Containment.
See SECURITY.md — ptyclose reports leaderGroupGone, ttyProcessesKilled and uncontainedPids separately, and containmentVerified is true only when nothing survived.
How to use it
Containment. is exposed by the Mac Developer Bridge MCP server. Add the server to your MCP client (Claude Desktop, Cursor, Windsurf and others), and the Containment. tool becomes available to the model automatically. See the full listing for setup details and every tool this server provides.
FULL MAC DEVELOPER BRIDGE LISTINGOther tools in Mac Developer Bridge (34)
Apply or check a unified diff with git apply
Read the local bridge audit tail
Runtime identity, paths, permissions context, shell, audit mode, Codex binary, focus policy, and background-Chrome status
Inspect the installed ChatGPT Chrome extension, OpenAI native-host registration, and live read-only page-bridge status without patching the OpenAI extension
Click an element in an approved tab without foregrounding Chrome
Release an MDB workspace tab back to the idle pool, or close a non-workspace background tab
Fill inputs, textareas, selects, or contenteditable fields in the background
Navigate an approved tab without selecting it
Lease an idle tab from the persistent MDB group and open a URL without creating a new tab
Read visible text and interactive elements from an approved tab
List tabs in the real signed-in Chrome profile without activating Chrome; scoped only when Strict approvals is on
Create or expand the MDB pool while Chrome is already foreground; default target is eight reusable tabs
Inspect the extension-owned MDB Chrome group, lease activity, and reusable background-tab pool; no website grant required
Search and page stored Codex threads
Read a stored Codex thread without resuming it
Page stored turns with full, summary, or omitted items
The session cap is taken, not merely checked, so concurrent ptystart calls cannot exceed it.
Recursive or non-recursive directory listing
mkdir, remove, move, copy, chmod, or symlink
Read text or base64 with offset pagination
lstat metadata and symlink target
Atomic replace, create, append, or binary write
End the session and reclaim it
Read the transcript from a byte cursor, optionally long-polling
Change the window size, confirmed by a kernel read-back
Signal the session's process group
Start a program on a real terminal and return a session id
Send keystrokes, including control characters
Each session keeps the last MACDEVBRIDGEPTYRINGBYTES of output in a fixed ring; ptyread reports lostBytes when a cursor falls behind it.
Run any foreground shell command, optionally with cwd, env, stdin, timeout, and output cap
Signal a background process group
List persistent job metadata
Inspect running state and log tails
Start a detached long-running process