StuntKit
Give your AI agent a browser it can use safely. StuntKit is the code Stunt Double runs on every agent session, extracted and published so you can use it in your own agents, read exactly what it does and send fixes back.
It is open source under the Apache-2.0 license, at
github.com/stunt-double/stuntkit.
StuntKit packages are published under the @stunt-double scope, on GitHub
Packages until that scope is available on npm (GitHub Packages asks for a token
even for public packages). The self-hosted worker ships as the Docker image
ghcr.io/stunt-double/worker:latest.
What's in it
| Package | What it does | Source |
|---|---|---|
@stunt-double/browser-toolset | Browser tools for AI agents over any browser you bring, with opt-in safety guards | stunt-double/stuntkit |
@stunt-double/icons | The Continuity icon pack: 235 stroked icons as geometry, standalone SVG files and React components | stunt-double/stuntkit |
@stunt-double/spelling | Whole-word American, British and Canadian spelling localization, from American or British source text | stunt-double/stuntkit |
@stunt-double/wao | Web Agent Optimiser: a drop-in script that repairs the accessibility tree agents read, so legacy sites work for agents without a rebuild | stunt-double/stuntkit |
Why it's open source
A browser agent on someone else's site is a liability until you can see what it will refuse to do. Telling a model "never pay or sign up" in a prompt is a request it can ignore. StuntKit puts that rule in the tools instead: when a guard refuses, the click never reaches the page. You can read every guard, test it and change it.
Your security team should be able to read what an agent will do before it does. Now they can.
Contribute
Issues and pull requests are welcome on the repository. It has a
CONTRIBUTING.md with the local setup, and every commit needs a
Developer Certificate of Origin sign-off
(git commit -s). Report security issues privately through GitHub rather than
in a public issue.
Next steps
Automate Stunt Double from Claude
Connect the MCP server to Claude and drive actors, checklists, and interviews from a conversation.
Give an AI agent a safe browser
Use @stunt-double/browser-toolset to let Claude or any function-calling model read and act on real pages, with guards that refuse payments, sign-ups, passwords and card numbers.