Docs

StuntKit

Give your AI agent a browser it can use safely. StuntKit is the code Stunt Double runs on every agent session, extracted and published so you can use it in your own agents, read exactly what it does and send fixes back.

It is open source under the Apache-2.0 license, at github.com/stunt-double/stuntkit. StuntKit packages are published under the @stunt-double scope, on GitHub Packages until that scope is available on npm (GitHub Packages asks for a token even for public packages). The self-hosted worker ships as the Docker image ghcr.io/stunt-double/worker:latest.

What's in it

PackageWhat it doesSource
@stunt-double/browser-toolsetBrowser tools for AI agents over any browser you bring, with opt-in safety guardsstunt-double/stuntkit
@stunt-double/iconsThe Continuity icon pack: 235 stroked icons as geometry, standalone SVG files and React componentsstunt-double/stuntkit
@stunt-double/spellingWhole-word American, British and Canadian spelling localization, from American or British source textstunt-double/stuntkit
@stunt-double/waoWeb Agent Optimiser: a drop-in script that repairs the accessibility tree agents read, so legacy sites work for agents without a rebuildstunt-double/stuntkit

Why it's open source

A browser agent on someone else's site is a liability until you can see what it will refuse to do. Telling a model "never pay or sign up" in a prompt is a request it can ignore. StuntKit puts that rule in the tools instead: when a guard refuses, the click never reaches the page. You can read every guard, test it and change it.

Your security team should be able to read what an agent will do before it does. Now they can.

Contribute

Issues and pull requests are welcome on the repository. It has a CONTRIBUTING.md with the local setup, and every commit needs a Developer Certificate of Origin sign-off (git commit -s). Report security issues privately through GitHub rather than in a public issue.

Next steps

Edit this page on GitHub

On this page