A host that runs one server per identity, opens and closes its browser itself and offers its model only the page
tools (invisible_dots) had two choices, both wrong: hand its model instructions about browser_open, a tool that
model does not have, and a browser argument offering a helper it cannot open; or rewrite every description and
copy the rules into a prompt of its own, where they drift from these. INVISIBLE_MCP_HOST_MANAGED=1, read once at
import like the session id, is the third: the process serves main alone (the argument leaves every schema through
SkipJsonSchema, and support is refused if sent anyway) and its instructions are the page rules alone. Opening and
closing stay tools, because such a host still needs browser_open (the engine's download is answered in steps) and
browser_close (Firefox writes its profile before the client stops the process).
INSTRUCTIONS is now three texts joined for a standalone client: the opening rule, PAGE_RULES and the two browsers.
The page rules are the same words in both modes. They gained what a host's runs measured on 2026-10-10 (45 tasks of
invisible_dots, 773 page calls, 90 that led nowhere): reach a page through a link seen or an address given, search
with Brave and read the results with browser_snapshot, and after a 404 take the next address from a page that
loaded (58 of the 90 calls were addresses from memory, 27 of the 54 pages dropped unread answer 404); answer a
consent dialog before clicking under it (four clicks waited 15 s and failed); go back or reload with a navigation,
since a key pressed on the page never reaches the browser's own shortcuts; and two rules that host's skill carried
and this server did not (a calendar wants its days clicked; a number not read on the page is not one to give). The
sentence that support is the second page moved to the paragraph about support.
browser_read_text resolved its selector with document.querySelector while every other tool goes through the engine,
so a snapshot's :nth-match(...) handle failed there while the same string clicked, and a field inside a shadow root
read as missing. It now counts and reads through page.locator, as DIAGNOSE_JS was moved off querySelectorAll on
2026-09-30. test_read_text_in_a_browser holds both on a real page (the old resolver fails those two and passes plain
CSS), and test_a_host_that_opens_the_browser holds the mode in a process of its own.