Rust 实现驱动系统自带 WebView 的 MCP 协议浏览器,macOS/WebKit 环境下 24ms 响应、9 个 MCP 工具,开源轻量替代 Playwright 方案。
Houston,我们删掉了 Chromium:你的 Agent 浏览器只有 594 KB,随系统一起发布。完整 WebKit,MCP 原生,常驻模式 24 ms。
如今每一个触网的 AI Agent 都拖着同样的累赘:headless Chromium。
Playwright 每次在 Agent 所在的机器上下载约 400 MB 的浏览器。云浏览器 API(Browserbase、Steel、Hyperbrowser)以订阅方式向你租用 Chrome——而且你的页面数据离开了你的机器。而所有这些只是为了完成 Agent 真正需要做的事:打开一个页面、读取内容、截一张图、点击一个按钮、填写一个表单。
与此同时,你的电脑已经自带了一个完整的浏览器引擎。macOS 有 WebKit。Windows 有 WebView2——也就是 Chromium,不过是预装的。Linux 有 WebKitGTK。
所以我构建了 navette(法语"穿梭机"的意思):一个单独的 Rust 二进制文件,驱动你操作系统自带的 WebView,并且说 MCP 协议——也就是 Agent 们已经在用的协议。
594 KB 安装大小。不需要 Chromium。不需要下载。
navette serve --port 8765 # HTTP API on loopback
navette mcp # MCP stdio server for agent hosts
navette install-daemon # resident: warm from login
一个二进制文件,三种运行模式。
Nine MCP tools: navigate, read, screenshot, click, type, evaluate, wait, sessions, session_close. The screenshot comes back as MCP image content — your agent literally sees the page.
九个 MCP 工具:navigate、read、screenshot、click、type、evaluate、wait、sessions、session_close。截图以 MCP image content 的形式返回——你的 Agent 能真正"看见"页面。
底层实现:每个会话一个 WKWebView,运行在一个幽灵窗口中(真实的像素,停在屏幕外所以能渲染但无人可见)。导航完成是事件驱动的——我在 Rust 中用原始 objc2 消息发送实现了 WKNavigationDelegate,内容提取在 didFinish 回调中运行,所以一次热导航 + 完整 markdown 读取只需要 8 ms。
Same machine (M1, 8 GB), same corpus (100 local pages + 20 real URLs), reproducible with one command (python3 navbench.py):
同一台机器(M1, 8 GB),同一份语料(100 个本地页面 + 20 个真实 URL),一条命令可复现(python3 navbench.py):
两个必须坦诚的披露,因为基准测试帖子的生命线就是透明:
Lightpanda is the fastest page-reader (3.3 ms through a zero-bias raw-CDP probe — I measured it through a fair minimal client, not just through Playwright). It parses a partial DOM and cannot render, screenshot, or act. If your agent only reads static pages, use it — or plain fetch + readability.
Lightpanda 是最快的页面读取器(通过零偏差的原始 CDP 探测只需 3.3 ms——我通过一个公平的最小化客户端测量,不只是通过 Playwright)。它解析部分 DOM,无法渲染、截图或交互。如果你的 Agent 只需要读取静态页面,用它——或者直接用 fetch + readability。
The two rows Lightpanda wins (fresh boot, peak RAM) are the price of rendering. Three WebKit helper processes and a backing store are what buy screenshots and full fidelity. That tax is the product.
Lightpanda 获胜的两项(全新启动、峰值内存)是渲染的代价。三个 WebKit 辅助进程和一个后备存储换来的是截图和完整保真度。这份代价就是产品本身。
The claim I'll defend: nobody else combines 0.6 MB + 1 ms actions + a 0.9 s hundred-page crawl + full WebKit rendering + a resident 24 ms mode.
我的核心论点:没有人能同时做到 0.6 MB + 1 ms 操作 + 0.9 秒百页爬取 + 完整 WebKit 渲染 + 常驻 24 ms 模式。
说服我的演示
I pointed the resident daemon at a login form and a research loop and let an agent drive through MCP only:
我把常驻守护进程对准一个登录表单和一个研究循环,让 Agent 只通过 MCP 驱动:
Act 1 — authenticate: type credentials, click, verify the session ("You logged into a secure area!"), screenshot the authenticated page.
第一幕——认证:输入凭据、点击、验证会话("你已登录安全区域!")、给已认证页面截图。
Act 2 — research: DuckDuckGo → extract results → open one (it was dead — moved on) → read the article → screenshot.
第二幕——研究:DuckDuckGo → 提取结果 → 打开一个(它已失效——继续下一个)→ 读取文章 → 截图。
Full walkthrough with the verbatim tool calls and screenshots is in demo/JOURNEY.md.
完整的演练过程(含原始工具调用和截图)见 demo/JOURNEY.md。
cargo build --release
./target/release/navette serve --port 8765
# or let your agent host own the lifecycle:
./target/release/navette mcp
Register it in any MCP client (ZCode example):
在任何 MCP 客户端中注册(ZCode 示例):
{ "mcp": { "servers": { "navette": {
"command": "/path/to/navette", "args": ["mcp"] } } } }
Then just talk to your agent: "open this dashboard, check if the deploy banner is there, screenshot it for me."
然后直接对你的 Agent 说:"打开这个仪表盘,检查部署横幅是否在,给我截图。"
macOS today. Windows (WebView2) and Linux (WebKitGTK/WPE) are the next backends — the 8 primitives are engine-agnostic by design, and the engine strategy is written down: system-first, official embed (WebView2 Fixed Version) or distro packages as fallback. Never vendor a browser the way Playwright does.
目前支持 macOS。Windows(WebView2)和 Linux(WebKitGTK/WPE)是下一个要做的后端——8 个原语在设计上与引擎无关,引擎策略已写成文档:优先使用系统提供的,官方嵌入(WebView2 Fixed Version)或发行版包作为备选。绝不要走 Playwright 那种 vendor 一个浏览器的老路。
The automation long tail is missing. Network interception, file uploads, hover, dialogs — Playwright has twenty years of API surface. The core agent loop (navigate, read, see, act, wait, sessions) is complete; the tail is the roadmap.
自动化领域的长尾需求还是空白。网络拦截、文件上传、悬停、对话框——Playwright 有二十年的 API 积累。核心 Agent 循环(navigate、read、see、act、wait、sessions)已经完整;长尾部分在路线图上。
Fresh-process cold start can't beat a blind engine. A full WebKit spawns three helper processes; Lightpanda spawns none because it renders nothing. That's why navette ships a resident mode: warm from login, 24 ms forever.
全新进程的冷启动无法击败一个无渲染引擎。完整的 WebKit 会生成三个辅助进程;Lightpanda 不会生成任何进程,因为它不渲染。这就是为什么 navette 提供常驻模式:从登录起就热备,永久 24 ms。
Headless Chromium is the Postgres of web automation. navette is trying to be the embedded SQLite — the browser agents bring with them, for the fastest-growing half of the agent world: agents that run locally, on machines that already have an engine.
无头 Chromium 是网络自动化的 Postgres。navette 试图成为嵌入式 SQLite——Agent 自带的浏览器,面向 Agent 世界增长最快的那一半:本地运行、在已有引擎的机器上的 Agent。
Apple shipped a Safari MCP server for coding agents this year. The thesis is being validated from above. navette is it from below: tiny, open, cross-platform-bound.
苹果今年为编程 Agent 发布了一个 Safari MCP server。这个论点正从上游得到验证。navette 则是从下游来做这件事:小巧、开源、跨平台。
Repo, benchmarks and the reproducible harness: https://github.com/slabbdev/navette
代码库、基准测试和可复现测试工具:https://github.com/slabbdev/navette
If you run agents locally, I'd genuinely love your feedback — especially the failure cases.
如果你在本地运行 Agent,我真心希望得到你的反馈——尤其是失败案例。