Ghost runs on your own machine — the client starts it, so there is no endpoint to ping. Last commit 6 Sep 2026.
Verified desktop control for agents on Windows and Linux: apps with no API, windows, shell, browser.
We read the source, 19 h ago · rules 3dff92dd89df
A value the model can set ends up inside a file or shell call. That is not a flaw by itself — for a terminal server it is the job — but it is where things go wrong when it is not.
let mut c = Command::new(shell);
What this server is able to do. For an MCP server this is often the job itself — a terminal server runs commands because that is what it is for. Listed so you know what you are plugging in, not as an accusation.
proc = subprocess.Popen(
Is this your server and something here is wrong? Tell us — corrections are free and do not require a plan.
That is not a flaw by itself — but it is where things go wrong when it is not the job. We re-read this code on every release. Watch it and you hear from us the day another one appears.
Sandboxed computer-use for AI agents: drive real browser + desktop apps in nested X11 windows
Control Windows desktop via MCP: mouse, keyboard, screenshots, clipboard, and apps.
Browser + dev-server logs on one correlated timeline, for Claude Code and AI agents.
Hosted browser for AI agents: screenshots, post-JS DOM, console, WCAG. No install, no API key.
Self-hosted MCP server: sandboxed browser, desktop, vision, code-edit packs for any agent.
macOS desktop control for Claude: click, type, screenshot, AX tree, browser control, agentic loops.
Browser QA agent that won't return a false green: verified PASS/FAIL + access-control probing.
Launch, inspect, control, and share isolated cloud browsers for your agents.
Answers built from our own checks of this server.