Visual edit skill

Open and collaboratively edit a running local app in Design, with shared fallback previews and source handoff.

by BuilderIO·MIT license·★ 4,514 Stars on the repo·GitHub ↗

Use now

Files of Visual edit

BuilderIO/main1 file shown
SKILL.md
Show the full text609 lines

Visual Edit

Use /visual-edit when the user wants to inspect or edit a real local app visually instead of generating standalone Alpine HTML. The source of truth is the running localhost app plus its route URLs. Design shows those routes as iframe-backed screens on the infinite canvas.

The editor is hosted at https://design.agent-native.com. Never start local Design; only the target app and bridge run locally.

See the Visual Edit guide for a worked onboarding-flow example.

Fast local startup

  • Do not install this skill into the target app or start a local Design server. The skill belongs to the coding host; Design is always the hosted app above.
  • If you need to start an Agent-Native framework app yourself, use AUTH_DISABLED=1 with its normal dev command. This is local-only and gives the visual editor the framework's dev identity without a user login.
  • If an agent-owned local server redirects a requested screen to /sign-in, restart that server with AUTH_DISABLED=1 and probe the route again before opening Design. Never present a sign-in page as the requested screen.
  • Before calling open-visual-edit, verify the target URL responds. Start an agent-owned dev server with its normal command when it is down, and wait for the requested routes to respond before opening Design. Never leave a dead localhost URL in the canvas.
  • Preserve a server you did not start; use its existing authenticated browser session or explain that the target app, rather than Design, requires login.
  • When the user gives explicit paths, skip route inventory and place those paths directly. Discover routes only when paths were not supplied.

Installation

npx @agent-native/core@latest skills add visual-edit installs the skill and hosted Design MCP connector. npx skills@latest add BuilderIO/agent-native --skill visual-edit installs instructions only; page-capable WebMCP hosts need no connector installation.

Put Design Beside The Chat

Prefer the MCP App from open-visual-edit: it keeps Design beside chat. Use Copy prompt to hand the visual edits to the coding agent; the host may request conversation confirmation. Otherwise, openUrl is a credential-free, read-only fallback; never claim it is editable.

  • Inline-browser hosts should open https://design.agent-native.com/visual-edit and call its open-visual-edit WebMCP tool. It works signed in or out; the one-time capability is not a Design account session. A page-capable browser controller is enough, so Claude-in-Chrome, Claude Code browser tools, the ChatGPT Chrome/browser extension, Puppeteer or Playwright MCP, CDP, and similar JavaScript-capable controllers do not need the hosted MCP connector.
  • VS Code uses its Design webview/deep link. Without page WebMCP, use the hosted Design MCP connector and its normal OAuth/device authorization. Never replace either path with a local Design server.

Inside Design, use Show/Hide UI from the Cmd K menu or press Figma's Shift \ shortcut to toggle all editing chrome so only the canvas remains.

Browser WebMCP (Default Without Connector)

Without a connected Design MCP, use a visible browser tab with a main-world JavaScript evaluator. Prefer the host's inline browser; use external Chrome only when requested or unavailable. Open https://design.agent-native.com/visual-edit, keep it visible while tools register, and read the title before work. Never enter, copy, or request passwords, cookies, tokens, or codes. Signed-out loopback visual-edit works; other pages that block tools behind sign-in still require a signed-in tab. If the browser exposes CDP permissions, grant local-network-access to https://design.agent-native.com before calling page tools; otherwise use the page's Connect button and let the browser's permission prompt complete.

Use a native browser-session WebMCP bridge when the host provides one: list once with list-browser-session-webmcp-tools and run with run-browser-session-webmcp-tool, or use the list-host-webmcp-tools and run-host-webmcp-tool pair. Preserve the exact discovered name, origin, and args. Otherwise use the page-world API. Agent-Native pages expose this helper:

Example assumes signed-in or existing bridge; fresh signed-out loopback must add the locally held bridgeToken described below.

const an = window.__agentNativeWebMcp;
const status = await an.ready({ waitMs: 20_000 });
if (status.state !== "ready") throw new Error(status.error ?? status.state);
const tools = await an.tools("visual-edit");
if (!tools.some((tool) => tool.name === "open-visual-edit")) {
  throw new Error("open-visual-edit is not registered yet");
}
const result = await an.call("open-visual-edit", {
  devServerUrl: "http://localhost:5173",
  paths: ["/"],
  navigate: true,
}, { waitMs: 2_000 });
if (result.state === "pending") {
  // On the next evaluation, read the still-running call without replaying it.
  an.result(result.id);
}

If the helper is absent, use standard WebMCP directly. document.modelContext is canonical; navigator.modelContext is deprecated:

const ctx = document.modelContext;
const tool = (await ctx.getTools()).find((candidate) => candidate.name === NAME);
if (!tool) throw new Error(`WebMCP tool not found: ${NAME}`);
const codex = typeof ctx.codexExecuteTool === "function" ||
  typeof ctx.codexGetTools === "function";
const result = await ctx.executeTool(tool, codex ? ARGS : JSON.stringify(ARGS));

The helper handles live discovery, partial registries, and pending calls. If a call returns state: "pending", read an.result(id) on the next evaluation; never replay a write. For Claude Code or Cowork, javascript_tool runs this page-world code with top-level await; for Codex open the page with cua.createBrowserTab("iab", url, { visible: true }), then use CDP Runtime.evaluate with awaitPromise: true; Puppeteer and Playwright MCP can use their page evaluator. Playwright isolated worlds cannot see document.modelContext. Keep evaluator output small, batch dependent calls, and do not navigate inside a batch.

Tool descriptors are page-local. Do not copy them into the host, hand-build authenticated HTTP requests, or replace named tools with clicks, typing, DOM automation, or screenshots. UI automation remains appropriate for canvas work without a named tool or when requested. If both bridges are unavailable after one discovery and one independent evaluator check, use hosted MCP/CLI before changing state.

For a fresh signed-out loopback connection, generate the bridge token locally, start the durable bridge with it, and pass that same token once as the page tool's bridgeToken; the page never returns it. Reuse a matching running bridge without the token. Account-backed or private Design work requires a signed-in session or the authenticated Design MCP connector. After canvas edits, call an.call("get-visual-edit-prompt", {}, { waitMs: 2_000 }) and apply the returned handoff. The page tool may show an approval dialog; let the user approve it and never bypass that consent.

Core Model

  • Each screen is a URL-backed iframe, not copied HTML.
  • Each screen keeps URL metadata: connectionId, routeId, path, url, bridgeUrl, title, and viewport size.
  • The owner edits through the local bridge. Shared /visual-edit/:designId?share=1 links render a sanitized inert snapshot, refreshed on route or DOM changes; guests never reach the owner's localhost. Guest edits stay pending until an owner or editor applies them to source.
  • Authorized viewers and commenters on private designs can edit the shared Visual Edit canvas and submit pending changes without writing design files. The owner or editor applies those source changes.
  • The /visual-edit skill needs no Design account sign-in. open-visual-edit mints a five-minute, single-use capability for the exact /visual-edit/:designId local-editor route. The MCP host redeems it outside model-visible text, then opens the existing editor with localhost edit access. A public /visual-edit/:designId route enables browser-only DOM editing of public localhost snapshots; handoffs stay pending until applied. The owner sees Apply edits when a recipient has pending changes. This capability is not an account session: /_agent-native/session remains signed out, and account-backed save/share/generate actions remain denied.
  • Hosted MCP highlights get-visual-edit-pending; pass the visual-edit design ID for a tab-free handoff. It returns a revision; after applying, call acknowledge-visual-edit-pending with that revision, then pull again. empty means no edits; session-ended means edits were lost; unknown means the marker was unreadable, not proof of no change.
  • Browser hosts can use page-local get-visual-edit-prompt.
  • The open-visual-edit action is owned by Design. From another app, use the hosted MCP server at https://design.agent-native.com/mcp or the page's WebMCP helper, not pnpm action in the target app. The page path works signed out only for loopback apps in public mode, using a short-lived capability-scoped principal; hosted MCP uses its normal OAuth identity.
  • Ordinary public links stay read-only. Public /visual-edit/:designId and authorized private shares allow DOM-only edits, never source writes. Guest Interact is blocked; snapshots strip active content and owner-local resources, and persisted writes stay role-gated. Loopback is not a trust boundary because tunnels can proxy remote callers.
  • The live editor is same-origin through the local bridge proxy. This boots CSR apps and root-relative assets, but it is still a localhost editing proxy: app-origin cookies, WebSockets/HMR, SSE, and non-GET app API calls may need a future dev-server/plugin integration for perfect parity with the app's own origin.
  • The canvas is the editing view; Interact runs the normal URL with rails and a device bar. Interact preserves navigation, scrolling, links, and controls; the canvas pans/zooms and suppresses native frame interaction.
  • While a localhost screen has pending live visual edits, do not switch back to Interact until the user either applies the edits to source or explicitly aborts/discards the preview.
  • Alt-drag duplicates a localhost frame and its URL metadata. Change the copy's path/query for another state; preserve the order of named or numbered flows. Shorthand like localhost:1234/onboarding/1 means http://localhost:1234/onboarding/1.

Useful Canvas Sets

Use a focused batch of 3-7 frames by default: one ordered frame per requested route/query state, repeat routes at requested desktop/tablet/mobile viewports, and include URL-addressable empty, loading, error, modal-open, or selected-item states. Keep the Screens section readable so Layers remains useful while editing. Do not expand beyond 7 frames unless the user explicitly asks for an exhaustive audit or a complete route inventory.

Do not expand every discovered route or every viewport unless the user asks for an exhaustive audit. Preserve the user's labels and sequence so the canvas reads like the workflow they described.

Select And Reprompt

When a chat message begins with [Reprompt selection], the selected subtree is a hard write boundary. The only mutation path is propose-node-rewrite with the exact repromptId, target, and baseVersionHash captured in design-reprompt-pending:<designId>:<fileId>. Never use apply-visual-edit, apply-source-edit, write-source, write-local-file, edit-design, or any other content-writing action for that request. Clarifying questions are allowed, but a requested change must remain a proposal.

Produce one variant by default. Produce two or three only when the instruction asks for options. A retry includes priorProposalId; keep the same target and base version, incorporate the feedback, and call propose-node-rewrite again. The UI previews the returned subtree without persisting it.

Use resolve-node-rewrite for the accept/reject lifecycle. Accept applies the chosen variant as one version-checked inline/Yjs content transaction so one undo restores the prior structure; reject clears the proposal without changing content. For conversational resolution such as "apply the second one," call view-screen, read the active design.reprompt.proposal, and pass its proposalId plus the zero-based variantIndex to resolve-node-rewrite.

Review Quality

Treat the running app as truth, preserving its component language, tokens, route state, and content. Compare visual edits before/after at requested viewports and check meaningful URL, hover, focus, scroll, and modal states.

Account And Sharing Model

  • The capability permits live iframe inspection, session-local edits, undo/redo, and Copy prompt. The copied instructions go to the coding agent; they do not persist account-owned Design data.
  • Public /design/:id links stay read-only without a signed-in owner/editor session. Never use the local capability to upgrade that ordinary sharing surface.
  • Prefer links returned by Design actions or /_agent-native/open deep links; never surface _session= tokens or hand-build capability URLs.
  • Do not attempt account-backed write actions with the browser capability. The trusted local open-visual-edit CLI call may register its bridge, create or reuse its workspace-owned local design, and place screens without an account. Direct source-file action writes, generation, saving into an account, and sharing still require an authenticated action caller. If a signed-out visitor wants those durable account operations, send them through the framework sign-in return flow first.

Required Local Bridge

The live-edit bridge is unlocked by a shared secret (the "bridge token") that must match on two sides: the local bridge process, and the user's connection row in Design (which the browser reads to authorize /live-edit-bridge, /read-file, /write-file). Get them to match by letting the open-visual-edit action mint the token, then starting the bridge with it. This is the only ordering that works for the remote-MCP flow - the bridge cannot push its own token to the server without a CLI auth token, so the server mints instead and the bridge adopts. The connectionId (usually localhost_...) only identifies the row; never pass it as bridgeToken.

For a fresh signed-out browser flow, generate the token locally, keep it in the host process, and pass it once as the page tool's optional bridgeToken; the page never returns it:

BRIDGE_TOKEN="$(node -e 'process.stdout.write(require("node:crypto").randomBytes(32).toString("hex"))')"
AGENT_NATIVE_BRIDGE_TOKEN="$BRIDGE_TOKEN" npx @agent-native/core@latest design connect --url http://localhost:5173 --root . --daemon

Reuse an existing matching connection without bridgeToken; hosted MCP can mint the token when page WebMCP is unavailable.

From the target app repo, make sure its dev server is running, then:

1. Discover routes without starting a durable bridge (one-shot, exits):

npx @agent-native/core@latest design connect --url http://localhost:5173 --root . --json

This prints the manifest (routes + capabilities). Parse it to build routeManifest for the next step. (Skip this if the user already gave explicit paths/URLs to place.)

Inside the agent-native monorepo itself, use the workspace CLI instead of npx — npx installs the last published @agent-native/core, which will not contain local changes and costs a slow install on every call:

pnpm dev:cli design connect --url http://localhost:5173 --root templates/<app> --json

2. For the hosted MCP path, call open-visual-edit (see Action Flow below) with NO bridgeToken. The server mints one, stores it on the user's connection row, copies it into the placed screens' metadata, and returns it to you as bridgeToken. Capture it.

3. Start the persistent bridge adopting that token (single line; prefer the env var so the secret does not appear in ps):

AGENT_NATIVE_BRIDGE_TOKEN="<bridgeToken from step 2>" npx @agent-native/core@latest design connect --url http://localhost:5173 --root . --daemon

(Equivalently, pass --bridge-token <token>.) This starts a detached bridge on http://127.0.0.1:7331, adopts the server-minted token — so bridge and row agree and live-edit authorizes with no self-registration — and stays alive after the command exits.

For a manual health/manifest check on the running bridge:

curl http://127.0.0.1:7331/health

/health needs no token. The full manifest at /manifest.json is preview-token protected, so an unauthenticated curl of it returns {"ok":false,"error":"invalid or missing preview token"} — that response means the bridge is up, not that it is broken.

Only use --json for the step-1 route probe. Never use --json, --once, or --dry-run for the durable step-3 bridge: they print the manifest and exit, so Design falls back to a non-editable live iframe.

The bridge listens on a single fixed port (7331) and refuses to start for a second, different app. It is detached with no log file, so if --daemon reports a timeout, check for a stale process (lsof -ti:7331) before retrying.

If local Design uses PGlite, never invoke the in-process CLI against that server: both open the same directory and the second owner is rejected. For a signed-out local test, start Design with AUTH_DISABLED=1, open /visual-edit, and call the server-action open-visual-edit through window.__agentNativeWebMcp after it registers. This keeps one PGlite owner; get-visual-edit-prompt is only the post-edit handoff. With auth enabled, sign in to hosted Design MCP or use shared Postgres before using the CLI action.

Action Flow

When a browser is available, reuse the local bridge and call the Design page's open-visual-edit WebMCP tool. For a fresh signed-out connection, pass the locally held bridgeToken; it reads its preview manifest and challenge proof, then sends both for validation. Hosted Design never fetches 127.0.0.1. If the page has no WebMCP, use the connected Design MCP server or its normal hosted MCP fallback.

From another app, call the connected Design MCP tool mcp__agent-native-design__open-visual-edit with the JSON arguments below. It registers or refreshes the localhost bridge, mints and stores the bridge token, creates or reuses a Design project, places URL-backed screens, stores visual-edit context, and navigates to overview mode in one call. Never run pnpm action from the target app's checkout: its local registry does not contain Design actions.

Call it before starting the durable bridge: it does not contact the bridge, so the server can mint bridgeToken for the bridge to adopt. Omit that input.

{
  "title": "Docs homepage visual edit",
  "devServerUrl": "http://localhost:5173",
  "bridgeUrl": "http://127.0.0.1:7331",
  "rootPath": "/absolute/path/to/app",
  "routeManifest": { "...": "from /manifest.json" },
  "paths": ["/", "/pricing", "/checkout?step=payment"]
}

The action returns designId, connectionId, bridgeToken, screens, urlPath, and credential-free openUrl. MCP App metadata carries the hidden one-time launcher. Keep the ids for follow-ups and pass the token to design connect; reusing the connection reuses its token.

Desktop and mobile side by side

Pass viewports to place every requested route once per viewport. Frames lay out as a grid: one row per route, one column per viewport. Presets are desktop (1280x900), laptop (1440x900), tablet (834x1112), and mobile (390x844); an explicit { "label": "...", "width": N, "height": N } also works.

{
  "title": "Tasks responsive visual edit",
  "devServerUrl": "http://localhost:5173",
  "bridgeUrl": "http://127.0.0.1:7331",
  "rootPath": "/absolute/path/to/app",
  "paths": ["/tasks", "/inbox"],
  "viewports": ["desktop", "mobile"]
}

Prefer this over two separate calls with defaultWidth/defaultHeight: it keeps each route's viewports aligned in a row and titles them Tasks — Desktop / Tasks — Mobile so the canvas reads clearly. viewports overrides defaultWidth/defaultHeight. With no routes/paths, it expands every route in the localhost manifest, which is usually far more frames than the user wants — name the paths.

Managing screens and breakpoints manually

Select a screen and use the right-rail Screen section to switch between Static HTML and URL-backed modes, edit its route/path, choose a localhost connection, add another URL screen, or remove the selected screen. URL mode keeps the iframe live; switching to Static stores a sanitized snapshot of the current frame, including its current client state when the page can provide it. The same operations are available to a page-capable agent through add-localhost-screens, update-screen-source, add-breakpoint, and remove-breakpoint.

Adding more page frames later

Call open-visual-edit again with the same designId and connectionId and only the new paths. Missing IDs resume the saved project for the same connection; newDesign: true creates a separate one. Matching frames refresh in place and keep user geometry unless coordinates are passed.

{
  "designId": "<existing-design-id>",
  "connectionId": "<existing-connection-id>",
  "devServerUrl": "http://localhost:5173",
  "paths": ["/settings", "/team"],
  "startY": 2200
}

Do NOT add defaultWidth/defaultHeight just to restate the default size: supplying either one marks the viewport as explicitly requested, which overwrites frame sizes the user has already adjusted on the canvas.

For a numbered flow the user describes in chat, keep the labels and order:

{
  "designId": "<existing-design-id>",
  "connectionId": "<existing-connection-id>",
  "devServerUrl": "http://localhost:1234",
  "routes": [
    { "url": "localhost:1234/onboarding/1", "title": "Screen 1" },
    { "url": "localhost:1234/onboarding/2", "title": "Screen 2" },
    { "url": "localhost:1234/onboarding/3", "title": "Screen 3" }
  ]
}

If no routes or paths are supplied, open-visual-edit uses every route from the localhost manifest.

Fallback only when open-visual-edit is unavailable and hosted Design MCP is authorized:

  1. Register or refresh the bridge with connect-localhost, passing the /manifest.json result as routeManifest and capabilities.
  2. Create or reuse a Design project with create-design.
  3. Place URL-backed screens with add-localhost-screens.
  4. Navigate to overview mode with navigate.

The fallback still targets https://design.agent-native.com; only the app and bridge URLs are localhost. Never run pnpm action from templates/design.

Open The Design Surface

  • Use the link, deepLink, or MCP App embed returned by Design actions so the user sees the canvas. Prefer the MCP App; its host launcher carries the one-time capability. The credential-free openUrl is read-only fallback.
  • Never return or open a hand-built /design/:id?_session=... URL.
  • If the user is working in VS Code, the Agent-Native extension can open the same URL via vscode://builder.agent-native/open?url=<encoded-design-url>. Its Agent-Native: Open Design Canvas command also starts the local bridge and opens hosted Design in the VS Code side panel.
  • Once open-visual-edit returns the expected screenCount, hand back the link and stop. Do not open it yourself in a browser-automation tool to screenshot or poll until it renders — a cold dev server can take 10-30s regardless of who's watching, and that wait adds nothing the response didn't already confirm. Reach for browser automation only if the user later reports the canvas is broken.

Applying Visual Edits Back To Source

With Design closed, call hosted Design MCP's highlighted get-visual-edit-pending for the design ID; it returns the handoff and revision. Verify the applied source, acknowledge that revision, then pull again. If MCP is unavailable, read the local bridge:

npx @agent-native/core@latest design pending --root . --design-id <design-id-from-visual-edit-url>

Pass the ID after visual-edit in the Design URL; the CLI prints that design's prompt (null when empty).

Canvas edits on a localhost screen never write source directly. They stay pending until the coding agent pulls them with get-visual-edit-pending or the copied prompt, then writes them to source. There is no separate canvas Apply button. An MCP App sends its prompt through the host or local Design agent; otherwise use Copy prompt to your agent.

ChatGPT and Claude Code should pull, apply, acknowledge, and pull again. Browser WebMCP hosts can call get-visual-edit-prompt. Never acknowledge before applying the source change.

  • Style, text, and drag/drop edits collect into one pending batch for a single apply.
  • After the write lands, the target app's own dev-server HMR refreshes the frames — no manual reload. If frames do not refresh, the write did not land; say so rather than assuming.
  • The separate disk-icon "Apply to source" button is the deterministic whole-file HTML/CSS writer. It is intentionally disabled for compiled .jsx/.tsx routes — those must go through the agent path above.

Editing URLs

Keep localhost screens as URL files plus screenMetadata[fileId]. Do not replace them with copied srcdoc HTML unless the user explicitly asks for a frozen snapshot. To change a state, rerun open-visual-edit with the new path/query, use the Screen settings section, call update-screen-source, or duplicate the screen and update the copy's URL metadata.

Local Files in the Code Tab

Once a connection is registered, the design editor's Code panel (left rail → Code, or navigate --view editor --designId <id> --leftPanel code) shows a local-files workspace root for that connection next to the design's own files. Treat that root like VS Code opened at the connected project directory: file tree, search, open/edit, and save are backed by the real local files. It lists the connected app's text/code files through the bridge (list-local-files / read-local-file); build output, node_modules, .git, and secret-looking paths (.env*, key files) are always excluded.

  • Browsing and reading need only editor access on the design plus the running bridge.
  • Saving goes through write-local-file: the first save opens the write-consent dialog (an 8-hour, folder-scoped grant) and retries automatically once granted. Only text/code files are writable; secret paths are always blocked.
  • If the agent calls write-local-file directly (not through a UI save) and it fails with "no write-consent grant", call request-localhost-write-consent. It opens the write-consent dialog in the editor, or reports alreadyGranted if one already exists. Granting is human-only — grant-localhost-write-consent is hidden from agents, so you cannot approve it yourself. Tell the user to click "Allow writes", then retry write-local-file once. Do not keep retrying blindly: the write stays blocked until the user approves.
  • Saves are conflict-checked against the file's on-disk version — a file that changed since it was read fails with a version conflict instead of being overwritten.

React Source Writeback

  • Use compiler/debug provenance (project-relative file, line, column, component, and runtime multiplicity) to locate React/TSX source. Treat it as evidence, not as permission for a generic AST structural transform.
  • Read positionPrecision on every anchor before you trust line/column. authored means those are the real JSX coordinates. transformed means they are the dev server's own output coordinates — React 19 removed _debugSource and exposes only an owner stack, so this is the normal case on a Vite/Next dev server, and the line will not match the file. unknown means no tier was reported. On anything but authored, use the file and component to find the element by its JSX shape and re-derive the line from the file you read; never edit at the reported line.
  • A single-instance leaf text edit, literal className/class edit, or flat literal style={{ ... }} property may use apply-visual-edit with a local-file source and a complete target.sourceAnchor. Forward the anchor's positionPrecision with it — the action refuses a transformed anchor with status: "needsAgent" instead of seeking to a line that means something else in the authored file. Preview first (omit persist), inspect proposedDiff, then call with persist: true.
  • Reparenting, grouping/ungrouping, wrappers, dynamic expressions, repeated .map() instances, shared components, breakpoint-scoped edits, and cross-file changes go through the coding agent with complete subject/target anchors and their runtime relationship. apply-visual-edit refuses these with status: "needsAgent" rather than guessing.
  • Before each write, read the file and pass its exact versionHash to write-local-file with requireExpectedVersionHash: true; on conflict, re-read and re-plan. Keep the optimistic preview until HMR/runtime confirms the result. Human write consent remains mandatory and agents cannot grant it.

Verification

For a plain "open this app" request, open-visual-edit's own response is the verification — see Open The Design Surface. Reach for the checks below only to diagnose an actual report, or to confirm an applied edit landed:

  • list-localhost-connections returns the expected connection and routes.
  • The Design editor opens in overview mode.
  • Every requested screen renders the intended localhost URL, showing real app content rather than an endless loading spinner.
  • The screen iframe carries a src, not a srcdoc. A localhost screen with a srcdoc is a bug, not a slow load — check it in the browser devtools before reporting the canvas as working.
  • Alt-dragging a screen copies the URL-backed frame, not an inline HTML clone.
  • A query/path edit changes only the target screen's URL metadata and iframe.
  • get-visual-edit-pending is the tab-free handoff; acknowledge its revision after applying. get-visual-edit-prompt is the browser equivalent.
  • The Code tab shows a local-files root for the connection and opens its files.
1---
2name: visual-edit
3description: >-
4 Open and collaboratively edit a running local app in Design, with shared
5 fallback previews and source handoff. Use when the user asks to inspect,
6 share, or edit a real local app in Design.
7metadata:
8 visibility: exported
9---
10 
11# Visual Edit
12 
13Use `/visual-edit` when the user wants to inspect or edit a real local app
14visually instead of generating standalone Alpine HTML. The source of truth is
15the running localhost app plus its route URLs. Design shows those routes as
16iframe-backed screens on the infinite canvas.
17 
18The editor is hosted at `https://design.agent-native.com`. Never start local
19Design; only the target app and bridge run locally.
20 
21See the [Visual Edit guide](https://github.com/BuilderIO/agent-native/blob/main/skills/visual-edit/README.md)
22for a worked onboarding-flow example.
23 
24## Fast local startup
25 
26- Do not install this skill into the target app or start a local Design server.
27 The skill belongs to the coding host; Design is always the hosted app above.
28- If you need to start an Agent-Native framework app yourself, use
29 `AUTH_DISABLED=1` with its normal dev command. This is local-only and gives
30 the visual editor the framework's dev identity without a user login.
31- If an agent-owned local server redirects a requested screen to `/sign-in`,
32 restart that server with `AUTH_DISABLED=1` and probe the route again before
33 opening Design. Never present a sign-in page as the requested screen.
34- Before calling `open-visual-edit`, verify the target URL responds. Start an
35 agent-owned dev server with its normal command when it is down, and wait for
36 the requested routes to respond before opening Design. Never leave a dead
37 localhost URL in the canvas.
38- Preserve a server you did not start; use its existing authenticated browser
39 session or explain that the target app, rather than Design, requires login.
40- When the user gives explicit paths, skip route inventory and place those
41 paths directly. Discover routes only when paths were not supplied.
42 
43## Installation
44 
45`npx @agent-native/core@latest skills add visual-edit` installs the skill and
46hosted Design MCP connector. `npx skills@latest add BuilderIO/agent-native
47--skill visual-edit` installs instructions only; page-capable WebMCP hosts need
48no connector installation.
49 
50## Put Design Beside The Chat
51 
52Prefer the MCP App from `open-visual-edit`: it keeps Design beside
53chat. Use **Copy prompt** to hand the visual edits to the coding agent; the host
54may request conversation confirmation. Otherwise,
55`openUrl` is a credential-free, read-only fallback; never claim it is editable.
56 
57- Inline-browser hosts should open `https://design.agent-native.com/visual-edit`
58 and call its `open-visual-edit` WebMCP tool. It works signed in or out; the
59 one-time capability is not a Design account session. A page-capable browser
60 controller is enough, so Claude-in-Chrome, Claude Code browser tools, the
61 ChatGPT Chrome/browser extension, Puppeteer or Playwright MCP, CDP, and
62 similar JavaScript-capable controllers do not need the hosted MCP connector.
63- VS Code uses its Design webview/deep link. Without page WebMCP, use the hosted
64 Design MCP connector and its normal OAuth/device authorization. Never replace
65 either path with a local Design server.
66 
67Inside Design, use **Show/Hide UI** from the `Cmd K` menu or press Figma's
68`Shift \` shortcut to toggle all editing chrome so only the canvas remains.
69 
70## Browser WebMCP (Default Without Connector)
71 
72Without a connected Design MCP, use a visible browser tab with a main-world
73JavaScript evaluator. Prefer the host's inline browser; use external Chrome
74only when requested or unavailable. Open
75`https://design.agent-native.com/visual-edit`, keep it visible while tools
76register, and read the title before work. Never enter, copy, or request
77passwords, cookies, tokens, or codes. Signed-out loopback visual-edit works;
78other pages that block tools behind sign-in still require a signed-in tab.
79If the browser exposes CDP permissions, grant `local-network-access` to
80`https://design.agent-native.com` before calling page tools; otherwise use the
81page's Connect button and let the browser's permission prompt complete.
82 
83Use a native browser-session WebMCP bridge when the host provides one: list
84once with `list-browser-session-webmcp-tools` and run with
85`run-browser-session-webmcp-tool`, or use the `list-host-webmcp-tools` and
86`run-host-webmcp-tool` pair. Preserve the exact discovered name, origin, and
87args. Otherwise use the page-world API. Agent-Native pages expose this helper:
88 
89Example assumes signed-in or existing bridge; fresh signed-out loopback must add
90the locally held `bridgeToken` described below.
91 
92```js
93const an = window.__agentNativeWebMcp;
94const status = await an.ready({ waitMs: 20_000 });
95if (status.state !== "ready") throw new Error(status.error ?? status.state);
96const tools = await an.tools("visual-edit");
97if (!tools.some((tool) => tool.name === "open-visual-edit")) {
98 throw new Error("open-visual-edit is not registered yet");
99}
100const result = await an.call("open-visual-edit", {
101 devServerUrl: "http://localhost:5173",
102 paths: ["/"],
103 navigate: true,
104}, { waitMs: 2_000 });
105if (result.state === "pending") {
106 // On the next evaluation, read the still-running call without replaying it.
107 an.result(result.id);
108}
109```
110 
111If the helper is absent, use standard WebMCP directly. `document.modelContext`
112is canonical; `navigator.modelContext` is deprecated:
113 
114```js
115const ctx = document.modelContext;
116const tool = (await ctx.getTools()).find((candidate) => candidate.name === NAME);
117if (!tool) throw new Error(`WebMCP tool not found: ${NAME}`);
118const codex = typeof ctx.codexExecuteTool === "function" ||
119 typeof ctx.codexGetTools === "function";
120const result = await ctx.executeTool(tool, codex ? ARGS : JSON.stringify(ARGS));
121```
122 
123The helper handles live discovery, partial registries, and pending calls. If a
124call returns `state: "pending"`, read `an.result(id)` on the next evaluation;
125never replay a write. For Claude Code or Cowork, `javascript_tool` runs this
126page-world code with top-level `await`; for Codex open the page with
127`cua.createBrowserTab("iab", url, { visible: true })`, then use CDP
128`Runtime.evaluate` with `awaitPromise: true`; Puppeteer and Playwright MCP can
129use their page evaluator. Playwright isolated worlds cannot see
130`document.modelContext`. Keep evaluator output small, batch dependent calls,
131and do not navigate inside a batch.
132 
133Tool descriptors are page-local. Do not copy them into the host, hand-build
134authenticated HTTP requests, or replace named tools with clicks, typing, DOM
135automation, or screenshots. UI automation remains appropriate for canvas work
136without a named tool or when requested. If both bridges are unavailable after
137one discovery and one independent evaluator check, use hosted MCP/CLI before
138changing state.
139 
140For a fresh signed-out loopback connection, generate the bridge token locally,
141start the durable bridge with it, and pass that same token once as the page
142tool's `bridgeToken`; the page never returns it. Reuse a matching running
143bridge without the token. Account-backed or private Design work requires a
144signed-in session or the authenticated Design MCP connector. After canvas edits,
145call `an.call("get-visual-edit-prompt", {}, { waitMs: 2_000 })` and apply the
146returned handoff. The page tool may show an approval dialog; let the user
147approve it and never bypass that consent.
148 
149## Core Model
150 
151- Each screen is a URL-backed iframe, not copied HTML.
152- Each screen keeps URL metadata: `connectionId`, `routeId`, `path`,
153 `url`, `bridgeUrl`, title, and viewport size.
154- The owner edits through the local bridge. Shared
155 `/visual-edit/:designId?share=1` links render a sanitized inert snapshot,
156 refreshed on route or DOM changes; guests never reach the owner's localhost.
157 Guest edits stay pending until an owner or editor applies them to source.
158- Authorized viewers and commenters on private designs can edit the shared
159 Visual Edit canvas and submit pending changes without writing design files.
160 The owner or editor applies those source changes.
161- **The `/visual-edit` skill needs no Design account sign-in.**
162 `open-visual-edit` mints a five-minute, single-use capability for the exact
163 `/visual-edit/:designId` local-editor route. The MCP host redeems it outside
164 model-visible text, then opens the existing editor with localhost edit access.
165 A public `/visual-edit/:designId` route enables browser-only DOM editing of
166 public localhost snapshots; handoffs stay pending until applied. The owner
167 sees **Apply edits** when a recipient has pending changes.
168 This capability is not an account session: `/_agent-native/session` remains
169 signed out, and account-backed save/share/generate actions remain denied.
170- Hosted MCP highlights `get-visual-edit-pending`; pass the visual-edit
171 design ID for a tab-free handoff. It returns a revision; after applying,
172 call `acknowledge-visual-edit-pending` with that revision, then pull again.
173 `empty` means no edits; `session-ended` means edits were lost;
174 `unknown` means the marker was unreadable, not proof of no change.
175- Browser hosts can use page-local `get-visual-edit-prompt`.
176- The `open-visual-edit` action is owned by Design. From another app, use the
177 hosted MCP server at `https://design.agent-native.com/mcp` or the page's
178 WebMCP helper, not `pnpm action` in the target app. The page path works
179 signed out only for loopback apps in public mode, using a short-lived
180 capability-scoped principal; hosted MCP uses its normal OAuth identity.
181- Ordinary public links stay read-only. Public `/visual-edit/:designId` and
182 authorized private shares allow DOM-only edits, never source writes. Guest
183 Interact is blocked; snapshots strip active content and owner-local resources,
184 and persisted writes stay role-gated. Loopback is not a trust boundary because
185 tunnels can proxy remote callers.
186- The live editor is same-origin through the local bridge proxy. This boots
187 CSR apps and root-relative assets, but it is still a localhost editing proxy:
188 app-origin cookies, WebSockets/HMR, SSE, and non-GET app API calls may need a
189 future dev-server/plugin integration for perfect parity with the app's own
190 origin.
191- The canvas is the editing view; Interact runs the normal URL with rails and a
192 device bar. Interact preserves navigation, scrolling, links, and controls;
193 the canvas pans/zooms and suppresses native frame interaction.
194- While a localhost screen has pending live visual edits, do not switch back to
195 Interact until the user either applies the edits to source or explicitly
196 aborts/discards the preview.
197- Alt-drag duplicates a localhost frame and its URL metadata. Change the copy's
198 path/query for another state; preserve the order of named or numbered flows.
199 Shorthand like `localhost:1234/onboarding/1` means
200 `http://localhost:1234/onboarding/1`.
201 
202## Useful Canvas Sets
203 
204Use a focused batch of 3-7 frames by default: one ordered frame per requested
205route/query state, repeat routes at requested desktop/tablet/mobile viewports,
206and include URL-addressable empty, loading, error, modal-open, or selected-item
207states. Keep the Screens section readable so Layers remains useful while
208editing. Do not expand beyond 7 frames unless the user explicitly asks for an
209exhaustive audit or a complete route inventory.
210 
211Do not expand every discovered route or every viewport unless the user asks for
212an exhaustive audit. Preserve the user's labels and sequence so the canvas
213reads like the workflow they described.
214 
215## Select And Reprompt
216 
217When a chat message begins with `[Reprompt selection]`, the selected subtree is
218a hard write boundary. The only mutation path is `propose-node-rewrite` with
219the exact `repromptId`, target, and `baseVersionHash` captured in
220`design-reprompt-pending:<designId>:<fileId>`. Never use `apply-visual-edit`,
221`apply-source-edit`, `write-source`, `write-local-file`, `edit-design`, or any
222other content-writing action for that request. Clarifying questions are allowed,
223but a requested change must remain a proposal.
224 
225Produce one variant by default. Produce two or three only when the instruction
226asks for options. A retry includes `priorProposalId`; keep the same target and
227base version, incorporate the feedback, and call `propose-node-rewrite` again.
228The UI previews the returned subtree without persisting it.
229 
230Use `resolve-node-rewrite` for the accept/reject lifecycle. Accept applies the
231chosen variant as one version-checked inline/Yjs content transaction so one
232undo restores the prior structure; reject clears the proposal without changing
233content. For conversational resolution such as "apply the second one," call
234`view-screen`, read the active `design.reprompt.proposal`, and pass its
235`proposalId` plus the zero-based `variantIndex` to `resolve-node-rewrite`.
236 
237## Review Quality
238 
239Treat the running app as truth, preserving its component language, tokens, route
240state, and content. Compare visual edits before/after at requested viewports and
241check meaningful URL, hover, focus, scroll, and modal states.
242 
243## Account And Sharing Model
244 
245- The capability permits live iframe inspection, session-local edits, undo/redo,
246 and **Copy prompt**. The copied instructions go to the coding agent; they do
247 not persist account-owned Design data.
248- Public `/design/:id` links stay read-only without a signed-in owner/editor
249 session. Never use the local capability to upgrade that ordinary sharing
250 surface.
251- Prefer links returned by Design actions or `/_agent-native/open` deep links;
252 never surface `_session=` tokens or hand-build capability URLs.
253- Do not attempt account-backed write actions with the browser capability. The
254 trusted local `open-visual-edit` CLI call may register its bridge, create or
255 reuse its workspace-owned local design, and place screens without an account.
256 Direct source-file action writes, generation, saving into an account, and
257 sharing still require an authenticated action caller. If a signed-out visitor
258 wants those durable account operations, send them through the framework
259 sign-in return flow first.
260 
261## Required Local Bridge
262 
263The live-edit bridge is unlocked by a shared secret (the "bridge token") that
264must match on two sides: the local bridge process, and the user's connection row
265in Design (which the browser reads to authorize `/live-edit-bridge`,
266`/read-file`, `/write-file`). Get them to match by letting the
267`open-visual-edit` action mint the token, then starting the
268bridge with it. This is the only ordering that works for the remote-MCP flow -
269the bridge cannot push its own token to the server without a CLI auth token, so
270the server mints instead and the bridge adopts.
271The `connectionId` (usually `localhost_...`) only identifies the row; never
272pass it as `bridgeToken`.
273 
274For a fresh signed-out browser flow, generate the token locally, keep it in the
275host process, and pass it once as the page tool's optional `bridgeToken`; the
276page never returns it:
277 
278```bash
279BRIDGE_TOKEN="$(node -e 'process.stdout.write(require("node:crypto").randomBytes(32).toString("hex"))')"
280AGENT_NATIVE_BRIDGE_TOKEN="$BRIDGE_TOKEN" npx @agent-native/core@latest design connect --url http://localhost:5173 --root . --daemon
281```
282 
283Reuse an existing matching connection without `bridgeToken`; hosted MCP can
284mint the token when page WebMCP is unavailable.
285 
286From the target app repo, make sure its dev server is running, then:
287 
288**1. Discover routes without starting a durable bridge** (one-shot, exits):
289 
290```bash
291npx @agent-native/core@latest design connect --url http://localhost:5173 --root . --json
292```
293 
294This prints the manifest (routes + capabilities). Parse it to build
295`routeManifest` for the next step. (Skip this if the user already gave explicit
296paths/URLs to place.)
297 
298Inside the agent-native monorepo itself, use the workspace CLI instead of
299`npx` — `npx` installs the last published `@agent-native/core`, which will not
300contain local changes and costs a slow install on every call:
301 
302```bash
303pnpm dev:cli design connect --url http://localhost:5173 --root templates/<app> --json
304```
305 
306**2. For the hosted MCP path, call `open-visual-edit`** (see Action Flow below)
307with NO `bridgeToken`.
308The server mints one, stores it on the user's connection row, copies it into the
309placed screens' metadata, and returns it to you as `bridgeToken`. Capture it.
310 
311**3. Start the persistent bridge adopting that token** (single line; prefer the
312env var so the secret does not appear in `ps`):
313 
314```bash
315AGENT_NATIVE_BRIDGE_TOKEN="<bridgeToken from step 2>" npx @agent-native/core@latest design connect --url http://localhost:5173 --root . --daemon
316```
317 
318(Equivalently, pass `--bridge-token <token>`.) This starts a detached bridge on
319`http://127.0.0.1:7331`, adopts the server-minted token — so bridge and row
320agree and live-edit authorizes with no self-registration — and stays alive after
321the command exits.
322 
323For a manual health/manifest check on the running bridge:
324 
325```bash
326curl http://127.0.0.1:7331/health
327```
328 
329`/health` needs no token. The full manifest at `/manifest.json` is
330preview-token protected, so an unauthenticated `curl` of it returns
331`{"ok":false,"error":"invalid or missing preview token"}` — that response means
332the bridge is up, not that it is broken.
333 
334Only use `--json` for the step-1 route probe. Never use `--json`, `--once`,
335or `--dry-run` for the durable step-3 bridge: they print the manifest and exit,
336so Design falls back to a non-editable live iframe.
337 
338The bridge listens on a single fixed port (7331) and refuses to start for a
339second, different app. It is detached with no log file, so if `--daemon` reports
340a timeout, check for a stale process (`lsof -ti:7331`) before retrying.
341 
342If local Design uses PGlite, never invoke the in-process CLI against that server:
343both open the same directory and the second owner is rejected. For a signed-out
344local test, start Design with `AUTH_DISABLED=1`, open `/visual-edit`, and call
345the server-action `open-visual-edit` through `window.__agentNativeWebMcp` after
346it registers. This keeps one PGlite owner; `get-visual-edit-prompt` is only the
347post-edit handoff. With auth enabled, sign in to hosted Design MCP or use shared
348Postgres before using the CLI action.
349 
350## Action Flow
351 
352When a browser is available, reuse the local bridge and call the Design page's
353`open-visual-edit` WebMCP tool. For a fresh signed-out connection, pass the
354locally held `bridgeToken`; it reads its preview manifest and challenge proof,
355then sends both for validation. Hosted Design never fetches `127.0.0.1`. If the
356page has no WebMCP, use the connected Design MCP server or its normal hosted
357MCP fallback.
358 
359From another app, call the connected Design MCP tool
360`mcp__agent-native-design__open-visual-edit` with the JSON arguments below. It
361registers or refreshes the localhost bridge,
362mints and stores the bridge token, creates or reuses a Design project, places
363URL-backed screens, stores visual-edit context, and navigates to overview mode
364in one call. Never run `pnpm action` from the target app's checkout: its local
365registry does not contain Design actions.
366 
367Call it before starting the durable bridge: it does not contact the bridge, so
368the server can mint `bridgeToken` for the bridge to adopt. Omit that input.
369 
370```json
371{
372 "title": "Docs homepage visual edit",
373 "devServerUrl": "http://localhost:5173",
374 "bridgeUrl": "http://127.0.0.1:7331",
375 "rootPath": "/absolute/path/to/app",
376 "routeManifest": { "...": "from /manifest.json" },
377 "paths": ["/", "/pricing", "/checkout?step=payment"]
378}
379```
380 
381The action returns `designId`, `connectionId`, `bridgeToken`, `screens`,
382`urlPath`, and credential-free `openUrl`. MCP App metadata carries the
383hidden one-time launcher. Keep the ids for follow-ups
384and pass the token to `design connect`; reusing the connection reuses its token.
385 
386### Desktop and mobile side by side
387 
388Pass `viewports` to place every requested route once per viewport. Frames lay
389out as a grid: one row per route, one column per viewport. Presets are
390`desktop` (1280x900), `laptop` (1440x900), `tablet` (834x1112), and `mobile`
391(390x844); an explicit `{ "label": "...", "width": N, "height": N }` also works.
392 
393```json
394{
395 "title": "Tasks responsive visual edit",
396 "devServerUrl": "http://localhost:5173",
397 "bridgeUrl": "http://127.0.0.1:7331",
398 "rootPath": "/absolute/path/to/app",
399 "paths": ["/tasks", "/inbox"],
400 "viewports": ["desktop", "mobile"]
401}
402```
403 
404Prefer this over two separate calls with `defaultWidth`/`defaultHeight`: it
405keeps each route's viewports aligned in a row and titles them
406`Tasks — Desktop` / `Tasks — Mobile` so the canvas reads clearly. `viewports`
407overrides `defaultWidth`/`defaultHeight`. With no `routes`/`paths`, it expands
408every route in the localhost manifest, which is usually far more frames than
409the user wants — name the paths.
410 
411### Managing screens and breakpoints manually
412 
413Select a screen and use the right-rail **Screen** section to switch between
414Static HTML and URL-backed modes, edit its route/path, choose a localhost
415connection, add another URL screen, or remove the selected screen. URL mode
416keeps the iframe live; switching to Static stores a sanitized snapshot of the
417current frame, including its current client state when the page can provide it.
418The same operations are available to a page-capable agent through
419`add-localhost-screens`, `update-screen-source`, `add-breakpoint`, and
420`remove-breakpoint`.
421 
422### Adding more page frames later
423 
424Call `open-visual-edit` again with the same `designId` and `connectionId` and
425only the new paths. Missing IDs resume the saved project for the same
426connection; `newDesign: true` creates a separate one. Matching frames refresh
427in place and keep user geometry unless coordinates are passed.
428 
429```json
430{
431 "designId": "<existing-design-id>",
432 "connectionId": "<existing-connection-id>",
433 "devServerUrl": "http://localhost:5173",
434 "paths": ["/settings", "/team"],
435 "startY": 2200
436}
437```
438 
439Do NOT add `defaultWidth`/`defaultHeight` just to restate the default size:
440supplying either one marks the viewport as explicitly requested, which
441overwrites frame sizes the user has already adjusted on the canvas.
442 
443For a numbered flow the user describes in chat, keep the labels and order:
444 
445```json
446{
447 "designId": "<existing-design-id>",
448 "connectionId": "<existing-connection-id>",
449 "devServerUrl": "http://localhost:1234",
450 "routes": [
451 { "url": "localhost:1234/onboarding/1", "title": "Screen 1" },
452 { "url": "localhost:1234/onboarding/2", "title": "Screen 2" },
453 { "url": "localhost:1234/onboarding/3", "title": "Screen 3" }
454 ]
455}
456```
457 
458If no `routes` or `paths` are supplied, `open-visual-edit` uses every route
459from the localhost manifest.
460 
461Fallback only when `open-visual-edit` is unavailable and hosted Design MCP is
462authorized:
463 
4641. Register or refresh the bridge with `connect-localhost`, passing the
465 `/manifest.json` result as `routeManifest` and `capabilities`.
4662. Create or reuse a Design project with `create-design`.
4673. Place URL-backed screens with `add-localhost-screens`.
4684. Navigate to overview mode with `navigate`.
469 
470The fallback still targets `https://design.agent-native.com`; only the app and
471bridge URLs are localhost. Never run `pnpm action` from `templates/design`.
472 
473## Open The Design Surface
474 
475- Use the `link`, `deepLink`, or MCP App embed returned by Design actions so the
476 user sees the canvas. Prefer the MCP App; its host launcher carries the
477 one-time capability. The credential-free `openUrl` is read-only fallback.
478- Never return or open a hand-built `/design/:id?_session=...` URL.
479- If the user is working in VS Code, the Agent-Native extension can open the
480 same URL via
481 `vscode://builder.agent-native/open?url=<encoded-design-url>`. Its
482 `Agent-Native: Open Design Canvas` command also starts the local bridge and
483 opens hosted Design in the VS Code side panel.
484- Once `open-visual-edit` returns the expected `screenCount`, hand back the
485 link and stop. Do not open it yourself in a browser-automation tool to
486 screenshot or poll until it renders — a cold dev server can take 10-30s
487 regardless of who's watching, and that wait adds nothing the response didn't
488 already confirm. Reach for browser automation only if the user later reports
489 the canvas is broken.
490 
491## Applying Visual Edits Back To Source
492 
493With Design closed, call hosted Design MCP's highlighted
494`get-visual-edit-pending` for the design ID; it returns the handoff and
495revision. Verify the applied source, acknowledge that revision, then pull again.
496If MCP is unavailable, read the local bridge:
497 
498```bash
499npx @agent-native/core@latest design pending --root . --design-id <design-id-from-visual-edit-url>
500```
501 
502Pass the ID after `visual-edit` in the Design URL; the CLI prints that
503design's prompt (`null` when empty).
504 
505Canvas edits on a localhost screen never write source directly. They stay
506pending until the coding agent pulls them with `get-visual-edit-pending` or the
507copied prompt, then writes them to source. There is no separate canvas Apply
508button. An MCP App sends its prompt through the host or local Design agent;
509otherwise use **Copy prompt to your agent**.
510 
511ChatGPT and Claude Code should pull, apply, acknowledge, and pull again.
512Browser WebMCP hosts can call `get-visual-edit-prompt`. Never acknowledge
513before applying the source change.
514 
515- Style, text, and drag/drop edits collect into one pending batch for a single
516 apply.
517- After the write lands, the target app's own dev-server HMR refreshes the
518 frames — no manual reload. If frames do not refresh, the write did not land;
519 say so rather than assuming.
520- The separate disk-icon "Apply to source" button is the deterministic
521 whole-file HTML/CSS writer. It is intentionally disabled for compiled
522 `.jsx`/`.tsx` routes — those must go through the agent path above.
523 
524## Editing URLs
525 
526Keep localhost screens as URL files plus `screenMetadata[fileId]`. Do not
527replace them with copied `srcdoc` HTML unless the user explicitly asks for a
528frozen snapshot. To change a state, rerun `open-visual-edit` with the new
529path/query, use the Screen settings section, call `update-screen-source`, or
530duplicate the screen and update the copy's URL metadata.
531 
532## Local Files in the Code Tab
533 
534Once a connection is registered, the design editor's Code panel (left rail →
535Code, or `navigate --view editor --designId <id> --leftPanel code`) shows a
536local-files workspace root for that connection next to the design's own files.
537Treat that root like VS Code opened at the connected project directory: file
538tree, search, open/edit, and save are backed by the real local files. It lists
539the connected app's text/code files through the bridge
540(`list-local-files` / `read-local-file`); build output, `node_modules`,
541`.git`, and secret-looking paths (`.env*`, key files) are always excluded.
542 
543- Browsing and reading need only editor access on the design plus the running
544 bridge.
545- Saving goes through `write-local-file`: the first save opens the
546 write-consent dialog (an 8-hour, folder-scoped grant) and retries
547 automatically once granted. Only text/code files are writable; secret paths
548 are always blocked.
549- If the agent calls `write-local-file` directly (not through a UI save) and it
550 fails with "no write-consent grant", call `request-localhost-write-consent`.
551 It opens the write-consent dialog in the editor, or reports `alreadyGranted`
552 if one already exists. Granting is human-only —
553 `grant-localhost-write-consent` is hidden from agents, so you cannot approve
554 it yourself. Tell the user to click "Allow writes", then retry
555 `write-local-file` once. Do not keep retrying blindly: the write stays
556 blocked until the user approves.
557- Saves are conflict-checked against the file's on-disk version — a file that
558 changed since it was read fails with a version conflict instead of being
559 overwritten.
560 
561## React Source Writeback
562 
563- Use compiler/debug provenance (project-relative file, line, column,
564 component, and runtime multiplicity) to locate React/TSX source. Treat it as
565 evidence, not as permission for a generic AST structural transform.
566- Read `positionPrecision` on every anchor before you trust `line`/`column`.
567 `authored` means those are the real JSX coordinates. `transformed` means they
568 are the dev server's own output coordinates — React 19 removed `_debugSource`
569 and exposes only an owner stack, so this is the normal case on a Vite/Next
570 dev server, and the line will not match the file. `unknown` means no tier was
571 reported. On anything but `authored`, use the file and component to find the
572 element by its JSX shape and re-derive the line from the file you read; never
573 edit at the reported line.
574- A single-instance leaf text edit, literal `className`/`class` edit, or flat
575 literal `style={{ ... }}` property may use `apply-visual-edit` with a
576 `local-file` source and a complete `target.sourceAnchor`. Forward the
577 anchor's `positionPrecision` with it — the action refuses a `transformed`
578 anchor with `status: "needsAgent"` instead of seeking to a line that means
579 something else in the authored file. Preview first (omit `persist`), inspect
580 `proposedDiff`, then call with `persist: true`.
581- Reparenting, grouping/ungrouping, wrappers, dynamic expressions, repeated
582 `.map()` instances, shared components, breakpoint-scoped edits, and
583 cross-file changes go through the coding agent with complete subject/target
584 anchors and their runtime relationship. `apply-visual-edit` refuses these
585 with `status: "needsAgent"` rather than guessing.
586- Before each write, read the file and pass its exact `versionHash` to
587 `write-local-file` with `requireExpectedVersionHash: true`; on conflict,
588 re-read and re-plan. Keep the optimistic preview until HMR/runtime confirms
589 the result. Human write consent remains mandatory and agents cannot grant it.
590 
591## Verification
592 
593For a plain "open this app" request, `open-visual-edit`'s own response is
594the verification — see Open The Design Surface. Reach for the checks below
595only to diagnose an actual report, or to confirm an applied edit landed:
596 
597- `list-localhost-connections` returns the expected connection and routes.
598- The Design editor opens in overview mode.
599- Every requested screen renders the intended localhost URL, showing real app
600 content rather than an endless loading spinner.
601- The screen iframe carries a `src`, not a `srcdoc`. A localhost screen with a
602 `srcdoc` is a bug, not a slow load — check it in the browser devtools before
603 reporting the canvas as working.
604- Alt-dragging a screen copies the URL-backed frame, not an inline HTML clone.
605- A query/path edit changes only the target screen's URL metadata and iframe.
606- `get-visual-edit-pending` is the tab-free handoff; acknowledge its revision
607 after applying. `get-visual-edit-prompt` is the browser equivalent.
608- The Code tab shows a local-files root for the connection and opens its files.
609 

Discussion

Alternatives

shadcn/uiManages shadcn components and projects — adding, searching, fixing, debugging, styling, and composing UI, including chat interfaces. Provides project context, component docs, and usage examples. Applies when working with shadcn/ui, component registries, presets, --preset codes, or any project with a components.json file. Also triggers for "shadcn init", "create an app with --preset", or "switch to --preset".Coding · MITADK Code ReferenceThis skill should be used when the user wants to "write agent code", build an agent with ADK", "add a tool", "create a callback", "define an agent", use state management" — in a project that needs ADK (Agent Development Kit) API patterns and code examples. It provides a quick reference for agent types, tool definitions, orchestration patterns, callbacks, state management, the graph Workflow API, and reference recipes to study. Do NOT use for scaffolding (use google-agents-cli-scaffold) or deployment (use google-agents-cli-deploy).Coding · Apache-2.0ModsmithPatterns, cost review and ready templates for Claude Mods (Claude Code plugins whose behaviour is a function-hooks module). Adds what the built-in mod authoring does not: proven designs (fork-check-draw, tool + ledger, mode registry, artifact-backed state), prompt-cache and token-cost review, a vetting pass for someone else's mod, and rules for mods that compose. USE WHEN: build a mod, make a claude mod, mod templates, quiz me after each turn, assumptions tool / register_assumption, supervisor that checks the turn, next-steps check, mode selector / mode registry, effort by domain, model router that keeps the cache, prompt cache cost of a mod, what does this mod cost per turn, review or vet someone's mod before installing, mods that work together, Kanban artifact as shared project state. NOT FOR: classic shell-command hooks in settings.json (PreToolUse etc.), a plain skill or slash command, MCP server authoring, or looking up the hooks API itself (use the engine's plugin-authoring guidance and generated types).Coding · MITWeb artifacts builderSuite of tools for creating elaborate, multi-component claude.ai HTML artifacts using modern frontend web technologies (React, Tailwind CSS, shadcn/ui). Use for complex artifacts requiring state management, routing, or shadcn/ui components - not for simple single-file HTML/JSX artifacts.Coding · Apache-2.0