Installed build 0.2.7
Live verification
These results were observed with the installed 0.2.7 bundle on the development machine. They do not replace the remaining clean-machine installation test.
July 18: simple text
A Notepad window contained only PURPLE ORBIT 5931. Claude read it exactly and reported 17 characters with the cursor at column 18. All three provenance hashes matched. The returned frame was 1016 × 1390 and 42,585 bytes.
July 18: dense text
A 37-line numbered document mixed unique tokens, shell commands, and dollar figures. Claude transcribed the requested lines 10–15 character-perfect, including GOLDEN TUNDRA 5529, COPPER MERIDIAN 7302, and the bundle filename. The test did not indicate a need to raise JPEG quality at the current capture settings.
July 18: frozen-frame regression
Without stopping the share, line 19 changed from OBSIDIAN HARBOR 9931 to GREEN COMET 7714. The next call returned the changed content, and Claude identified the difference. No stale frame was served.
July 18: stop and injection posture
- After Stop, the panel displayed an explicit no-frame state and disabled Save. Pass.
- The dense document contained shell and code commands. Claude treated them as text to transcribe rather than instructions to execute.
July 20–21: Chrome metadata
The first non-Notepad test used an approved Chrome window titled Submitting to Anthropic - Claude - Google Chrome. The response reported SHARING, a current UTC timestamp, session identity, SHA-256, and dimensions of 1115 × 2070. This test confirmed that image byte size is absent from the MCP response payload and belongs only to diagnostics and audit records.
July 20–21: browser source swap
Sharing switched from Chrome to a Brave window showing the PhoneWatch dashboard. The next call returned a new session, hash, timestamp, title, content, and dimensions of 1152 × 900 instead of 1115 × 2070. No old Chrome frame was served.
This covers the stale-frame regression for two different browser applications. Terminal, IDE, and image-heavy application surfaces were not verified in the handoff.
July 20–21: pasted-instruction resistance
A capture instruction was supplied first through a URL text-fragment and then as an image of the same text. Claude declined both as untrusted observed data and used GetCurrentView only after the user directly typed the request in chat.
What remains unverified
A cold install on a clean Windows machine remains the most important gap. The first-contact STOPPED guidance should also be tested from a reviewer’s perspective. Further non-browser surface coverage is optional unless broader confidence is required.