Ghost Developer Studio

Ghost Hands

Playwright drives. Stagehand thinks. Browser Use wanders.
Ghost Hands answers for every move.

Agent hands for the web โ€” with a governor attached. Every action is classified before it runs, judged against a policy, written to a provenance trail before it executes, and gated on a human approval when it matters.

$ pip install ghost-handsLive on PyPI

v0.3.0 is live on PyPI and GitHub; the current build is v0.6.0 โ€” approvals by phone: consequential actions can be decided on Ryan's phone (a MrGhosty notification + in-app Approve/Deny) through the same bridge the AndroidDriver uses, alongside GhostBus agent mode, the Body Protocol, and policy packs. Nothing here is vaporware: every number below was measured on the current build.

The wedge

Every browser-agent tool in the field will click Pay, Send, or Delete the moment a model tells it to. Ghost Hands is the layer that says: classify first.

๐Ÿ›ก๏ธ

Governed by default

Each action is classified and checked against a policy before the driver moves. Consequential actions stop for approval โ€” and with no approver attached, "ask" means denied. Silence is never consent.

readonly write consequential
๐Ÿงพ

Recorded, then replayable

A JSONL provenance trail captures perceive โ†’ decide โ†’ govern โ†’ execute โ†’ result for every step. Any finished run graduates into a deterministic, model-free script: explore with a model once, re-run forever for free.

๐Ÿ‘ป

Our own stack

The browser body is a from-scratch, standard-library CDP client driving Chromium directly. Zero runtime dependencies โ€” no Playwright, no Selenium, nobody else's automation layer under the hood. (We drive Chromium, the browser; we didn't write a browser engine.)

๐Ÿ‘€

Cheap eyes

Perception is a numbered element map parsed from the page โ€” no screenshot firehose, no vision model. The bundled demo reads a whole page in about 174 tokens (696 map chars).

๐Ÿฉน

Self-healing targets

Pages mutate between looking and clicking. When a target's number no longer points at the element the decider meant, the hands re-find it by descriptor, retry once, and write the heal into the trail.

๐Ÿง 

Any brain, or none

Pluggable deciders: explicit scripts, deterministic offline rules, or any OpenAI-compatible model (key from the environment only, never stored). Plus tabs, session save/load, real screenshots, and a stdlib MCP server.

๐ŸšŒ

Works the bus (new in 0.4)

ghost-hands bus-agent joins a GhostBus workspace as the agent other agents task: it claims governed work, posts progress, uploads its trail as a shared file โ€” and when the governor asks, the approval request itself travels over the bus. Policy packs (readonly / standard / strict) tune the leash per deployment.

readonly standard strict
๐Ÿ“ฑ

One hands, many bodies

A written Body Protocol defines the driver contract, proven by three bodies โ€” real Chromium, an in-memory web, and a simulated phone with apps, notes, toggles, and rendered PNG screenshots โ€” all driven by the same runner, governor, and trail. The Android driver is specified in the protocol; the simulator is its rehearsal.

Verified, not vibes

Measured on the v0.6.0 build, October 8, 2026 โ€” the same suites that ship in the repo.

299
pytest tests passing
88/88
bench cases (offline suite)
2/2
live cases: example.com + a real Wikipedia search
0
runtime dependencies
perceive  step 4 ยท 21 elements ยท 1,842 map chars
decide    step 4 ยท {"kind": "click", "target": 7}
govern    step 4 ยท classification=consequential ยท outcome=ask
execute   step 4 ยท [7] <button> "Place order โ€” pay $42"  โ† held for approval
stop      denied ยท approval required, no approver
The honest limits: the LLM decider's wire protocol is proven against a local stub endpoint; live-model driving quality is unproven and depends on the model you bring. The Chromium driver is proven on fixture pages plus example.com and Wikipedia โ€” not on the whole web. There are no head-to-head speed benchmarks against other tools, and we won't claim any we haven't run. The bus agent is proven against the real GhostBus server booted locally (both its shapes); the Android driver and the MrGhosty bridge are built and proven against the bridge wire contract โ€” proof on a physical phone is still ahead.

Where it's headed

v0.4.0 shipped the GhostBus transport (other agents can task the hands, and approvals route back over the bus), policy packs (readonly / standard / strict), and the Body Protocol with a simulated phone body. v0.5.0 built the Android body itself โ€” MrGhosty's accessibility service hosts the bridge and AndroidDriver speaks the same protocol, so one pair of hands works the phone and the web. v0.6.0 added the phone approver: when a run hits a consequential action, the question goes to Ryan's phone and only his tap answers it โ€” the bridge API can ask, but it can never approve. Next: proving it on Ryan's phone.