Show AI control, temporarily block physical input, and allow user takeover - #445
Merged
Jeomon merged 9 commits intoOct 3, 2026
Merged
Conversation
Track physical user activity, gate MCP tool calls, and show visible AI ownership. Document the asynchronous release and in-flight command limits pending further safety work.
Member
|
Can you also show a screenshot of it when the takeover happens |
Contributor
Author
Member
|
Thanks again |
This was referenced Oct 3, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.


Description
Ctrl+Alt+Shift+Backspace. Physical input then passes through, new AI tool calls other thanControlStatusare blocked, and AI control can resume only after 10 seconds without physical activity and after held physical keys and mouse buttons are released.ControlStatusduring takeover and add tests for input gating, state transitions, visual feedback, capture, and failure paths.Motivation
Testing
b15a549had 854 passing tests and two unsolicited-notification tests timed out.904d6afexplicitly selects a legacy MCP session for those notification tests. The new upstream Windows / Python 3.14 run ond501a7dpassed: 865 passed, 0 failed.Limitations
Input interception and takeover are best-effort, not a security boundary or a guarantee that human and AI input can never mix. Physical input is not suppressed before the indicator is visible, while capture hides it, or after a detected hook/indicator failure. Cleanup of AI-held keys and mouse buttons after a detected failure is asynchronous, so a brief overlap with physical input remains possible. Windows can also silently remove a low-level input hook; periodic replacement reduces but does not eliminate that undetected window. Stepwise desktop input stops at a checkpoint, but an already-running external command or launched process is not cancelled and completed side effects are not undone. Modern sessionless MCP clients cannot receive unsolicited state logs and should query
ControlStatus.Screenshots
None attached: the earlier smoke test checked screenshots in memory to avoid retaining private desktop content. Its indicator and capture flash were confirmed on the test display; the restored glow and notice are covered by automated visual tests but have not had a new physical-display check on this combined branch.
Related Issues
None.