VectorOxide

One browser.
You and the agent both look.

VectorOxide is a real browser pane inside VectorBrain. What the agent reads is the page in front of you, in the session you signed into, and it asks before it touches anything.

VectorOxide full screen inside VectorBrain, on its start screen: a new tab beside two open ones, the address bar, and at its right the buttons Find, Keep, Ask, Save, Capture, Taste and Full screen. Under the VECTOROXIDE wordmark, twelve kept pages, and a footnote: reading a page marks that turn external.
With a page open
The buttons at the right of the address bar: Find, Keep, then Ask, Save, Capture and Taste, then Full screen.
  1. FindCtrl F
  2. Keepto the start screen
  3. Askabout this page
  4. Saveits words, to web/
  5. Capturea picture, to media/
  6. Tastewith a note on why
  7. Full screenF11, Esc to leave

VectorOxide’s real start screen, running on example data. The kept pages are invented.

01

It reads what you are looking at.

pane.read returns the page’s text and numbers its buttons, links and fields itself, fresh on every read. A click names a number from the read just before it.

At most 120 elements and 32,000 characters per read. A longer page is read in part, and the answer says so.

How a run works

find the first Saturday crossing

A conversation with Ivo Marchetti. The request asks for the first Saturday crossing on the ferry timetable. The pane.read step is opened: the page’s address, title and text, then its interactive elements, each with a number, a tag and a label, such as 4, a link, Saturday 09:25.
02

Every click asks, in words.

A click, a fill, a key press or a scroll stops for you, whatever your trust level. The card names the element in the page’s own words and shows where a link really goes.

Shown here on example data. On the one live run so far the standing grant was on, so this card has not yet been seen on a real site.

What an approval replays
An approval card in the conversation: Click the “Saturday 09:25” link, on harborferries.example. The link goes to https://harborferries.example/book?sailing=sat-0925. A note says the element is named the way the page labels it and that this happens on the website, not on your computer. Allow, Refuse, a box to stop asking about clicks and typing until the app restarts, and the line that refusing is a normal answer, not a failure.
03

Twelve tabs. Zoom per site.

Up to 12 tabs, each its own webview on one shared profile. Every agent command means the tab in front, so it never works in a tab you cannot see.

Zoom is kept per site, 25% to 500%. Ask pins the page to your next message; Save and Capture keep it in the project.

Where a capture lands
The browser pane’s bar. Four tabs: the ferry timetable in front, fares, tide tables and a coast forecast. Below, home, back, forward and reload, the address https://harborferries.example/timetable, a 125% zoom chip, find, keep, and buttons to ask about the page, save it, capture it, save it to Taste and leave full screen.
The pane’s own bar, from the desktop build. The page area below it is a native webview, which the capture harness cannot draw.
Placeholder

Screenshot: the pane with a real page loaded.

Needs the running app rather than the capture harness, because the webview is native. Not captured yet.

04

You sign in. It never types a password.

A fill aimed at a password field is refused. An approval stores its input as it will run, so a password in one would sit in the app’s database while you decided.

You sign in yourself, and the agent then works inside that session.

Where credentials live
The VectorOxide start screen with nothing kept: the wordmark and Native Rust Browser, the line “A window onto the public web, opened inside your workspace”, and three rules. You type the address: there is no search engine here, https and the public web only. You sign in, not the agent: it can never type a password. Every action waits for you, unless you grant it autonomy.
05

Done once, on a live site.

On 2026-09-13 the agent opened a live page, read it, clicked through, filled a four-field form and submitted it, in the pane, in real time. Four runs, journal rows 59461 to 59585.

The standing autonomy grant was on, so none of those clicks stopped to ask.

What has shipped
Placeholder

Screen recording: the 2026-09-13 run, in the pane.

The agent opening a page, reading it, clicking through, filling a four-field form and submitting, in real time. Not recorded yet. The caption will say whether the standing autonomy grant was on or off when it was made.

Also in the code

A page cannot reach your files.

pane.open, pane.read, pane.act and pane.capture count as outside data. Once a run uses one, it can make a new document but cannot change what exists, delete or run anything until your next message. And the pane’s webview carries none of the app’s code, so a page loaded in it cannot call the app at all.

vb-cmd-pane/src/pane.rsThe taint rule

https and the public web.

An address is checked before the pane hears it, and every navigation the page makes for itself is checked again. A plain-http hop is retried over https. The one loopback address it opens is a dev server this app started.

vb-cmd-pane/src/lib.rs · navigation_allowed, secure_formThe dev server, when it codes

Keep a page two ways.

Save writes the page’s words into the project’s web/ folder, which the agent can only read back through a command that marks the run external. Capture photographs what you see into media/, and only you can press it.

vb-cmd-browser · browser.save; vb-cmd-pane · pane.capture

Headless reads, visible hands.

The agent can also read a page away from you, in a separate logged-out engine. Click and fill exist only in this pane, where you can see them happen.

vb-cmd-browser; vb-cmd-pane
What it will not do

Deliberately absent. Even the start screen’s icons are letters on a colour made from the address, so opening it tells nine sites nothing.

At a glance

VectorOxide, by the numbers.

Tabs
12 at most. Each is a browser process of around 100 MB, so the cap is in code.vb-cmd-pane/src/lib.rs · MAX_TABS
Elements per read
120, numbered fresh on every read.vb-cmd-pane/src/lib.rs · MAX_ELEMENTS
Text per read
32,000 characters.vb-cmd-pane/src/lib.rs · MAX_TEXT
Text per fill
4,000 characters. Never into a password field.vb-cmd-pane/src/lib.rs · MAX_FILL
Actions
click, fill, press, scroll. Each asks unless you granted autonomy.vb-cmd-pane/src/lib.rs · ACTIONS
Zoom
25% to 500%, on Chromium’s 17-step ladder, remembered per site.ui/src/Browser.tsx · ZOOM_STEPS
Engine
A WebView2 child webview the app places over the stage. Windows only today.vb-app/src/pane.rs
Largest capture
32 MB.vb-cmd-pane/src/lib.rs · CAPTURE_CAP

The details,
for the careful.

Can the agent use sites I am signed into?

Yes. The pane is one shared browser profile, so the agent reads and acts inside the session you opened. It cannot sign in for you: a fill aimed at a password field is refused, and you type your own passwords.

Will the agent click things without asking?

Not unless you say so. Every click, fill, key press and scroll stops for approval at every trust level. You can lift that for the rest of the app session with a box on the card, or grant standing autonomy in Settings, Trust. Only a person can grant either.

What happens to my files after the agent reads a web page?

That run can no longer change anything that already exists, delete or run anything. It can still read, answer and write what it found as something new: a Canvas document, or a .md, .txt or .csv file under the project’s web/ folder, both marked as from the web. Your next message starts a new run without the restriction. The taint rule

Can a web page in the pane control VectorBrain?

No. The pane’s webview carries no capability and no script of the app’s, so a page loaded in it cannot reach the command bus. That was probed in the running app rather than assumed.

Can it work in a tab I am not looking at?

No. Every pane command acts on the tab in front. An agent that wants another page opens a new tab, which comes to the front where you see it.

Has the approval card been shown on a real website?

Not yet. The live run on 2026-09-13 had the standing autonomy grant on, so none of its clicks stopped to ask. The card on this page is drawn from example data.

Which platforms does the browser pane run on?

Windows. The pane is a WebView2 webview, and driving it works on Windows only today. Platform details

Look at the web together.
It asks before it touches.

One pane, one session, and every click on a card you can read before it happens.