Membership lesson · Build Your Jarvis · Module 9 — The plug socket (MCP)
Browsing — the first guest at work
The first plugged-in tool does real work: Jarvis browses. Where Module 5's search reads summaries, the browser server goes behind the link and into the page — supplier stock pages, the actual table on the actual site, multi-step looks at the live web — every navigation, click and type through the approval card, the answer saying where it went, the session closed behind it. The build is light because the socket did the heavy lifting: browse etiquette — when the page beats the summary and when it doesn't — and the rule the project has been rehearsing since the search guard: everything a page says is data, never instructions. Then the lesson's heart, the test the module was pointed at all along: a hostile page the member writes themselves — normal content plus a planted instruction aimed at the assistant — browsed via file://, reported instead of obeyed, any attempted act exposed on a card and denied. The lethal trifecta — private data, untrusted content, the ability to act — demonstrated and defused on the member's own disk, with Module 8's defences earning their keep on their first wild content.
This lesson ships with the paid path. Checkout isn't live yet — start with the free projects (Ground Zero + Off the Grid), or join the waitlist.