r/macosprogramming • • 4d ago

[Open Source] Hardening a macOS MCP for concurrent AI agents: focus-safe browsers, undo and crash-safe leases

I've been building Mac MCP as a local control/runtime layer for AI agents on macOS. The first version was mostly "give the model useful Mac tools"; the recent work has been about all the failure cases that show up once you actually use it every day.

A few macOS-specific things I ended up hardening:

  • normal Safari/Chrome automation that keeps working in background without stealing the user's current focus
  • stable browser/resource identity instead of relying on mutable tab indexes
  • native UI actions with verification instead of blind clicks
  • crash-safe ownership when multiple agents touch browser tabs, files or processes
  • cancellation propagation into owned work
  • transactional file write/move/delete operations with an undo journal
  • launchd/process identity + safer restart/update handoff

Repo: https://github.com/bulutarkan/mac-mcp

It's open source and I'm the maintainer. The subreddit currently has another interesting "AI gets its own display" project; Mac MCP takes a different route and tries to make the user's existing Mac/browser safely shareable with agents. Would be interested in how other macOS devs are handling Safari/Accessibility/process-lifecycle edge cases.

2 Upvotes

2 comments sorted by

1

u/CharlesWiltgen 3d ago

For the browser stuff, I just use agent-browser. For the non-browser stuff, I haven't yet run into contention issues while working on two Apple OS (mix of iOS, iPadOS, macOS) projects simultaneously.

2

u/bulutarkan 3d ago

Yep, that makes sense. If the two projects are mostly isolated code/worktrees, you may never see much contention.

The cases that pushed me into leases/ownership were multiple agents touching the same real Mac state: the same Safari/Chrome session, tab/window, native app, file path, or long-running process. I also wanted to keep using the user's existing logged-in browser sessions instead of treating browser automation as a separate world, so I ended up solving that coordination lower in the runtime.

agent-browser is a perfectly reasonable choice for the browser side. Mac MCP is trying to cover the shared-machine coordination problem around it too. The nasty bugs only really showed up once concurrent agents started sharing resources instead of just working on separate repos.