Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
27 commits
Select commit Hold shift + click to select a range
396c7fb
feat: scaffold ChatGPT Desktop CDP adapter and MCP/CLI tools
cursoragent Sep 29, 2026
8361ae1
chore: rebuild artifact with chatgpt_desktop MCP tools
cursoragent Sep 29, 2026
686ba5f
fix: align ChatGPT Desktop DOM module with exploration results
cursoragent Sep 29, 2026
6155184
test: cover CDP-first facade with app-server backend fallback
cursoragent Sep 29, 2026
b0490e5
feat: align ChatGPT Desktop CDP send/wait/read with live DOM
cursoragent Sep 29, 2026
5617e07
docs: document chatgpt-desktop project send and full read
cursoragent Sep 29, 2026
5401759
feat: deep-read and list via app-server; keep send/wait on CDP
cursoragent Sep 29, 2026
f800045
chore: retrigger Package CI for app-server deep-read redesign
cursoragent Sep 29, 2026
bf0275c
feat: app-server list/search/read per 0.158.0; fix modelProviders
cursoragent Sep 29, 2026
f4e3b67
feat: merge remote-control threads into desktop list
cursoragent Sep 29, 2026
241a08b
feat: separate host and modelProvider list filters; add list_hosts
cursoragent Sep 29, 2026
386ca5c
fix: include remotes in listHosts even without global-state env
cursoragent Sep 29, 2026
b71f10e
fix: codex list/read/send bugs from desktop work
cursoragent Sep 29, 2026
9dfdfa3
fix: CDP production risks from Ripwire audit
cursoragent Sep 29, 2026
9516f37
fix: host/modelProvider are freeform strings with dynamic discovery
cursoragent Sep 29, 2026
323e8e1
chore: regenerate artifact manifest after rebase onto main
cursoragent Sep 29, 2026
6b1cf36
test: include chatgpt_desktop_list_hosts in MCP tool inventory
cursoragent Sep 29, 2026
e5058cb
chore: refresh artifact source snapshot after tools.test fix
cursoragent Sep 29, 2026
c561a03
Fix Desktop CDP isolation, reply tracking, and dynamic thread inventory
ScriptedAlchemy Sep 29, 2026
76ce816
chore: refresh artifact snapshot after CDP review fixes
cursoragent Sep 29, 2026
009ba7c
Exclude local plugin checkout from artifact source snapshots
ScriptedAlchemy Sep 29, 2026
05c370c
Fix ChatGPT Desktop e2e discovery and thread handling
ScriptedAlchemy Sep 29, 2026
2718be5
Expose complete ChatGPT Desktop MCP workflow and skill
ScriptedAlchemy Sep 29, 2026
8e0cde2
fix: page ChatGPT Desktop MCP results below document cap
ScriptedAlchemy Sep 29, 2026
58b1b22
Merge origin/main into ChatGPT Desktop branch
ScriptedAlchemy Sep 29, 2026
dc38123
fix: page merged Desktop inventory and resolve project scope
ScriptedAlchemy Sep 29, 2026
94b283c
fix: address Codex review of Desktop search, read fallback and backen…
ScriptedAlchemy Sep 29, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
7 changes: 7 additions & 0 deletions .changeset/chatgpt-desktop-cdp.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
---
"grok-bot-cli": minor
---

Scaffold ChatGPT Desktop CDP adapter and MCP/CLI tools (`chatgpt_desktop_*`). List/search keep separate `host` / `modelProvider` filters; `list_hosts` discovers hosts and providers. Codex list-threads always passes `modelProviders: []`, pages via `nextCursor`, and falls back from `useStateDbOnly` when empty. Codex send/read/wait strip Desktop `local:` ids; remote-control "thread not loaded" maps to `REMOTE_THREAD_NOT_LOADED` with host. Thread reads use `thread/read` metadata + `thread/turns/list` (never deprecated `includeTurns`).

Keep CDP loopback-only across discovery, bound and close sessions, serialize UI operations, distinguish partial replies and uncertain sends, and preserve dynamic remote/provider filtering and ordered empty-safe history reads.
7 changes: 7 additions & 0 deletions .changeset/desktop-e2e-reliability.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
---
"grok-bot-cli": patch
---

Fix ChatGPT Desktop host discovery, bounded thread reads and searches, list pagination, CDP navigation and project clicks, status reachability, and result provenance. Add complete MCP and skill guidance, project filters, archived-thread reads and explicit unarchive-on-send support.

Keep MCP Desktop results below the Agent Bundle document cap with resumable, lossless read fragments and byte-bounded list/search pages. Compact display titles while matching search against full titles, and align remote host counts with filtered inventory.
5 changes: 5 additions & 0 deletions .changeset/desktop-merged-pagination-projects.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
---
"grok-bot-cli": patch
---

Page ChatGPT Desktop threads from a stable, sorted merged inventory so CDP and remote rows appear once in their timestamp range and requested page sizes are filled. Resolve project labels from Desktop assignments and workspace roots. Verify new-chat navigation and project scope before sending, and report unavailable project roots promptly.
3 changes: 3 additions & 0 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -8,3 +8,6 @@ tmp-agents/
*.log
.DS_Store
*.tsbuildinfo

# Local plugin checkout is not part of the shipped source snapshot.
/plugin/
23 changes: 21 additions & 2 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -228,11 +228,27 @@ Residual risks, stated honestly: requests without both matching thread and turn

Current shim limitation: Desktop's spawn-time app-tools MCP `-c` overrides are not forwarded to the already-running managed daemon. No restoration path or app-tools parity has been demonstrated here; this is not a claim of permanent protocol impossibility. Fully quit and relaunch ChatGPT.app after install (or login) so it inherits `CODEX_CLI_PATH`. `status` reads the macOS GUI-domain value via `launchctl getenv` (what Desktop actually inherits) alongside the calling shell's value. LaunchAgent persistence is macOS-first; elsewhere install still writes the wrapper and bridge but leaves `CODEX_CLI_PATH` for you to export. `~/.codex/bin` holds scripts only — there is no extra revert note to clean up; revert is `gbot codex desktop-shim uninstall` plus this section.

**ChatGPT Desktop over CDP (scaffold).** Prefer the Desktop UI surface via Chrome DevTools Protocol when you need more than the app-server socket. CDP is **local-only** (`127.0.0.1`); there is no remote transport. Relaunch the macOS app with a debug port (Electron fuses block Node inspect, not Chromium's flag):

```sh
osascript -e 'tell application "ChatGPT" to quit' \
&& open -a /Applications/ChatGPT.app --args --remote-debugging-port=9222
gbot chatgpt-desktop status
gbot chatgpt-desktop threads --limit 20
gbot chatgpt-desktop search "launch"
gbot chatgpt-desktop read <threadId>
gbot chatgpt-desktop read <threadId> --full --limit 200
gbot chatgpt-desktop send --project Launch "hello"
gbot chatgpt-desktop send --thread-id <threadId> "hello"
```

MCP tools: `chatgpt_desktop_status`, `chatgpt_desktop_list_threads`, `chatgpt_desktop_search_threads`, `chatgpt_desktop_read_thread`, `chatgpt_desktop_send`, `chatgpt_desktop_wait_reply`. List/search/read prefer the Codex app-server (`thread/list` with `modelProviders: []`, `thread/read` + `thread/turns/list`; never `thread/resume` for reads). Send / new-thread / wait / selected-thread stay on CDP; DOM read is fallback only. Desktop `local:<conversationId>` strips to the bare app-server id. Results report `backend: "cdp" | "app-server"`. Details: [docs/chatgpt-desktop-cdp.md](docs/chatgpt-desktop-cdp.md).

**Status contract (`gbot codex status --json`).** `reachable` is endpoint reachability only. `socketState` is `socket`, `absent`, `permission-denied`, or `not-a-socket`; `mode` is `daemon` for a usable daemon, otherwise the failure: `socket-absent`, `permission-denied` (the file or the connect refused this user), `not-a-socket`, `connect-failed` (socket present, nothing completed the WebSocket upgrade), `handshake-failed` (upgrade or `initialize` failed), `windows-unsupported`, or `bad-response` (reachable, but `initialize` returned something off-schema — `reachable` stays `true`). `schema.compatibility` is `exact` when the daemon reports the pinned version, `unverified` when it differs (methods usually survive upgrades, but the shapes are not re-checked), or `unknown`. `cliVersionProbe` reports whether `codex --version` answered (`ok`, `missing`, `timeout` after 3 s, `error`). The document is always written to stdout and includes `exitCode`; it is `0` only for a usable daemon.

`desktopShimConfigured` is true when the installed wrapper is selected by Desktop-facing `CODEX_CLI_PATH` (the GUI domain on macOS). This describes configuration for future launches; a running Desktop may not have inherited it, and the wrapper may have fallen back to stock Codex. `desktopAttached` is `"private-stdio"` when a Desktop-bundled app-server process is observed, otherwise `"unknown"`. That process observation and shim configuration can both be present. Neither a configured shim nor a reachable daemon proves Desktop is attached to that daemon. Verify actual attachment with a controlled shared-thread interaction and matching thread/turn IDs.

**Thread discovery.** `list-threads --limit N` (1–200) pages with the opaque `--cursor` from the previous `nextCursor`; JSON keeps the cursor verbatim, text output prints a sanitized `more: --cursor …` hint. Text fields are stripped of terminal control sequences in both outputs (single-line fields also lose line breaks; `preview` keeps its newlines; a structured `source` such as `{ "custom": … }` passes through unchanged), `status` is one of `notLoaded | idle | active | systemError | unknown`, and non-numeric `updatedAt` becomes `null`. Unknown arguments are rejected before the socket is touched; a response that does not match the pinned schema (including an entry without a string `id`) fails with `reason: "bad-response"`.
**Thread discovery.** `list-threads --limit N` (1–200) pages with the opaque `--cursor` from the previous `nextCursor`; JSON keeps the cursor verbatim, text output prints a sanitized `more: --cursor …` hint. Requests pass `modelProviders: []` so threads from every provider appear (the daemon otherwise filters to the current provider) and `useStateDbOnly: true` for a fast state-DB listing, falling back to a full scan when that first page is empty. Text fields are stripped of terminal control sequences in both outputs (single-line fields also lose line breaks; `preview` keeps its newlines; a structured `source` such as `{ "custom": … }` passes through unchanged), `status` is one of `notLoaded | idle | active | systemError | unknown`, and non-numeric `updatedAt` / `createdAt` become `null`. Extra fields when present: `section`, `projectId`, `modelProvider`, `model`, `originator`. Unknown arguments are rejected before the socket is touched; a response that does not match the pinned schema (including an entry without a string `id`) fails with `reason: "bad-response"`.

**Routes, attribution, and loops.** `gbot codex send` runs on the machine that owns `CODEX_HOME`, as the user who owns the socket, with that user's Codex credentials; the socket path comes only from `CODEX_HOME` or `CODEX_APP_SERVER_SOCK`, never from the message or an agent-supplied argument. gbot has no remote transport. A cloud-hosted Grok Bot on the box cannot reach a desktop socket at `/home/box/.codex/...` — use Grok Bot Shell with a machineId to run `gbot` on the user's registered machine (after `codex app-server daemon start` / bootstrap there). `GROK_BOT_CODEX_THREADS=id,id` lets the operator pin `send` to approved threads (`reason: "route-not-allowed"` otherwise). Every send gets a delivery envelope: `messageId` (also sent as Codex's native `clientUserMessageId`), `correlationId` (defaults to the message id), optional `replyTo`, and `hop`. A reply passes the original correlation id and `hop` + 1:

Expand Down Expand Up @@ -262,7 +278,10 @@ The npm package is also an [Agent Bundle](https://scriptedalchemy.github.io/agen
that gives Codex, Claude Code, and Cursor a `grok-bot` MCP server with messaging,
Codex conversation, and managed bridge tools, plus a `talk-to-grok-bot` skill.
`gbot_send` and `gbot_thread` handle Grok conversations; `codex_threads`,
`codex_send`, `codex_new`, `codex_wait`, and `codex_watch` handle Codex conversations. Claude Code and Cursor bundles also include `/gbot:codex-send`, `/gbot:codex-threads`, and `/gbot:codex-wait` commands under `commands/`.
`codex_send`, `codex_new`, `codex_wait`, and `codex_watch` handle Codex conversations.
`chatgpt_desktop_*` tools drive ChatGPT Desktop over local CDP (with app-server
fallback). Claude Code and Cursor bundles also include `/gbot:codex-send`,
`/gbot:codex-threads`, and `/gbot:codex-wait` commands under `commands/`.
`gbot_bridge_start`, `gbot_bridge_status`, `gbot_bridge_stop`, and
`gbot_codex_respond` manage automatic delivery and scoped operator responses.
The tools bundle this repository's gateway client and worker, so the installed
Expand Down
2 changes: 1 addition & 1 deletion artifact/agent-bundle.compile-evidence.json

Large diffs are not rendered by default.

2 changes: 1 addition & 1 deletion artifact/agent-bundle.manifest.json

Large diffs are not rendered by default.

Loading