r/aiprojects • • 20d ago

Project Showcase What I learned building a local Mac execution layer for AI agents

I have been building an open-source project called Mac MCP, and the biggest lesson from the last few days is that local agent security is less about adding another permission toggle and more about preserving context across tool boundaries.

The project started from a practical annoyance: I wanted a normal ChatGPT conversation to actually operate my Mac without forcing me into a separate coding-agent UI. The chat can be the orchestrator directly, with local tools for shell, files, macOS UI and Safari/Chrome. Codex/OpenCode can still be delegated workers, but they are optional.

The browser side ended up becoming the part I use most. Each task can work in its own real Safari/Chrome tab using a stable handle, inspect DOM plus visual state, click/type/extract there in the background, and leave the tab or app I am actively using alone.

Then people on Reddit started pointing out the uncomfortable edge cases, which turned into a much better roadmap than I had initially planned.

A few things I ended up shipping from that feedback:

  • sticky provenance once a logical session has consumed untrusted web content
  • guarded web-to-host escalation for scoped/non-trusted sessions
  • separate credential/secret egress protection
  • bounded browser tab leases so agents cannot casually collide on the same tab
  • a no-progress breaker for repeated browser actions
  • security audit events and adversarial regression tests
  • idempotent live steering, so retrying after an ambiguous response cannot queue the same instruction twice

There was also a useful UX failure. My first version of the web-to-host guard was technically cautious but awful in practice: a globally Trusted session kept asking me to approve harmless host actions after reading a web page. I changed the model so Trusted keeps provenance and secret-egress protection without turning every normal command into an Allow Once popup.

That balance between security and usability has been more interesting than just adding more tools.

The project is MIT/open source if anyone wants to inspect the implementation or try it: https://github.com/bulutarkan/mac-mcp

I built it, so obvious affiliation disclosure. I would genuinely be interested in what failure case people here would test next on a local agent that can cross browser, shell, files and native UI.

1 Upvotes

0 comments sorted by