Skip to main content

Stuntkit

Give your AI agent a browser it can use safely. Stuntkit is the code Stunt Double runs on every agent session, extracted and published so you can use it in your own agents, read exactly what it does and send fixes back.

It is open source under the Apache-2.0 license and published to npm under the @stdbl scope.

What's in it

PackageWhat it doesSource
@stdbl/browser-toolsetBrowser tools for AI agents over any browser you bring, with opt-in safety guardsstunt-double/stuntkit
@stdbl/workerThe self-hosted worker CLI and Docker image that runs Stunt Double sessions inside your networkstunt-double/worker
@stdbl/relayThe WebSocket relay that pairs a worker with the cloud agent, so neither side accepts inbound connectionsstunt-double/worker

More packages are on the way to Stuntkit, starting with the American and British spelling localizer this site uses and the Continuity icon set.

Why it's open source

A browser agent on someone else's site is a liability until you can see what it will refuse to do. Telling a model "never pay or sign up" in a prompt is a request it can ignore. Stuntkit puts that rule in the tools instead: when a guard refuses, the click never reaches the page. You can read every guard, test it and change it.

The worker runs inside your network, so your security team should be able to read it before it does. Now they can.

Contribute

Issues and pull requests are welcome on both repositories. Each has a CONTRIBUTING.md with the local setup, and every commit needs a Developer Certificate of Origin sign-off (git commit -s). Report security issues privately through GitHub rather than in a public issue.

Next steps