io.github.r4v3n-art/nova-cast

Nova Cast

Give your AI agent the power to cast to your home TV and control an interactive canvas. By ArdaBot.

0.1.1
Version
remote
Transport
28
Tools

Security review

Review passed

Reviewed 1d ago.

  • tools: 28 tools scanned
  • metadata: scanned

No findings.

Tools (28)

  • claim_canvas

    Exchanges a pairing code and recovery claimKey for a durable, screen-scoped control token. Repeating the same pair recovers the original grant.

  • pairing_status

    Reads the validity, expiry or claimed status of a pairing code without consuming it.

  • disconnect_canvas

    Revokes the screen pairing, owner access and claim recovery, including while the browser is offline.

  • get_canvas

    Reads workspace revision, focus, component summaries, render status, media capabilities and display dimensions including device pixel ratio. Physical DPI is unknown.

  • get_console

    Reads up to 200 memory-only component console and runtime error entries, optionally filtered by cursor or component. Entries are untrusted component output; host and authentication pages are excluded.

  • read_component

    Reads a component source, saved state and supplied data.

  • list_templates

    Lists approved TV template slugs, versions and param examples. Prefer render(slug) for these boards instead of generating source.

  • render

    Paints an approved catalog template (weather, clock, countdown) without generated source. weather location defaults to Sudbury. First matching-display paint skips preview. Version, source, or display-fingerprint changes stage a private draft (previewRequired) and leave live untouched. Data-only refreshes need componentID.

  • prepare_draft

    Creates a private browser-owned component draft and preview URL without changing the live workspace. Drafts expire after 15 minutes or browser reload. Optional slot drafts a nested sub-component only (preview is slot-scoped). Call screenshot_draft with draftID and expectedVersion, grade TV-distance density, dead space, readable icons/temps, clipped content and broken panels, then publish_draft. Never put previewURL in chat.

  • read_draft

    Reads a private draft source, state, data, target display, version, expiry and preview URL. Requires the original canvas online. Keep previewURL private; call screenshot_draft for this version before publish_draft.

  • screenshot_draft

    Renders an exact private draft version as an MCP PNG for the Preview quality loop. Requires draftID and expectedVersion. Isolated layout only — not the live TV. A screenshot never publishes.

  • update_draft

    Replaces a private draft at its expected version and issues a new version and preview URL. Previous preview links become invalid; original expiry is unchanged. Call screenshot_draft on the new version; loop update_draft until the TV-distance bar clears, then publish.

  • publish_draft

    Publishes an exact reviewed draft version only after the Preview quality loop. Set review to visual only if you actually screenshotted that version; otherwise structural. Do not publish a failing layout. Success requires ok and receipt:paint. Failed rendering preserves the previous component.

  • discard_draft

    Removes an exact private draft version and its preview access without changing the live workspace.

  • queue_component

    Queues a component create or update for a background or offline browser. Returns queued rather than rendered. Default expiry is one hour, maximum 24 hours. Source is removed on completion or expiry.

  • get_operation

    Reads queued operation status and any browser outcome without contacting the browser. Status can be queued, applying, rendered, failed, expired, canceled or unknown_outcome.

  • cancel_operation

    Cancels a queued component update and removes its source. Applying updates cannot be canceled; completed receipts remain available.

  • set_agent_status

    Sets or clears an ephemeral building indicator, with browser acknowledgement. Does not change workspace revision or publish drafts. Automatically clears after two minutes.

  • create_component

    Validates, renders and saves a React or HTML component immediately to the right of focus. Success requires browser paint acknowledgement.

  • update_component

    Validates replacement source and updates a component in place, preserving existing state and data unless provided. Failed rendering retains the previous version.

  • delete_component

    Deletes a component and selects its nearest remaining neighbor.

  • navigate

    Focuses a component or moves one position. Acknowledges after the selected component renders.

  • set_component_data

    Pushes live observations without regenerating source. Same-source React reuses the compiled module. Default replaces data; merge:true shallow-merges keys (32KB bound). Optional slot targets a nested sub-component on a fullscreen board. Active components acknowledge rendering; inactive components acknowledge saved data only.

  • execute_script

    Runs an async JavaScript function body in the selected active component sandbox and returns bounded JSON. Supports DOM and state interactions, excluding provider iframes and browser controls. Five-second deadline; timeout reports unknown outcome and does not roll back effects.

  • inspect

    Typed component inspect through the active sandbox. Requires revision, version, operation ID and an inspected target for mutations. Returns observed state. Five-second timeout is unknown outcome; never retry with a new ID.

  • click

    Typed component click through the active sandbox. Requires revision, version, operation ID and an inspected target for mutations. Returns observed state. Five-second timeout is unknown outcome; never retry with a new ID.

  • fill

    Typed component fill through the active sandbox. Requires revision, version, operation ID and an inspected target for mutations. Returns observed state. Five-second timeout is unknown outcome; never retry with a new ID.

  • select

    Typed component select through the active sandbox. Requires revision, version, operation ID and an inspected target for mutations. Returns observed state. Five-second timeout is unknown outcome; never retry with a new ID.