pulkit Chawla · linkedin.com/in/pulkitchawla11

About

An AI agent that operates a Mac the way a person does: Accessibility-tree perception, human-like cursor paths, Keychain-backed secrets that never reach the model. Native Swift.

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Latest commit

History

1 Commit

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

HumanHands

An AI agent that operates a Mac the way a person does. It perceives the screen through the macOS Accessibility tree, decides the next move with Claude, and drives the real, visible cursor along a human-like path, typing with human cadence, instead of teleporting the pointer.

Built in 2026 as a personal project. Fully native Swift, macOS 14+, no Electron, no browser extension.

Why it exists

Surveying computer-use agents in 2026 showed an empty intersection: the real-OS agents teleported the pointer and had no concept of credentials; the tools with real secret vaults were browser-only; and the human-motion libraries had never been wired to an LLM. HumanHands is the glue between those three.

Three design calls

1. Perceive through the Accessibility tree, not screenshots. The AX tree is local, free and pixel-exact. The agent grounds every action in element geometry, so screen data never leaves the machine and the loop runs on a Claude subscription through the CLI (claude setup-token) at zero API cost. Vision is kept only as a concurrent fallback when the tree is missing or wrong.

2. Learn by compression, not gradients. A hosted model cannot be fine-tuned, and the agent kept stumbling on the same spots. After reading the agent-memory literature (Reflexion, ExpeL, Voyager, Agent Workflow Memory, Skyvern's learn-once-replay), the design became: distil each messy successful run into a clean reusable recipe plus its gotchas, inject that as guidance next time, and once a path proves stable graduate it into a deterministic macro that replays with no model calls and only wakes the model when the screen diverges. A traversed path compressed into a reflex.

3. Keep secrets structurally out of the model. Real credentials live in the Keychain and reach the model only as placeholder tokens that are substituted at the last instant, in the executor. A domain-verified gate refuses to type a secret unless the genuine site is confirmed. User-owned app and site allowlists bound what the agent can touch. TOTP generation, a redaction registry, a tripwire and a kill switch sit in the same ring.

Architecture

Ring-layered SwiftPM targets; every OS primitive sits behind a protocol so the logic rings test off-device.

RingTargetRole
0HHCorePure value types, no OS dependencies
0HHOSBridgeOS-touching primitives (CGEvent, AX, ScreenCaptureKit, Keychain) behind protocols
1HHExecutionHumanised executor: WindMouse paths, Fitts' law timing, typing cadence
1HHPerceptionPerception geometry, the single coordinate chokepoint
1HHSecretsVault, placeholder substitution, TOTP, redaction, tripwire
1HHSafetyDomain-verified site gate
2HHSitesPer-site profiles: allowlist + playbook
2HHAgentProvider abstraction and the perceive → decide → act loop
3HHRuntimeShared engine and structured event stream used by both front-ends
humanhandsCLI: preflight, capture, run
HumanHandsAppSwiftUI app: a window that runs a goal
HHTests135 pure-logic tests, run off-device

Build and run

swift build
swift test# 135 tests, no device access needed
Scripts/build-app.sh # builds and signs HumanHands.app into dist/# reasoning provider: either a Claude subscription token or an API key
claude setup-token &&export ANTHROPIC_AUTH_TOKEN='sk-ant-oat...'# orexport ANTHROPIC_API_KEY='sk-ant-api...'
.build/debug/humanhands preflight # checks Accessibility and Screen Recording permissions
.build/debug/humanhands run "open Safari and search for the TU/e library opening hours"

macOS will ask for Accessibility (and, for the vision fallback, Screen Recording) permission the first time. Nothing runs outside the allowlists you configure.

Status

Working personal tool, not a product. Things that are deliberately not here: cloud relays, telemetry, credential sync, anything that would move screen contents or secrets off the machine.

Author: Pulkit Chawla · linkedin.com/in/pulkitchawla11

About

An AI agent that operates a Mac the way a person does: Accessibility-tree perception, human-like cursor paths, Keychain-backed secrets that never reach the model. Native Swift.

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Latest commit

History

1 Commit

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

HumanHands

An AI agent that operates a Mac the way a person does. It perceives the screen through the macOS Accessibility tree, decides the next move with Claude, and drives the real, visible cursor along a human-like path, typing with human cadence, instead of teleporting the pointer.

Built in 2026 as a personal project. Fully native Swift, macOS 14+, no Electron, no browser extension.

Why it exists

Surveying computer-use agents in 2026 showed an empty intersection: the real-OS agents teleported the pointer and had no concept of credentials; the tools with real secret vaults were browser-only; and the human-motion libraries had never been wired to an LLM. HumanHands is the glue between those three.

Three design calls

1. Perceive through the Accessibility tree, not screenshots. The AX tree is local, free and pixel-exact. The agent grounds every action in element geometry, so screen data never leaves the machine and the loop runs on a Claude subscription through the CLI (claude setup-token) at zero API cost. Vision is kept only as a concurrent fallback when the tree is missing or wrong.

2. Learn by compression, not gradients. A hosted model cannot be fine-tuned, and the agent kept stumbling on the same spots. After reading the agent-memory literature (Reflexion, ExpeL, Voyager, Agent Workflow Memory, Skyvern's learn-once-replay), the design became: distil each messy successful run into a clean reusable recipe plus its gotchas, inject that as guidance next time, and once a path proves stable graduate it into a deterministic macro that replays with no model calls and only wakes the model when the screen diverges. A traversed path compressed into a reflex.

3. Keep secrets structurally out of the model. Real credentials live in the Keychain and reach the model only as placeholder tokens that are substituted at the last instant, in the executor. A domain-verified gate refuses to type a secret unless the genuine site is confirmed. User-owned app and site allowlists bound what the agent can touch. TOTP generation, a redaction registry, a tripwire and a kill switch sit in the same ring.

Architecture

Ring-layered SwiftPM targets; every OS primitive sits behind a protocol so the logic rings test off-device.

RingTargetRole
0HHCorePure value types, no OS dependencies
0HHOSBridgeOS-touching primitives (CGEvent, AX, ScreenCaptureKit, Keychain) behind protocols
1HHExecutionHumanised executor: WindMouse paths, Fitts' law timing, typing cadence
1HHPerceptionPerception geometry, the single coordinate chokepoint
1HHSecretsVault, placeholder substitution, TOTP, redaction, tripwire
1HHSafetyDomain-verified site gate
2HHSitesPer-site profiles: allowlist + playbook
2HHAgentProvider abstraction and the perceive → decide → act loop
3HHRuntimeShared engine and structured event stream used by both front-ends
humanhandsCLI: preflight, capture, run
HumanHandsAppSwiftUI app: a window that runs a goal
HHTests135 pure-logic tests, run off-device

Build and run

swift build
swift test# 135 tests, no device access needed
Scripts/build-app.sh # builds and signs HumanHands.app into dist/# reasoning provider: either a Claude subscription token or an API key
claude setup-token &&export ANTHROPIC_AUTH_TOKEN='sk-ant-oat...'# orexport ANTHROPIC_API_KEY='sk-ant-api...'
.build/debug/humanhands preflight # checks Accessibility and Screen Recording permissions
.build/debug/humanhands run "open Safari and search for the TU/e library opening hours"

macOS will ask for Accessibility (and, for the vision fallback, Screen Recording) permission the first time. Nothing runs outside the allowlists you configure.

Status

Working personal tool, not a product. Things that are deliberately not here: cloud relays, telemetry, credential sync, anything that would move screen contents or secrets off the machine.

Author: Pulkit Chawla · linkedin.com/in/pulkitchawla11

About

An AI agent that operates a Mac the way a person does: Accessibility-tree perception, human-like cursor paths, Keychain-backed secrets that never reach the model. Native Swift.

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Latest commit

History

1 Commit

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

HumanHands

An AI agent that operates a Mac the way a person does. It perceives the screen through the macOS Accessibility tree, decides the next move with Claude, and drives the real, visible cursor along a human-like path, typing with human cadence, instead of teleporting the pointer.

Built in 2026 as a personal project. Fully native Swift, macOS 14+, no Electron, no browser extension.

Why it exists

Surveying computer-use agents in 2026 showed an empty intersection: the real-OS agents teleported the pointer and had no concept of credentials; the tools with real secret vaults were browser-only; and the human-motion libraries had never been wired to an LLM. HumanHands is the glue between those three.

Three design calls

1. Perceive through the Accessibility tree, not screenshots. The AX tree is local, free and pixel-exact. The agent grounds every action in element geometry, so screen data never leaves the machine and the loop runs on a Claude subscription through the CLI (claude setup-token) at zero API cost. Vision is kept only as a concurrent fallback when the tree is missing or wrong.

2. Learn by compression, not gradients. A hosted model cannot be fine-tuned, and the agent kept stumbling on the same spots. After reading the agent-memory literature (Reflexion, ExpeL, Voyager, Agent Workflow Memory, Skyvern's learn-once-replay), the design became: distil each messy successful run into a clean reusable recipe plus its gotchas, inject that as guidance next time, and once a path proves stable graduate it into a deterministic macro that replays with no model calls and only wakes the model when the screen diverges. A traversed path compressed into a reflex.

3. Keep secrets structurally out of the model. Real credentials live in the Keychain and reach the model only as placeholder tokens that are substituted at the last instant, in the executor. A domain-verified gate refuses to type a secret unless the genuine site is confirmed. User-owned app and site allowlists bound what the agent can touch. TOTP generation, a redaction registry, a tripwire and a kill switch sit in the same ring.

Architecture

Ring-layered SwiftPM targets; every OS primitive sits behind a protocol so the logic rings test off-device.

RingTargetRole
0HHCorePure value types, no OS dependencies
0HHOSBridgeOS-touching primitives (CGEvent, AX, ScreenCaptureKit, Keychain) behind protocols
1HHExecutionHumanised executor: WindMouse paths, Fitts' law timing, typing cadence
1HHPerceptionPerception geometry, the single coordinate chokepoint
1HHSecretsVault, placeholder substitution, TOTP, redaction, tripwire
1HHSafetyDomain-verified site gate
2HHSitesPer-site profiles: allowlist + playbook
2HHAgentProvider abstraction and the perceive → decide → act loop
3HHRuntimeShared engine and structured event stream used by both front-ends
humanhandsCLI: preflight, capture, run
HumanHandsAppSwiftUI app: a window that runs a goal
HHTests135 pure-logic tests, run off-device

Build and run

swift build
swift test# 135 tests, no device access needed
Scripts/build-app.sh # builds and signs HumanHands.app into dist/# reasoning provider: either a Claude subscription token or an API key
claude setup-token &&export ANTHROPIC_AUTH_TOKEN='sk-ant-oat...'# orexport ANTHROPIC_API_KEY='sk-ant-api...'
.build/debug/humanhands preflight # checks Accessibility and Screen Recording permissions
.build/debug/humanhands run "open Safari and search for the TU/e library opening hours"

macOS will ask for Accessibility (and, for the vision fallback, Screen Recording) permission the first time. Nothing runs outside the allowlists you configure.

Status

Working personal tool, not a product. Things that are deliberately not here: cloud relays, telemetry, credential sync, anything that would move screen contents or secrets off the machine.

Author: Pulkit Chawla · linkedin.com/in/pulkitchawla11

About

An AI agent that operates a Mac the way a person does: Accessibility-tree perception, human-like cursor paths, Keychain-backed secrets that never reach the model. Native Swift.

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Latest commit

History

1 Commit

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

HumanHands

An AI agent that operates a Mac the way a person does. It perceives the screen through the macOS Accessibility tree, decides the next move with Claude, and drives the real, visible cursor along a human-like path, typing with human cadence, instead of teleporting the pointer.

Built in 2026 as a personal project. Fully native Swift, macOS 14+, no Electron, no browser extension.

Why it exists

Surveying computer-use agents in 2026 showed an empty intersection: the real-OS agents teleported the pointer and had no concept of credentials; the tools with real secret vaults were browser-only; and the human-motion libraries had never been wired to an LLM. HumanHands is the glue between those three.

Three design calls

1. Perceive through the Accessibility tree, not screenshots. The AX tree is local, free and pixel-exact. The agent grounds every action in element geometry, so screen data never leaves the machine and the loop runs on a Claude subscription through the CLI (claude setup-token) at zero API cost. Vision is kept only as a concurrent fallback when the tree is missing or wrong.

2. Learn by compression, not gradients. A hosted model cannot be fine-tuned, and the agent kept stumbling on the same spots. After reading the agent-memory literature (Reflexion, ExpeL, Voyager, Agent Workflow Memory, Skyvern's learn-once-replay), the design became: distil each messy successful run into a clean reusable recipe plus its gotchas, inject that as guidance next time, and once a path proves stable graduate it into a deterministic macro that replays with no model calls and only wakes the model when the screen diverges. A traversed path compressed into a reflex.

3. Keep secrets structurally out of the model. Real credentials live in the Keychain and reach the model only as placeholder tokens that are substituted at the last instant, in the executor. A domain-verified gate refuses to type a secret unless the genuine site is confirmed. User-owned app and site allowlists bound what the agent can touch. TOTP generation, a redaction registry, a tripwire and a kill switch sit in the same ring.

Architecture

Ring-layered SwiftPM targets; every OS primitive sits behind a protocol so the logic rings test off-device.

RingTargetRole
0HHCorePure value types, no OS dependencies
0HHOSBridgeOS-touching primitives (CGEvent, AX, ScreenCaptureKit, Keychain) behind protocols
1HHExecutionHumanised executor: WindMouse paths, Fitts' law timing, typing cadence
1HHPerceptionPerception geometry, the single coordinate chokepoint
1HHSecretsVault, placeholder substitution, TOTP, redaction, tripwire
1HHSafetyDomain-verified site gate
2HHSitesPer-site profiles: allowlist + playbook
2HHAgentProvider abstraction and the perceive → decide → act loop
3HHRuntimeShared engine and structured event stream used by both front-ends
humanhandsCLI: preflight, capture, run
HumanHandsAppSwiftUI app: a window that runs a goal
HHTests135 pure-logic tests, run off-device

Build and run

swift build
swift test# 135 tests, no device access needed
Scripts/build-app.sh # builds and signs HumanHands.app into dist/# reasoning provider: either a Claude subscription token or an API key
claude setup-token &&export ANTHROPIC_AUTH_TOKEN='sk-ant-oat...'# orexport ANTHROPIC_API_KEY='sk-ant-api...'
.build/debug/humanhands preflight # checks Accessibility and Screen Recording permissions
.build/debug/humanhands run "open Safari and search for the TU/e library opening hours"

macOS will ask for Accessibility (and, for the vision fallback, Screen Recording) permission the first time. Nothing runs outside the allowlists you configure.

Status

Working personal tool, not a product. Things that are deliberately not here: cloud relays, telemetry, credential sync, anything that would move screen contents or secrets off the machine.

Author: Pulkit Chawla · linkedin.com/in/pulkitchawla11

About

An AI agent that operates a Mac the way a person does: Accessibility-tree perception, human-like cursor paths, Keychain-backed secrets that never reach the model. Native Swift.

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Latest commit

History

1 Commit

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

HumanHands

An AI agent that operates a Mac the way a person does. It perceives the screen through the macOS Accessibility tree, decides the next move with Claude, and drives the real, visible cursor along a human-like path, typing with human cadence, instead of teleporting the pointer.

Built in 2026 as a personal project. Fully native Swift, macOS 14+, no Electron, no browser extension.

Why it exists

Surveying computer-use agents in 2026 showed an empty intersection: the real-OS agents teleported the pointer and had no concept of credentials; the tools with real secret vaults were browser-only; and the human-motion libraries had never been wired to an LLM. HumanHands is the glue between those three.

Three design calls

1. Perceive through the Accessibility tree, not screenshots. The AX tree is local, free and pixel-exact. The agent grounds every action in element geometry, so screen data never leaves the machine and the loop runs on a Claude subscription through the CLI (claude setup-token) at zero API cost. Vision is kept only as a concurrent fallback when the tree is missing or wrong.

2. Learn by compression, not gradients. A hosted model cannot be fine-tuned, and the agent kept stumbling on the same spots. After reading the agent-memory literature (Reflexion, ExpeL, Voyager, Agent Workflow Memory, Skyvern's learn-once-replay), the design became: distil each messy successful run into a clean reusable recipe plus its gotchas, inject that as guidance next time, and once a path proves stable graduate it into a deterministic macro that replays with no model calls and only wakes the model when the screen diverges. A traversed path compressed into a reflex.

3. Keep secrets structurally out of the model. Real credentials live in the Keychain and reach the model only as placeholder tokens that are substituted at the last instant, in the executor. A domain-verified gate refuses to type a secret unless the genuine site is confirmed. User-owned app and site allowlists bound what the agent can touch. TOTP generation, a redaction registry, a tripwire and a kill switch sit in the same ring.

Architecture

Ring-layered SwiftPM targets; every OS primitive sits behind a protocol so the logic rings test off-device.

RingTargetRole
0HHCorePure value types, no OS dependencies
0HHOSBridgeOS-touching primitives (CGEvent, AX, ScreenCaptureKit, Keychain) behind protocols
1HHExecutionHumanised executor: WindMouse paths, Fitts' law timing, typing cadence
1HHPerceptionPerception geometry, the single coordinate chokepoint
1HHSecretsVault, placeholder substitution, TOTP, redaction, tripwire
1HHSafetyDomain-verified site gate
2HHSitesPer-site profiles: allowlist + playbook
2HHAgentProvider abstraction and the perceive → decide → act loop
3HHRuntimeShared engine and structured event stream used by both front-ends
humanhandsCLI: preflight, capture, run
HumanHandsAppSwiftUI app: a window that runs a goal
HHTests135 pure-logic tests, run off-device

Build and run

swift build
swift test# 135 tests, no device access needed
Scripts/build-app.sh # builds and signs HumanHands.app into dist/# reasoning provider: either a Claude subscription token or an API key
claude setup-token &&export ANTHROPIC_AUTH_TOKEN='sk-ant-oat...'# orexport ANTHROPIC_API_KEY='sk-ant-api...'
.build/debug/humanhands preflight # checks Accessibility and Screen Recording permissions
.build/debug/humanhands run "open Safari and search for the TU/e library opening hours"

macOS will ask for Accessibility (and, for the vision fallback, Screen Recording) permission the first time. Nothing runs outside the allowlists you configure.

Status

Working personal tool, not a product. Things that are deliberately not here: cloud relays, telemetry, credential sync, anything that would move screen contents or secrets off the machine.

Author: Pulkit Chawla · linkedin.com/in/pulkitchawla11

About

An AI agent that operates a Mac the way a person does: Accessibility-tree perception, human-like cursor paths, Keychain-backed secrets that never reach the model. Native Swift.

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Latest commit

History

1 Commit

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

HumanHands

An AI agent that operates a Mac the way a person does. It perceives the screen through the macOS Accessibility tree, decides the next move with Claude, and drives the real, visible cursor along a human-like path, typing with human cadence, instead of teleporting the pointer.

Built in 2026 as a personal project. Fully native Swift, macOS 14+, no Electron, no browser extension.

Why it exists

Surveying computer-use agents in 2026 showed an empty intersection: the real-OS agents teleported the pointer and had no concept of credentials; the tools with real secret vaults were browser-only; and the human-motion libraries had never been wired to an LLM. HumanHands is the glue between those three.

Three design calls

1. Perceive through the Accessibility tree, not screenshots. The AX tree is local, free and pixel-exact. The agent grounds every action in element geometry, so screen data never leaves the machine and the loop runs on a Claude subscription through the CLI (claude setup-token) at zero API cost. Vision is kept only as a concurrent fallback when the tree is missing or wrong.

2. Learn by compression, not gradients. A hosted model cannot be fine-tuned, and the agent kept stumbling on the same spots. After reading the agent-memory literature (Reflexion, ExpeL, Voyager, Agent Workflow Memory, Skyvern's learn-once-replay), the design became: distil each messy successful run into a clean reusable recipe plus its gotchas, inject that as guidance next time, and once a path proves stable graduate it into a deterministic macro that replays with no model calls and only wakes the model when the screen diverges. A traversed path compressed into a reflex.

3. Keep secrets structurally out of the model. Real credentials live in the Keychain and reach the model only as placeholder tokens that are substituted at the last instant, in the executor. A domain-verified gate refuses to type a secret unless the genuine site is confirmed. User-owned app and site allowlists bound what the agent can touch. TOTP generation, a redaction registry, a tripwire and a kill switch sit in the same ring.

Architecture

Ring-layered SwiftPM targets; every OS primitive sits behind a protocol so the logic rings test off-device.

RingTargetRole
0HHCorePure value types, no OS dependencies
0HHOSBridgeOS-touching primitives (CGEvent, AX, ScreenCaptureKit, Keychain) behind protocols
1HHExecutionHumanised executor: WindMouse paths, Fitts' law timing, typing cadence
1HHPerceptionPerception geometry, the single coordinate chokepoint
1HHSecretsVault, placeholder substitution, TOTP, redaction, tripwire
1HHSafetyDomain-verified site gate
2HHSitesPer-site profiles: allowlist + playbook
2HHAgentProvider abstraction and the perceive → decide → act loop
3HHRuntimeShared engine and structured event stream used by both front-ends
humanhandsCLI: preflight, capture, run
HumanHandsAppSwiftUI app: a window that runs a goal
HHTests135 pure-logic tests, run off-device

Build and run

swift build
swift test# 135 tests, no device access needed
Scripts/build-app.sh # builds and signs HumanHands.app into dist/# reasoning provider: either a Claude subscription token or an API key
claude setup-token &&export ANTHROPIC_AUTH_TOKEN='sk-ant-oat...'# orexport ANTHROPIC_API_KEY='sk-ant-api...'
.build/debug/humanhands preflight # checks Accessibility and Screen Recording permissions
.build/debug/humanhands run "open Safari and search for the TU/e library opening hours"

macOS will ask for Accessibility (and, for the vision fallback, Screen Recording) permission the first time. Nothing runs outside the allowlists you configure.

Status

Working personal tool, not a product. Things that are deliberately not here: cloud relays, telemetry, credential sync, anything that would move screen contents or secrets off the machine.

Author: Pulkit Chawla · linkedin.com/in/pulkitchawla11

About

An AI agent that operates a Mac the way a person does: Accessibility-tree perception, human-like cursor paths, Keychain-backed secrets that never reach the model. Native Swift.

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages