AI agent control for Mac: one launcher, three ways in.
Coco is the app you already open with a hotkey. It is also the layer that gives an AI agent control of your Mac, through a CLI, an MCP server, and an Agent Skill, all backed by the same 71 methods the launcher itself runs on.
What AI agent control on a Mac actually means here
Most Mac apps have no door for an agent to knock on. An AI coding assistant in your terminal can read and write files and run shell commands. It cannot open an app by name the way you would. It cannot read your clipboard history, take a screenshot and get the file path back, or change a setting and have it apply without a restart. That gap is what Coco's agent layer closes. It is not a new app. It is Coco's own launcher, clipboard manager, screenshot tool, live captions engine, calculator, plugin runtime and Raycast-compatible store, opened up behind a local socket that a CLI and an MCP server both speak.
The mechanism is one set of area.method pairs, everything Coco can do, defined once each with a schema attached: `apps.search`, `clipboard.list`, `screenshot.capture`, `settings.set` and 67 more. It is the same set the Coco launcher panel calls when you press its hotkey. Every surface reads from that one source: the `coco` command line, the `coco mcp` server your AI agent connects to over stdio, and the Agent Skill that teaches an agent how to use both. Nothing is duplicated. Nothing drifts out of sync, because there is only one implementation behind each method.
Access to the local socket is restricted to Coco-signed processes. A random script on your Mac cannot pretend to be the CLI. Inside that boundary, AI agent control on a Mac with Coco is default-allow. Install Coco, connect an agent, and every method above is available right away, with no consent dialog per action. A handful of files are deny-listed outright: AI API keys, ASR keys, the license cache, and Keychain items. That list is checked before anything else runs. You can also turn Agent Access off entirely, or block individual methods in Settings, at any time.
The 71 methods an AI agent can call through Coco
Search, open, activate, hide and quit apps
An agent can search installed apps by name, in the same pinyin, romaji and Hangul-aware index the launcher itself uses. It can then open, bring to front, hide or quit whichever app matches. Ask an agent to open Xcode and switch to it, and it calls the same method the hotkey panel calls when you type.
List, search and paste from your clipboard
The clipboard area lets an agent list recent entries, search them, fetch one by id, copy new text or an image to the clipboard, paste into the frontmost app, and favorite or delete an entry. Password-manager entries are never returned by any of these calls, no matter how the search is phrased.
Capture a screenshot and get a file path back
screenshot.capture takes the whole screen, one window, or a region. It hands the agent back a PNG path it can read, attach to a message, or pass to another tool. This is a new entry point built for agents, separate from the interactive capture you trigger yourself from the panel.
Start live captions and read the transcript back
An agent can start or stop a live captions session and check its status. It can also list or read saved transcripts. Ask it to caption a call and hand you the transcript afterward, and it is calling captions.start, captions.status and transcripts.read in sequence.
Calculator, unit, currency and emoji lookups
calc.eval, units.convert, currency.convert and emoji.search are the same pure functions behind Coco's built-in tools. An agent can settle a unit conversion or find the right emoji without leaving the conversation to open a calculator.
Run any installed plugin or Raycast extension
plugins.list and plugins.commands describe what is installed. plugins.run executes a command. raycast.list, raycast.run and raycast.session cover Raycast-compatible extensions the same way. An agent driving Coco can reach every plugin you have added, not just Coco's own features.
Browse, install and update from the Coco Store
store.list and store.search read the catalog. store.install, store.uninstall and store.update manage what is on your Mac. An agent can check whether a plugin exists in the Store and install it as part of a longer task, instead of stopping to ask you to do it by hand.
Read and change every setting, applied live
settings.list, settings.get, settings.schema, settings.set and settings.patch cover every key in Coco's configuration. A change an agent makes takes effect right away. It works the same as if you had changed it yourself in the Settings window, with no restart in between.
AI agent control on Coco, Raycast and Alfred
Raycast and Alfred are both launchers an agent might want to reach. Neither built a control surface for one. Raycast added an MCP integration, and it is worth being precise about what that is. Raycast acts as an MCP client: it can call out to other MCP servers from inside Raycast, not the other way around. There is no way for Claude Code, Cursor or ChatGPT to call into Raycast and ask it to open an app or read a clipboard entry.
Alfred exposes a URL scheme that can trigger a workflow. It has no authentication on that scheme; anything on the Mac that can open a URL can trigger an Alfred action. That is a door, but not a control surface built for an agent, and it carries none of the process-signature checking that gates Coco's socket. Coco is the only one of the three that ships a CLI, an MCP server and an Agent Skill an outside agent connects to directly.
| Coco | Raycast | Alfred | |
|---|---|---|---|
| CLI an outside agent can call | |||
| MCP server for agents to connect to | Client only | ||
| Agent Skill for Claude Code / Codex | |||
| Settings an agent changes apply live | |||
| Secrets and license files off-limits to agents | N/A | N/A | |
| Signed-process check on the control channel | N/A | No auth |
Setting up AI agent control on your Mac
Install Coco and its CLI
Drag Coco to Applications and open it once. Then run `coco cli install` from a terminal. It links the `coco` binary at Contents/Helpers/coco into your PATH, so `coco` works from any shell.
Connect your AI agent
For Claude Code, Claude Desktop, Cursor or Codex, run `coco mcp install --client claude-code`, swapping in the client you use. For an agent without an install flag, such as ChatGPT, copy the setup prompt from `coco skill install`, or run `npx skills add butterflydream-ai/Coco --skill coco -g -y`.
Ask it to use your Mac
Once connected, ask your agent to search the clipboard, open an app, take a screenshot, run a plugin, or change a setting. It calls one of Coco's 71 methods directly. You can watch each call and its result in your agent's own tool-use log.
Questions about AI agent control on a Mac
- Is it safe to let an AI agent control my Mac through Coco?
- The control channel only accepts connections from Coco-signed processes. That check happens at the operating-system level, before any request is answered, so a script cannot impersonate the CLI or the MCP server. A deny-list of secret files, including AI API keys, ASR keys, the license cache and Keychain items, is checked ahead of every request, before consent or routing logic runs. Those files are never reachable, even by a legitimate call. Coco is default-allow once installed, so there is no per-action popup, but you can turn Agent Access off entirely, or block individual methods such as clipboard.delete, in Settings whenever you want. Clipboard entries from a password manager are also filtered out of every clipboard call, regardless of how the search is worded.
- Which AI tools work with Coco's agent layer?
- Anything that speaks MCP connects through `coco mcp`. That covers Claude Code, Claude Desktop, Cursor, Codex, Windsurf, VS Code with GitHub Copilot, and Gemini and Grok clients that support MCP. `coco mcp install --client <name>` writes the connection for Claude Code, Claude Desktop, Cursor and Codex automatically. Agents such as ChatGPT or Perplexity that do not run local MCP servers can still use the CLI directly. Install the Agent Skill, or copy the setup prompt, and the agent runs `coco` commands through its own shell access. Any AI agent with shell access on your Mac can reach the same 71 methods, whether it gets there through MCP or through the command line.
- Does AI agent control cost extra on top of Coco?
- No. Coco is a one-time purchase, currently $49 at the launch price and $99 after, with no subscription. The CLI, the MCP server, the Agent Skill and all 71 methods are part of that same purchase. There is no separate agent tier, add-on license, or per-call fee. If you already own Coco, updating to a version that includes the agent layer is enough. The CLI ships inside the same app bundle at Contents/Helpers/coco, not as a separate download.
- Can I block or turn off AI agent control?
- Yes, in two ways. Settings → Agent Access has a master switch that turns the whole control channel off. That closes the local socket, so no CLI or MCP connection can reach Coco at all. Short of that, the same panel lists every method by name and lets you block individual ones. You could allow apps.search and clipboard.list while blocking clipboard.delete and settings.set, for instance. Both changes take effect right away for any agent already connected. The deny-listed secret files stay off-limits regardless of which switches are on.
Copy the prompt, or send it straight to the AI you already use — it drives Coco through the same commands you would type yourself.
Install the Coco skill (npx skills add butterflydream-ai/Coco --skill coco -g -y), then use coco to help me with AI agent control for Mac: one launcher, three ways in..