# supersurf - Doramagic AI Context Pack

> 定位：安装前体验与判断资产。它帮助宿主 AI 有一个好的开始，但不代表已经安装、执行或验证目标项目。

## 充分原则

- **充分原则，不是压缩原则**：AI Context Pack 应该充分到让宿主 AI 在开工前理解项目价值、能力边界、使用入口、风险和证据来源；它可以分层组织，但不以最短摘要为目标。
- **压缩策略**：只压缩噪声和重复内容，不压缩会影响判断和开工质量的上下文。

## 给宿主 AI 的使用方式

你正在读取 Doramagic 为 supersurf 编译的 AI Context Pack。请把它当作开工前上下文：帮助用户理解适合谁、能做什么、如何开始、哪些必须安装后验证、风险在哪里。不要声称你已经安装、运行或执行了目标项目。

## Claim 消费规则

- **事实来源**：Repo Evidence + Claim/Evidence Graph；Human Wiki 只提供显著性、术语和叙事结构。
- **事实最低状态**：`supported`
- `supported`：可以作为项目事实使用，但回答中必须引用 claim_id 和证据路径。
- `weak`：只能作为低置信度线索，必须要求用户继续核实。
- `inferred`：只能用于风险提示或待确认问题，不能包装成项目事实。
- `unverified`：不得作为事实使用，应明确说证据不足。
- `contradicted`：必须展示冲突来源，不得替用户强行选择一个版本。

## 它最适合谁

- **正在使用 Claude/Codex/Cursor/Gemini 等宿主 AI 的开发者**：README 或插件配置提到多个宿主 AI。 证据：`README.md` Claim：`clm_0003` supported 0.86

## 它能做什么

- **AI Skill / Agent 指令资产库**（可做安装前预览）：项目包含可被宿主 AI 读取的 Skill 或 Agent 指令文件，可用于把专业流程带入 Claude、Codex、Cursor 等宿主。 证据：`docs/skill.md` Claim：`clm_0001` supported 0.86
- **命令行启动或安装流程**（需要安装后验证）：项目文档中存在可执行命令，真实使用需要在本地或宿主环境中运行这些命令。 证据：`README.md` Claim：`clm_0002` supported 0.86

## 怎么开始

- `claude mcp add supersurf -- npx supersurf-mcp@latest mcp  # Claude Code` 证据：`README.md` Claim：`clm_0004` supported 0.86
- `claude mcp add supersurf -- node server/dist/bin/supersurf.js mcp` 证据：`README.md` Claim：`clm_0005` supported 0.86

## 继续前判断卡

- **当前建议**：先做权限沙盒试用
- **为什么**：项目存在安装命令、宿主配置或本地写入线索，不建议直接进入主力环境，应先在隔离环境试装。

### 30 秒判断

- **现在怎么做**：先做权限沙盒试用
- **最小安全下一步**：先跑 Prompt Preview；若仍要安装，只在隔离环境试装
- **先别相信**：工具权限边界不能在安装前相信。
- **继续会触碰**：命令执行、宿主 AI 配置、本地环境或项目文件

### 现在可以相信

- **适合人群线索：正在使用 Claude/Codex/Cursor/Gemini 等宿主 AI 的开发者**（supported）：有 supported claim 或项目证据支撑，但仍不等于真实安装效果。 证据：`README.md` Claim：`clm_0003` supported 0.86
- **能力存在：AI Skill / Agent 指令资产库**（supported）：可以相信项目包含这类能力线索；是否适合你的具体任务仍要试用或安装后验证。 证据：`docs/skill.md` Claim：`clm_0001` supported 0.86
- **能力存在：命令行启动或安装流程**（supported）：可以相信项目包含这类能力线索；是否适合你的具体任务仍要试用或安装后验证。 证据：`README.md` Claim：`clm_0002` supported 0.86
- **存在 Quick Start / 安装命令线索**（supported）：可以相信项目文档出现过启动或安装入口；不要因此直接在主力环境运行。 证据：`README.md` Claim：`clm_0004` supported 0.86

### 现在还不能相信

- **工具权限边界不能在安装前相信。**（unverified）：MCP/tool 类项目通常会触碰文件、网络、浏览器或外部 API，必须真实检查权限和日志。
- **真实输出质量不能在安装前相信。**（unverified）：Prompt Preview 只能展示引导方式，不能证明真实项目中的结果质量。
- **宿主 AI 版本兼容性不能在安装前相信。**（unverified）：Claude、Cursor、Codex、Gemini 等宿主加载规则和版本差异必须在真实环境验证。
- **不会污染现有宿主 AI 行为，不能直接相信。**（inferred）：Skill、plugin、AGENTS/CLAUDE/GEMINI 指令可能改变宿主 AI 的默认行为。 证据：`docs/skill.md`
- **可安全回滚不能默认相信。**（unverified）：除非项目明确提供卸载和恢复说明，否则必须先在隔离环境验证。
- **真实安装后是否与用户当前宿主 AI 版本兼容？**（unverified）：兼容性只能通过实际宿主环境验证。
- **项目输出质量是否满足用户具体任务？**（unverified）：安装前预览只能展示流程和边界，不能替代真实评测。
- **安装命令是否需要网络、权限或全局写入？**（unverified）：这影响企业环境和个人环境的安装风险。 证据：`README.md`

### 继续会触碰什么

- **命令执行**：包管理器、网络下载、本地插件目录、项目配置或用户主目录。 原因：运行第一条命令就可能产生环境改动；必须先判断是否值得跑。 证据：`README.md`
- **宿主 AI 配置**：Claude/Codex/Cursor/Gemini/OpenCode 等宿主的 plugin、Skill 或规则加载配置。 原因：宿主配置会改变 AI 后续工作方式，可能和用户已有规则冲突。 证据：`docs/skill.md`
- **本地环境或项目文件**：安装结果、插件缓存、项目配置或本地依赖目录。 原因：安装前无法证明写入范围和回滚方式，需要隔离验证。 证据：`README.md`
- **宿主 AI 上下文**：AI Context Pack、Prompt Preview、Skill 路由、风险规则和项目事实。 原因：导入上下文会影响宿主 AI 后续判断，必须避免把未验证项包装成事实。

### 最小安全下一步

- **先跑 Prompt Preview**：用安装前交互式试用判断工作方式是否匹配，不需要授权或改环境。（适用：任何项目都适用，尤其是输出质量未知时。）
- **只在隔离目录或测试账号试装**：避免安装命令污染主力宿主 AI、真实项目或用户主目录。（适用：存在命令执行、插件配置或本地写入线索时。）
- **先备份宿主 AI 配置**：Skill、plugin、规则文件可能改变 Claude/Cursor/Codex 的默认行为。（适用：存在插件 manifest、Skill 或宿主规则入口时。）
- **安装后只验证一个最小任务**：先验证加载、兼容、输出质量和回滚，再决定是否深用。（适用：准备从试用进入真实工作流时。）

### 退出方式

- **保留安装前状态**：记录原始宿主配置和项目状态，后续才能判断是否可恢复。
- **准备移除宿主 plugin / Skill / 规则入口**：如果试装后行为异常，可以把宿主 AI 恢复到试装前状态。
- **记录安装命令和写入路径**：没有明确卸载说明时，至少要知道哪些目录或配置需要手动清理。
- **如果没有回滚路径，不进入主力环境**：不可回滚是继续前阻断项，不应靠信任或运气继续。

## 哪些只能预览

- 解释项目适合谁和能做什么
- 基于项目文档演示典型对话流程
- 帮助用户判断是否值得安装或继续研究

## 哪些必须安装后验证

- 真实安装 Skill、插件或 CLI
- 执行脚本、修改本地文件或访问外部服务
- 验证真实输出质量、性能和兼容性

## 边界与风险判断卡

- **把安装前预览误认为真实运行**：用户可能高估项目已经完成的配置、权限和兼容性验证。 处理方式：明确区分 prompt_preview_can_do 与 runtime_required。 Claim：`clm_0006` inferred 0.45
- **命令执行会修改本地环境**：安装命令可能写入用户主目录、宿主插件目录或项目配置。 处理方式：先在隔离环境或测试账号中运行。 证据：`README.md` Claim：`clm_0007` supported 0.86
- **待确认**：真实安装后是否与用户当前宿主 AI 版本兼容？。原因：兼容性只能通过实际宿主环境验证。
- **待确认**：项目输出质量是否满足用户具体任务？。原因：安装前预览只能展示流程和边界，不能替代真实评测。
- **待确认**：安装命令是否需要网络、权限或全局写入？。原因：这影响企业环境和个人环境的安装风险。

## 开工前工作上下文

### 加载顺序

- 先读取 how_to_use.host_ai_instruction，建立安装前判断资产的边界。
- 读取 claim_graph_summary，确认事实来自 Claim/Evidence Graph，而不是 Human Wiki 叙事。
- 再读取 intended_users、capabilities 和 quick_start_candidates，判断用户是否匹配。
- 需要执行具体任务时，优先查 role_skill_index，再查 evidence_index。
- 遇到真实安装、文件修改、网络访问、性能或兼容性问题时，转入 risk_card 和 boundaries.runtime_required。

### 任务路由

- **AI Skill / Agent 指令资产库**：先基于 role_skill_index / evidence_index 帮用户挑选可用角色、Skill 或工作流。 边界：可做安装前 Prompt 体验。 证据：`docs/skill.md` Claim：`clm_0001` supported 0.86
- **命令行启动或安装流程**：先说明这是安装后验证能力，再给出安装前检查清单。 边界：必须真实安装或运行后验证。 证据：`README.md` Claim：`clm_0002` supported 0.86

### 上下文规模

- 文件总数：168
- 重要文件覆盖：40/168
- 证据索引条目：61
- 角色 / Skill 条目：1

### 证据不足时的处理

- **missing_evidence**：说明证据不足，要求用户提供目标文件、README 段落或安装后验证记录；不要补全事实。
- **out_of_scope_request**：说明该任务超出当前 AI Context Pack 证据范围，并建议用户先查看 Human Manual 或真实安装后验证。
- **runtime_request**：给出安装前检查清单和命令来源，但不要替用户执行命令或声称已执行。
- **source_conflict**：同时展示冲突来源，标记为待核实，不要强行选择一个版本。

## Prompt Recipes

### 适配判断

- 目标：判断这个项目是否适合用户当前任务。
- 预期输出：适配结论、关键理由、证据引用、安装前可预览内容、必须安装后验证内容、下一步建议。

```text
请基于 supersurf 的 AI Context Pack，先问我 3 个必要问题，然后判断它是否适合我的任务。回答必须包含：适合谁、能做什么、不能做什么、是否值得安装、证据来自哪里。所有项目事实必须引用 evidence_refs、source_paths 或 claim_id。
```

### 安装前体验

- 目标：让用户在安装前感受核心工作流，同时避免把预览包装成真实能力或营销承诺。
- 预期输出：一段带边界标签的体验剧本、安装后验证清单和谨慎建议；不含真实运行承诺或强营销表述。

```text
请把 supersurf 当作安装前体验资产，而不是已安装工具或真实运行环境。

请严格输出四段：
1. 先问我 3 个必要问题。
2. 给出一段“体验剧本”：用 [安装前可预览]、[必须安装后验证]、[证据不足] 三种标签展示它可能如何引导工作流。
3. 给出安装后验证清单：列出哪些能力只有真实安装、真实宿主加载、真实项目运行后才能确认。
4. 给出谨慎建议：只能说“值得继续研究/试装”“先补充信息后再判断”或“不建议继续”，不得替项目背书。

硬性边界：
- 不要声称已经安装、运行、执行测试、修改文件或产生真实结果。
- 不要写“自动适配”“确保通过”“完美适配”“强烈建议安装”等承诺性表达。
- 如果描述安装后的工作方式，必须使用“如果安装成功且宿主正确加载 Skill，它可能会……”这种条件句。
- 体验剧本只能写成“示例台词/假设流程”：使用“可能会询问/可能会建议/可能会展示”，不要写“已写入、已生成、已通过、正在运行、正在生成”。
- Prompt Preview 不负责给安装命令；如用户准备试装，只能提示先阅读 Quick Start 和 Risk Card，并在隔离环境验证。
- 所有项目事实必须来自 supported claim、evidence_refs 或 source_paths；inferred/unverified 只能作风险或待确认项。

```

### 角色 / Skill 选择

- 目标：从项目里的角色或 Skill 中挑选最匹配的资产。
- 预期输出：候选角色或 Skill 列表，每项包含适用场景、证据路径、风险边界和是否需要安装后验证。

```text
请读取 role_skill_index，根据我的目标任务推荐 3-5 个最相关的角色或 Skill。每个推荐都要说明适用场景、可能输出、风险边界和 evidence_refs。
```

### 风险预检

- 目标：安装或引入前识别环境、权限、规则冲突和质量风险。
- 预期输出：环境、权限、依赖、许可、宿主冲突、质量风险和未知项的检查清单。

```text
请基于 risk_card、boundaries 和 quick_start_candidates，给我一份安装前风险预检清单。不要替我执行命令，只说明我应该检查什么、为什么检查、失败会有什么影响。
```

### 宿主 AI 开工指令

- 目标：把项目上下文转成一次对话开始前的宿主 AI 指令。
- 预期输出：一段边界明确、证据引用明确、适合复制给宿主 AI 的开工前指令。

```text
请基于 supersurf 的 AI Context Pack，生成一段我可以粘贴给宿主 AI 的开工前指令。这段指令必须遵守 not_runtime=true，不能声称项目已经安装、运行或产生真实结果。
```

## 角色 / Skill 索引

- 共索引 1 个角色 / Skill / 项目文档条目。

- **SuperSurf — Agent Skill Guide**（skill）：You control a real Chrome browser. Real cookies, real sessions, real history. You are not using a headless browser or a simulator — you are operating a full Chrome instance with a human's profile. 激活提示：当用户任务与“SuperSurf — Agent Skill Guide”描述的流程高度相关时，先用它做安装前体验，再决定是否安装。 证据：`docs/skill.md`

## 证据索引

- 共索引 61 条证据。

- **SuperSurf**（documentation）：MCP-native browser automation. Any agent. Any model. Real Chrome, via extension — not CDP. 证据：`README.md`
- **supersurf-daemon**（documentation）：Multiplexer for SuperSurf — coordinates multiple MCP sessions sharing one Chrome extension connection. 证据：`daemon/README.md`
- **supersurf-mcp**（documentation）：Free and open-source MCP server for browser automation — gives AI agents control of a real Chrome browser via a Chrome extension. 证据：`server/README.md`
- **Package**（package_manifest）：{ "name": "supersurf-daemon", "version": "3.2.0", "description": "Daemon process for SuperSurf — coordinates multiple MCP sessions sharing one Chrome extension", "keywords": "mcp", "model-context-protocol", "browser-automation", "ai-agent", "daemon", "supersurf" , "homepage": "https://liquidbuiltit.github.io/Supersurf", "bugs": { "url": "https://github.com/liquidbuiltit/Supersurf/issues" }, "main": "dist/main.js", "types": "dist/main.d.ts", "bin": { "supersurf-daemon": "dist/main.js" }, "files": "dist", "README.md", "LICENSE" , "engines": { "node": " =18" }, "os": "darwin", "linux" , "license": "Apache-2.0", "author": "The Media Masons", "repository": { "type": "git", "url": "https://github… 证据：`daemon/package.json`
- **Package**（package_manifest）：{ "name": "supersurf-extension", "version": "3.2.0", "private": true, "description": "SuperSurf Chrome extension for browser automation", "license": "Apache-2.0", "scripts": { "build": "tsc && npx tsx build.ts", "dev": "tsc --watch", "test": "vitest run", "test.watch": "vitest", "zip": "zip -r supersurf-extension.zip ./assets/ ./dist/ ./manifest.json" }, "devDependencies": { "typescript": "~5.5.0", "vitest": "^4.0.18" } } 证据：`extension/package.json`
- **Package**（package_manifest）：{ "name": "supersurf", "version": "3.2.0", "private": true, "description": "MCP browser automation for autonomous AI agents", "license": "Apache-2.0", "workspaces": "shared", "server", "extension", "daemon" , "scripts": { "build.server": "cd server && npm run build", "build.extension": "cd extension && npm run build", "build.shared": "cd shared && npx tsc", "build.daemon": "cd daemon && npm run build", "build": "npm run build.shared && npm run build.daemon && npm run build.server && npm run build.extension", "dev.server": "cd server && npx tsx src/cli.ts --debug", "test.server": "cd server && npm test", "test.extension": "cd extension && npm test", "test.daemon": "cd daemon && npm test", "t… 证据：`package.json`
- **Package**（package_manifest）：{ "name": "supersurf-mcp", "mcpName": "io.github.LiquidBuiltIt/supersurf-mcp", "version": "3.2.0", "description": "Open-source MCP server for browser automation — gives AI agents control of a real Chrome browser via extension", "main": "dist/bin/supersurf.js", "types": "dist/bin/supersurf.d.ts", "bin": { "supersurf": "dist/bin/supersurf.js", "supersurf-mcp": "dist/bin/supersurf-mcp.js", "supersurf-daemon": "dist/bin/supersurf-daemon.js" }, "files": "dist", "README.md", "LICENSE" , "engines": { "node": " =18" }, "os": "darwin", "linux" , "license": "Apache-2.0", "author": "The Media Masons", "repository": { "type": "git", "url": "https://github.com/liquidbuiltit/Supersurf.git", "directory":… 证据：`server/package.json`
- **Package**（package_manifest）：{ "name": "shared", "version": "3.2.0", "private": true, "main": "dist/index.js", "types": "dist/index.d.ts", "scripts": { "test": "vitest run", "test.watch": "vitest" }, "devDependencies": { "@types/node": "^22.0.0", "typescript": "^5.5.0", "vitest": "^4.0.18" } } 证据：`shared/package.json`
- **SuperSurf — Agent Skill Guide**（skill_instruction）：You control a real Chrome browser. Real cookies, real sessions, real history. You are not using a headless browser or a simulator — you are operating a full Chrome instance with a human's profile. 证据：`docs/skill.md`
- **License**（source_file）：The Commons Clause License Condition v1.0 证据：`LICENSE`
- **License**（source_file）：The Commons Clause License Condition v1.0 证据：`daemon/LICENSE`
- **License**（source_file）：The Commons Clause License Condition v1.0 证据：`server/LICENSE`
- **Changelog**（documentation）：All notable changes to SuperSurf are documented in this file. 证据：`CHANGELOG.md`
- **Manifest**（structured_config）：{ "manifest version": 3, "name": "SuperSurf", "version": "3.2.0", "description": "Browser automation for AI agents via MCP", "permissions": "alarms", "cookies", "debugger", "activeTab", "tabs", "storage", "management", "webRequest", "webNavigation", "scripting", "tabGroups", "downloads" , "host permissions": " " , "background": { "service worker": "dist/background.js", "type": "module" }, "action": { "default title": "SuperSurf", "default popup": "dist/popup/popup.html", "default icon": { "16": "assets/icons/icon-16.png", "32": "assets/icons/icon-32.png", "48": "assets/icons/icon-48.png", "128": "assets/icons/icon-128.png" } }, "icons": { "16": "assets/icons/icon-16.png", "32": "assets/icon… 证据：`extension/manifest.json`
- **Cws.Publish**（source_file）：import { readFileSync, existsSync } from 'fs'; import { resolve } from 'path'; import { execSync } from 'child process'; ⋮---- async function getAccessToken : Promise ⋮---- async function upload token: string : Promise ⋮---- async function publish token: string : Promise ⋮---- async function main 证据：`scripts/cws.publish.ts`
- **Publish**（source_file）：import { readFileSync, existsSync } from 'fs'; import { resolve } from 'path'; import { execSync } from 'child process'; ⋮---- const ok = msg: string = console.log $ const fail = msg: string = console.error $ const info = msg: string = console.log $ const warn = msg: string = console.log $ ⋮---- const git = cmd: string = execSync cmd, const run = cmd: string = execSync cmd, ⋮---- type Step = 'github' 'npm:supersurf' 'cws'; ⋮---- function recordFailure step: Step, error: unknown ⋮---- function loadCWSCredentials ⋮---- async function getAccessToken clientId: string, clientSecret: string, refreshToken: string : Promise ⋮---- async function cwsUpload token: string : Promise ⋮---- async function… 证据：`scripts/publish.ts`
- **Index**（source_file）：import type { FileLogger, Config } from 'shared'; ⋮---- const debugLog = ...args: unknown = ⋮---- export interface DaemonExperimentRegistryOptions { defaults?: Config 'experiments' ; } ⋮---- export class DaemonExperimentRegistry ⋮---- constructor opts: DaemonExperimentRegistryOptions = ⋮---- applyDefaults experiments: string : void ⋮---- toggle sessionId: string, experiment: string, enabled: boolean : boolean ⋮---- isEnabled sessionId: string, experiment: string : boolean ⋮---- getAll sessionId: string : Record ⋮---- deleteSession sessionId: string : void ⋮---- initSession sessionId: string : void ⋮---- isAvailable experiment: string : boolean ⋮---- listAvailable : readonly string 证据：`daemon/src/experiments/index.ts`
- **Extension Bridge**（source_file）：import crypto from 'crypto'; import http from 'http'; import { WebSocketServer, WebSocket } from 'ws'; import type { FileLogger } from 'shared'; import { Matchmaker } from './profiles/matchmaker'; import type { PooledConnection } from './profiles/types'; ⋮---- const debugLog = ...args: unknown = ⋮---- function registrationHtml profileName: string : string ⋮---- export class ExtensionBridge ⋮---- constructor port: number = 5555, host: string = '127.0.0.1' ⋮---- get browser : string ⋮---- get buildTime : string null ⋮---- get connected : boolean ⋮---- async start : Promise ⋮---- private handleMessage ws: WebSocket, conn: PooledConnection, data: any : void ⋮---- async sendCmd method: string, p… 证据：`daemon/src/extension-bridge.ts`
- **Main**（source_file）：import fs from 'fs'; import path from 'path'; import os from 'os'; import net from 'net'; import crypto from 'crypto'; import { spawn } from 'child process'; import { FileLogger, ConfigService, HARDCODED DEFAULTS, ensureConfigFile, loadJsonConfig, loadEnvConfig, } from 'shared'; import { ExtensionBridge } from './extension-bridge'; import { SessionRegistry } from './session'; import { RequestScheduler } from './scheduler'; import { IPCServer } from './ipc'; import { DaemonExperimentRegistry } from './experiments/index'; import { ProfileRegistry } from './profiles/registry'; import { ensureExtension } from './profiles/extension-source'; import { replayPidLog, findOrphanPids, killOrphanPids,… 证据：`daemon/src/main.ts`
- **Scheduler**（source_file）：import type { FileLogger } from 'shared'; import type { ExtensionBridge } from './extension-bridge'; import type { SessionRegistry } from './session'; import type { QueuedRequest } from './types'; ⋮---- const debugLog = ...args: unknown = ⋮---- export class RequestScheduler ⋮---- constructor ⋮---- private getCurrentTabId profileId: string null : number null ⋮---- private setCurrentTabId profileId: string null, tabId: number null : void ⋮---- addSession sessionId: string : void ⋮---- removeSession sessionId: string : void ⋮---- enqueue sessionId: string, method: string, params: Record , timeout: number = 30000 : Promise ⋮---- private async drainQueue : Promise ⋮---- private hasQueuedRequests… 证据：`daemon/src/scheduler.ts`
- **Session**（source_file）：import type net from 'net'; import type { DaemonSession } from './types'; ⋮---- export class SessionRegistry ⋮---- add sessionId: string, socket: net.Socket : boolean ⋮---- remove sessionId: string : DaemonSession undefined ⋮---- get sessionId: string : DaemonSession undefined ⋮---- has sessionId: string : boolean ⋮---- get count : number ⋮---- ids : string ⋮---- values : IterableIterator ⋮---- setAttachedTabId sessionId: string, tabId: number null : void ⋮---- getAttachedTabId sessionId: string : number null ⋮---- setGroupId sessionId: string, groupId: number null : void ⋮---- addOwnedTab sessionId: string, tabId: number : void ⋮---- removeOwnedTab sessionId: string, tabId: number : void ⋮… 证据：`daemon/src/session.ts`
- **Index**（source_file）：import { capturePageState } from './capture-page-state.js'; import { waitForDOMStable } from './wait-for-ready.js'; import type { WebSocketConnection } from '../connection/websocket.js'; import type { TabHandlers } from '../handlers/tabs.js'; import type { NetworkTracker } from '../handlers/network.js'; import type { SessionContext } from '../session-context.js'; ⋮---- export class ExperimentalFeatures ⋮---- static registerHandlers wsConnection: WebSocketConnection, tabHandlers: TabHandlers, networkTracker: NetworkTracker, sessionContext: SessionContext : void ⋮---- function pollNetworkIdle tracker: NetworkTracker, idleMs: number, timeout: number : Promise 证据：`extension/src/experimental/index.ts`
- **Index**（source_file）：import { buildMembrane } from './membrane.js'; import type { WebSocketConnection } from '../../connection/websocket.js'; ⋮---- export function registerSecureEvalHandlers wsConnection: WebSocketConnection : void ⋮---- // Code tried to access a blocked API ⋮---- // SyntaxError or other runtime error — code can't reach dangerous APIs 证据：`extension/src/experimental/secure-eval.old/index.ts`
- **Index**（source_file）：import { buildMembrane } from './membrane.js'; import type { WebSocketConnection } from '../../connection/websocket.js'; ⋮---- export function registerSecureEvalHandlers wsConnection: WebSocketConnection : void ⋮---- // Code tried to access a blocked API ⋮---- // SyntaxError or other runtime error — code can't reach dangerous APIs 证据：`extension/src/security/secure-eval/index.ts`
- **Supersurf Daemon**（source_file）：import { dispatch } from './dispatcher'; 证据：`server/src/bin/supersurf-daemon.ts`
- **Supersurf**（source_file）：import { dispatch } from './dispatcher'; 证据：`server/src/bin/supersurf.ts`
- **Bridge**（source_file）：import crypto from 'crypto'; import http from 'http'; import { WebSocketServer, WebSocket } from 'ws'; import { createLog } from './logger'; ⋮---- export interface DialogEvent { type: 'alert' 'confirm' 'prompt' 'beforeunload'; message: string; defaultPrompt: string; url: string; hasBrowserHandler: boolean; timestamp: number; } ⋮---- export interface IExtensionTransport { sendCmd method: string, params?: Record , timeout?: number : Promise ; readonly connected: boolean; readonly browser: string; readonly buildTime: string null; onReconnect: = void null; onTabInfoUpdate: tabInfo: any = void null; notifyClientId clientId: string : void; start : Promise ; stop : Promise ; consumeDialogEvents :… 证据：`server/src/bridge.ts`
- **Index**（source_file）：import type { EvalFn } from '../../tools/lib/element-resolver'; import { getElementCenter } from '../../tools/lib/element-resolver'; import { experimentRegistry } from '../index'; import { getRecord, putRecord } from './store'; import { captureExpr, scoreExpr } from './page-scripts'; import type { Fingerprint, FingerprintRecord, ScoreHit } from './types'; import { mergeHandleMeta } from './handle-meta'; import type { HandleMeta } from './handle-meta'; ⋮---- export function domainOf url: string undefined : string ⋮---- // file:// pages have no hostname but are real, automatable pages — give them // a dedicated bucket route = path instead of collapsing into 'unknown'. ⋮---- export function ro… 证据：`server/src/experimental/fingerprinting/index.ts`
- **Index**（source_file）：import type { ToolSchema, ToolContext } from '../tools/lib/types'; import type { IExtensionTransport } from '../bridge'; import type { Config } from 'shared'; import { storageInspectionSchema, onBrowserStorage } from './storage-inspection'; ⋮---- type ExperimentName = typeof AVAILABLE EXPERIMENTS number ; ⋮---- class ExperimentRegistry ⋮---- bind transport: IExtensionTransport : void ⋮---- unbind : void ⋮---- async toggle feature: string, enabled: boolean : Promise ⋮---- enable feature: string : void ⋮---- disable feature: string : void ⋮---- isEnabled feature: string : boolean ⋮---- reset : void ⋮---- listAvailable : string ⋮---- getStates : Record ⋮---- isAvailable feature: string : boole… 证据：`server/src/experimental/index.ts`
- **Index**（source_file）：import { BALABIT PROFILE, type DistributionProfile } from './profile'; import { generatePersonality, type MousePersonality } from './personality'; import { generatePath, type Waypoint, type Viewport } from './generator'; import { createLog } from '../../logger'; ⋮---- interface HumanizationSession { personality: MousePersonality; cursorX: number; cursorY: number; profile: DistributionProfile; } ⋮---- export function initSession sessionId: string, profile?: DistributionProfile : void ⋮---- export function getSession sessionId: string : HumanizationSession undefined ⋮---- export function destroySession sessionId: string : void ⋮---- export function generateMovement sessionId: string, targetX:… 证据：`server/src/experimental/mouse-humanization/index.ts`
- **Page Diffing**（source_file）：export interface PageState { elementCount: number; textContent: string ; shadowRootCount: number; iframeCount: number; visibleIframeCount: number; hiddenElementCount: number; pageElementCount: number; formValues: Record ; } ⋮---- export interface DiffResult { added: string ; removed: string ; countDelta: number; formChanges: Array ; } ⋮---- export function diffSnapshots before: PageState, after: PageState : DiffResult ⋮---- / Score how reliable the diff is based on page complexity. Starts at 1.0 and applies flat penalties: - Shadow DOM present: -0.05 content may be hidden from snapshot - Iframes present: -0.05 cross-origin content invisible - Large page 5000 elements : -0.05 snapshot may be… 证据：`server/src/experimental/page-diffing.ts`
- **Tools**（source_file）：import type { IExtensionTransport } from './bridge'; import type { ToolSchema, ToolContext } from './tools/lib/types'; import { createLog } from './logger'; import { UsageMetricsLogger } from './usage-metrics-logger'; import { getExperimentalToolSchemas, experimentRegistry } from './experimental/index'; import { resolveWithHealing, captureInContext, healInContext, domainOf, routeOf } from './experimental/fingerprinting/index'; ⋮---- import { getToolSchemas } from './tools/schemas'; import { cdp as cdpFn, evalExpr as evalFn } from './tools/lib/cdp'; import { getElementCenter, getSelectorExpression, findAlternativeSelectors, } from './tools/lib/element-resolver'; import { formatResult, format… 证据：`server/src/tools.ts`
- **Index**（source_file）：import type { ToolContext } from '../lib/types'; import { analyzeCode, wrapWithPageProxy } from './secure-eval'; ⋮---- export async function onEvaluate ctx: ToolContext, args: any, options: any : Promise ⋮---- // Normalize function form to an IIFE expression so it actually executes. // Without this wrap, an arrow function like = 42 parses as a bare // function literal whose return value is discarded, yielding undefined. ⋮---- // Layer 1: Static AST analysis ~1ms ⋮---- // Layer 2: SW Proxy membrane ~10-20ms 证据：`server/src/tools/browser_evaluate/index.ts`
- **Secure Eval**（source_file）：export interface AnalysisResult { safe: boolean; reason?: string; } ⋮---- interface BlockedPattern { nodeType: string; matcher: node: any, ancestors: any = boolean; reason: string; } ⋮---- function isIdentifier node: any, name: string : boolean ⋮---- function isMemberCall callee: any, obj: string, prop: string : boolean ⋮---- export function analyzeCode code: string : AnalysisResult ⋮---- CallExpression node: any, state: any, ancestors: any MemberExpression node: any, state: any, ancestors: any NewExpression node: any, state: any, ancestors: any ImportExpression node: any, state: any, ancestors: any TaggedTemplateExpression node: any, state: any, ancestors: any Literal node: any, state: any… 证据：`server/src/tools/browser_evaluate/secure-eval.ts`
- **Index**（source_file）：import type { ToolContext } from '../lib/types'; import { experimentRegistry, diffSnapshots, calculateConfidence, formatDiffSection } from '../../experimental/index'; import { executeAction } from './registry'; ⋮---- export async function onInteract ctx: ToolContext, args: any, options: any : Promise ⋮---- // Let smooth scroll animations settle before capturing viewport 证据：`server/src/tools/interaction/index.ts`
- **Defaults**（source_file）：import type { Config } from './types'; 证据：`shared/config/defaults.ts`
- **Scaffold**（source_file）：import { SCAFFOLD DEFAULTS } from './defaults'; ⋮---- export interface ScaffoldResult { created: boolean; path: string; } ⋮---- export function ensureConfigFile filePath: string : ScaffoldResult 证据：`shared/config/scaffold.ts`
- **Index**（source_file）：import type { KeychainBackend } from './types'; import { KeychainNotAvailableError } from './types'; import { MacosKeychainBackend } from './macos'; import { LinuxKeychainBackend } from './linux'; ⋮---- export function getKeychainBackend platform: string = process.platform : KeychainBackend 证据：`shared/keychain/index.ts`
- **Tsconfig**（structured_config）：{ "extends": "../tsconfig.base.json", "compilerOptions": { "outDir": "./dist", "rootDir": "./src" }, "include": "src/ / .ts" , "exclude": "dist", "tests", "node modules" } 证据：`daemon/tsconfig.json`
- **Tsconfig**（structured_config）：{ "compilerOptions": { "target": "ES2022", "module": "ES2022", "moduleResolution": "bundler", "lib": "ES2022", "DOM" , "strict": true, "esModuleInterop": true, "skipLibCheck": true, "forceConsistentCasingInFileNames": true, "outDir": "./dist", "rootDir": "./src", "sourceMap": false, "declaration": false }, "include": "src/ / .ts" , "exclude": "dist", "node modules" } 证据：`extension/tsconfig.json`
- **Server**（structured_config）：{ "$schema": "https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json", "name": "io.github.LiquidBuiltIt/supersurf-mcp", "description": "MCP server giving AI agents control of a real Chrome browser via an extension, not CDP.", "repository": { "url": "https://github.com/liquidbuiltit/Supersurf", "source": "github" }, "version": "3.1.1", "packages": { "registryType": "npm", "identifier": "supersurf-mcp", "version": "3.1.1", "transport": { "type": "stdio" } } } 证据：`server/server.json`
- **Tsconfig**（structured_config）：{ "extends": "../tsconfig.base.json", "compilerOptions": { "outDir": "./dist", "rootDir": "./src" }, "include": "src/ / .ts" , "exclude": "dist", "tests", "node modules" } 证据：`server/tsconfig.json`
- **Tsconfig**（structured_config）：{ "extends": "../tsconfig.base.json", "compilerOptions": { "outDir": "./dist", "rootDir": "." }, "include": "./ / .ts" , "exclude": "dist", "node modules", "tests", "vitest.config.ts" } 证据：`shared/tsconfig.json`
- **Tsconfig.Base**（structured_config）：{ "compilerOptions": { "target": "ES2022", "module": "commonjs", "lib": "ES2022" , "strict": true, "esModuleInterop": true, "skipLibCheck": true, "forceConsistentCasingInFileNames": true, "resolveJsonModule": true, "declaration": true, "declarationMap": true, "sourceMap": true } } 证据：`tsconfig.base.json`
- **agent data**（source_file）：agent data CLAUDE.md knowledge/ .claude/ research/ .dialup.config.json .superpowers/ .worktrees/ 证据：`.gitignore`
- **Vitest.Config**（source_file）：import { defineConfig } from 'vitest/config'; 证据：`daemon/vitest.config.ts`
- **Index**（source_file）：SuperSurf — MCP Browser Automation for AI Agents Real Chrome, via Extension { "@context": "https://schema.org", "@type": "SoftwareApplication", "name": "SuperSurf", "applicationCategory": "DeveloperApplication", "operatingSystem": "macOS, Linux", "description": "SuperSurf is an MCP server that gives any AI agent control of a real Chrome browser through a Chrome extension — real profile, cookies, and logins, no CDP.", "url": "https://liquidbuiltit.github.io/Supersurf/", "downloadUrl": "https://www.npmjs.com/package/supersurf-mcp", "codeRepository": "https://github.com/liquidbuiltit/Supersurf", "softwareVersion": "3.1.0", "license": "https://www.apache.org/licenses/LICENSE-2.0", "offers": { "… 证据：`docs/index.html`
- **SuperSurf**（source_file）：SuperSurf is an MCP Model Context Protocol server that gives any AI agent control of a real Chrome browser through a Chrome extension — real profile, cookies, and logins, no CDP. Works with any MCP client Claude, GPT, or anything that speaks MCP . 证据：`docs/llms.txt`
- **Privacy Policy**（source_file）：SuperSurf — Privacy Policy { margin: 0; padding: 0; box-sizing: border-box; } body { font-family: -apple-system, BlinkMacSystemFont, 'Segoe UI', Roboto, sans-serif; font-size: 15px; line-height: 1.7; color: e0e0e0; background: 1a1a1e; padding: 40px 20px; } .container { max-width: 680px; margin: 0 auto; } header { display: flex; align-items: center; gap: 12px; margin-bottom: 32px; padding-bottom: 20px; border-bottom: 1px solid 2a2a30; } header h1 { font-size: 22px; font-weight: 600; color: f0f0f0; } header .version { font-size: 12px; color: 666; margin-left: 4px; } .effective-date { font-size: 13px; color: 666; margin-bottom: 28px; } h2 { font-size: 17px; font-weight: 600; color: f0f0f0; mar… 证据：`docs/privacy-policy.html`
- **Robots**（source_file）：Sitemap: https://liquidbuiltit.github.io/Supersurf/sitemap.xml 证据：`docs/robots.txt`
- **Sitemap**（source_file）：https://liquidbuiltit.github.io/Supersurf/ 2026-06-15 1.0 https://liquidbuiltit.github.io/Supersurf/documentation/ 2026-06-15 0.9 https://liquidbuiltit.github.io/Supersurf/documentation/tools.html 2026-06-15 0.8 https://liquidbuiltit.github.io/Supersurf/documentation/architecture.html 2026-06-15 0.8 https://liquidbuiltit.github.io/Supersurf/documentation/server.html 2026-06-15 0.7 https://liquidbuiltit.github.io/Supersurf/documentation/daemon.html 2026-06-15 0.7 https://liquidbuiltit.github.io/Supersurf/documentation/extension.html 2026-06-15 0.7 https://liquidbuiltit.github.io/Supersurf/documentation/security.html 2026-06-15 0.7 https://liquidbuiltit.github.io/Supersurf/privacy-policy.html… 证据：`docs/sitemap.xml`
- **Build**（source_file）：import fs from 'fs'; import path from 'path'; import { fileURLToPath } from 'url'; ⋮---- function copyAssets dir: string : number 证据：`extension/build.ts`
- **Vitest.Config**（source_file）：import { defineConfig } from 'vitest/config'; 证据：`extension/vitest.config.ts`
- **Cws.Auth**（source_file）：import { createServer } from 'http'; import { readFileSync, writeFileSync } from 'fs'; import { resolve } from 'path'; import { execSync } from 'child process'; 证据：`scripts/cws.auth.ts`
- **Daemon.Bundle**（source_file）：import fs from 'fs'; import path from 'path'; ⋮---- function copyDir src: string, dest: string : number 证据：`scripts/daemon.bundle.ts`
- **Shared.Bundle**（source_file）：import fs from 'fs'; import path from 'path'; ⋮---- function copyDir src: string, dest: string : number ⋮---- function rewriteFile filePath: string : boolean ⋮---- function rewriteDir dir: string : number 证据：`scripts/shared.bundle.ts`
- **Smoke Pack**（source_file）：import { execSync } from 'child process'; import { mkdtempSync, rmSync, readdirSync } from 'fs'; import { tmpdir } from 'os'; import { join, resolve } from 'path'; ⋮---- function run cmd: string, cwd: string : string 证据：`scripts/smoke-pack.ts`
- **Tree**（source_file）：import { execSync } from 'child process'; import path from 'path'; 证据：`scripts/tree.ts`
- **Version.Bump**（source_file）：import { readFileSync, writeFileSync } from 'fs'; import { resolve, join } from 'path'; import { execSync } from 'child process'; ⋮---- const git = cmd: string = execSync cmd, const gitCapture = cmd: string = execSync cmd, 证据：`scripts/version.bump.ts`
- **Vitest.Config**（source_file）：import { defineConfig } from 'vitest/config'; 证据：`server/vitest.config.ts`
- 其余 1 条证据见 `AI_CONTEXT_PACK.json` 或 `EVIDENCE_INDEX.json`。

## 宿主 AI 必须遵守的规则

- **把本资产当作开工前上下文，而不是运行环境。**：AI Context Pack 只包含证据化项目理解，不包含目标项目的可执行状态。 证据：`README.md`, `daemon/README.md`, `server/README.md`
- **回答用户时区分可预览内容与必须安装后才能验证的内容。**：安装前体验的消费者价值来自降低误装和误判，而不是伪装成真实运行。 证据：`README.md`, `daemon/README.md`, `server/README.md`

## 用户开工前应该回答的问题

- 你准备在哪个宿主 AI 或本地环境中使用它？
- 你只是想先体验工作流，还是准备真实安装？
- 你最在意的是安装成本、输出质量、还是和现有规则的冲突？

## 验收标准

- 所有能力声明都能回指到 evidence_refs 中的文件路径。
- AI_CONTEXT_PACK.md 没有把预览包装成真实运行。
- 用户能在 3 分钟内看懂适合谁、能做什么、如何开始和风险边界。

---

## Doramagic Context Augmentation

下面内容用于强化 Repomix/AI Context Pack 主体。Human Manual 只提供阅读骨架；踩坑日志会被转成宿主 AI 必须遵守的工作约束。

## Human Manual 骨架

使用规则：这里只是项目阅读路线和显著性信号，不是事实权威。具体事实仍必须回到 repo evidence / Claim Graph。

宿主 AI 硬性规则：
- 不得把页标题、章节顺序、摘要或 importance 当作项目事实证据。
- 解释 Human Manual 骨架时，必须明确说它只是阅读路线/显著性信号。
- 能力、安装、兼容性、运行状态和风险判断必须引用 repo evidence、source path 或 Claim Graph。

- **项目概览与设计理念**：importance `high`
  - source_paths: README.md, CHANGELOG.md, package.json, LICENSE
- **系统架构与组件交互**：importance `high`
  - source_paths: server/src/bin/supersurf.ts, server/src/bin/supersurf-daemon.ts, server/src/bridge.ts, daemon/src/main.ts, daemon/src/scheduler.ts
- **MCP 工具集、扩展内容脚本与安全机制**：importance `high`
  - source_paths: server/src/tools.ts, server/src/tools/interaction/index.ts, server/src/tools/browser_evaluate/secure-eval.ts, server/src/experimental/mouse-humanization/index.ts, server/src/experimental/page-diffing.ts
- **部署、平台支持与运维**：importance `high`
  - source_paths: server/package.json, daemon/package.json, extension/manifest.json, shared/config/defaults.ts, shared/config/scaffold.ts

## Repo Inspection Evidence / 源码检查证据

- repo_clone_verified: true
- repo_inspection_verified: true
- repo_commit: `f724e9b0bb12d1b2b48055f85c1348dfd0069317`
- inspected_files: `README.md`, `package.json`, `docs/skill.md`

宿主 AI 硬性规则：
- 没有 repo_clone_verified=true 时，不得声称已经读过源码。
- 没有 repo_inspection_verified=true 时，不得把 README/docs/package 文件判断写成事实。
- 没有 quick_start_verified=true 时，不得声称 Quick Start 已跑通。

## Doramagic Pitfall Constraints / 踩坑约束

这些规则来自 Doramagic 发现、验证或编译过程中的项目专属坑点。宿主 AI 必须把它们当作工作约束，而不是普通说明文字。

### Constraint 1: 可能修改宿主 AI 配置

- Trigger: 项目面向 Claude/Cursor/Codex/Gemini/OpenCode 等宿主，或安装命令涉及用户配置目录。
- Host AI rule: 列出会写入的配置文件、目录和卸载/回滚步骤。
- Why it matters: 安装可能改变本机 AI 工具行为，用户需要知道写入位置和回滚方法。
- Evidence: capability.host_targets | https://github.com/LiquidBuiltIt/Supersurf | host_targets=claude, mcp_host
- Hard boundary: 不要把这个坑点包装成已解决、已验证或可忽略，除非后续验证证据明确证明它已经关闭。

### Constraint 2: 能力判断依赖假设

- Trigger: README/documentation is current enough for a first validation pass.
- Host AI rule: 将假设转成下游验证清单。
- Why it matters: 假设不成立时，用户拿不到承诺的能力。
- Evidence: capability.assumptions | https://github.com/LiquidBuiltIt/Supersurf | README/documentation is current enough for a first validation pass.
- Hard boundary: 不要把这个坑点包装成已解决、已验证或可忽略，除非后续验证证据明确证明它已经关闭。

### Constraint 3: 维护活跃度未知

- Trigger: 未记录 last_activity_observed。
- Host AI rule: 补 GitHub 最近 commit、release、issue/PR 响应信号。
- Why it matters: 新项目、停更项目和活跃项目会被混在一起，推荐信任度下降。
- Evidence: evidence.maintainer_signals | https://github.com/LiquidBuiltIt/Supersurf | last_activity_observed missing
- Hard boundary: 不要把这个坑点包装成已解决、已验证或可忽略，除非后续验证证据明确证明它已经关闭。

- Trigger: no_demo
- Evidence: downstream_validation.risk_items | https://github.com/LiquidBuiltIt/Supersurf | no_demo; severity=medium
- Hard boundary: 不要把这个坑点包装成已解决、已验证或可忽略，除非后续验证证据明确证明它已经关闭。

### Constraint 5: 存在评分风险

- Trigger: no_demo
- Why it matters: 风险会影响是否适合普通用户安装。
- Evidence: risks.scoring_risks | https://github.com/LiquidBuiltIt/Supersurf | no_demo; severity=medium
- Hard boundary: 不要把这个坑点包装成已解决、已验证或可忽略，除非后续验证证据明确证明它已经关闭。

### Constraint 6: issue/PR 响应质量未知

- Trigger: issue_or_pr_quality=unknown。
- Host AI rule: 抽样最近 issue/PR，判断是否长期无人处理。
- Why it matters: 用户无法判断遇到问题后是否有人维护。
- Evidence: evidence.maintainer_signals | https://github.com/LiquidBuiltIt/Supersurf | issue_or_pr_quality=unknown
- Hard boundary: 不要把这个坑点包装成已解决、已验证或可忽略，除非后续验证证据明确证明它已经关闭。

### Constraint 7: 发布节奏不明确

- Trigger: release_recency=unknown。
- Host AI rule: 确认最近 release/tag 和 README 安装命令是否一致。
- Why it matters: 安装命令和文档可能落后于代码，用户踩坑概率升高。
- Evidence: evidence.maintainer_signals | https://github.com/LiquidBuiltIt/Supersurf | release_recency=unknown
- Hard boundary: 不要把这个坑点包装成已解决、已验证或可忽略，除非后续验证证据明确证明它已经关闭。
