Problem
The Agent Browser integration is an observation-only session. Its viewer is host-local; it has no authenticated user gateway, input arbitration, or verified trading account/mode. Browser order execution cannot safely use a browser that the user cannot privately sign into and hand back.
Agent deliverable
- Add an Open trading browser action and session card bound to the managed user, agent, browser host instance, session ID, and generation. Show sign-in, observe-only, paper-verified, live-locked, and takeover states.
- Integrate a short-lived viewer grant checked on both HTTP and WebSocket upgrade by a private gateway. Keep raw noVNC/VNC loopback-only; never expose controller tokens in URLs or Cloud DM.
- Give the human exclusive input during login/MFA/account choice. ATS receives no frames or page text then. Hand back only after a site verifier proves HTTPS origin, signed-in state, opaque account fingerprint, and positive paper/live mode; unsupported or ambiguous sites remain observe-only.
- Rotate generation and revoke ATS observation, previews, and arms immediately on human input, account/mode/origin/tab change, restart, adapter change, or profile restore. Optional encrypted profile persistence needs explicit retention and Forget session.
- Keep site-specific selectors and scoped navigation allowances in a private browser-host extension, not the generic public browser API.
Acceptance
On one pinned browser image and candidate paper site, the owner logs in through the authenticated viewer, selects an account there, then receives a sanitized read in the same Agent session after handback. Wrong user, replay, cross-origin WebSocket, second owner, login takeover, account flip, and browser restart cut off ATS immediately. No order action exists at this gate.
Evidence and dependency
src/core/agent_browser_session.ts describes the current view as observation only; packages/ats-skills/src/browser.js provides bounded snapshots. See docs/specs/2026-09-23-ats-agent-browser-remaining-gates-v2.md G2 and section 3. Requires companion app gateway and private Agent Browser host work; do not publish the raw noVNC service.
Problem
The Agent Browser integration is an observation-only session. Its viewer is host-local; it has no authenticated user gateway, input arbitration, or verified trading account/mode. Browser order execution cannot safely use a browser that the user cannot privately sign into and hand back.
Agent deliverable
Acceptance
On one pinned browser image and candidate paper site, the owner logs in through the authenticated viewer, selects an account there, then receives a sanitized read in the same Agent session after handback. Wrong user, replay, cross-origin WebSocket, second owner, login takeover, account flip, and browser restart cut off ATS immediately. No order action exists at this gate.
Evidence and dependency
src/core/agent_browser_session.ts describes the current view as observation only; packages/ats-skills/src/browser.js provides bounded snapshots. See docs/specs/2026-09-23-ats-agent-browser-remaining-gates-v2.md G2 and section 3. Requires companion app gateway and private Agent Browser host work; do not publish the raw noVNC service.