# Copy this prompt into your agent

Install Fruitctl from the canonical public producer
`https://github.com/xoxd-ai/fruitctl` for my current agent. Read its pinned
AGENTS.md, installation guide, compatibility matrix, and adoption manifest.
The current immutable runtime preview is `v0.1.0-alpha.2`, source revision
`6c8a5751b1ab92ee4093aa0091e88ef212021dab`. Verify the actual GitHub release is
published and immutable, verify its `fruitctl-release.json` asset digest and
archive checksums, and use those exact pins. Never treat main or latest as
immutable executable or skill bytes.
Fetch the source-pinned bootstrap with user curl configuration disabled
(`curl --disable`) or an equivalent verified HTTPS client.
Before execution, verify `scripts/install.sh` has SHA-256
`6e05a7a62f57491cfbda1f8d9212291f6237f04f4ac396bc04d183b88747cd58`.

This preview has scoped archive, native distribution, actual public adapter
bootstrap and synthetic VNC/MCP evidence. Its macOS 15+ ARM64 runtime bundles the signed, Apple-notarized
controller as `bin/claude-kvm-daemon`; verify its recorded hash and Developer ID
signature without changing its bytes. Linux needs the SSH bridge to a
configured Darwin controller. Real frontend rendering and desktop journeys,
physical overlay exclusion, SSH adoption and service objectives remain pending;
do not turn a configuration receipt into a desktop qualification claim.

Inspect my agent version, seat OS and architecture, and supported MCP/skill
installation surface. Use the native Darwin controller on a supported Mac or
the SSH bridge from Linux. Keep the VNC target credentials on the Darwin
controller through its local credential provider. Preserve my unrelated agent
instructions, MCP servers, and existing installation.

Configure only an operator-selected named target profile. Explain any required
Screen Sharing or macOS consent step precisely and wait for the user to perform
that step. Do not claim signing, notarization, or an IDE plugin bypasses user
consent or proves this adapter works. The installer does not create profiles or
credentials, enable Screen Sharing, start services or launch a GUI. A bare
controller has no stapled ticket; Gatekeeper may use its online notarization
ticket and require normal user approval. Do not remove protections or re-sign
the controller to bypass approval.

If no compatible immutable preview asset or required controller exists, report the missing artifact or
qualification and stop before substituting an unreviewed source build. Once
installed, check capabilities and health, obtain a complete fresh frame, and
ask for a designated reversible test action if none is already authorized.
Verify the resulting observation and human stop control. Do not replay uncertain
input automatically.

Report the installed release, full source revision, agent adapter/version,
controller/target OS, capture mode, and observed test outcome without secrets,
private screen content, or invented success. Enable the optional FuzzyBot spell
indicator only when this exact capture mode has a recorded exclusion proof.
Host remains an unqualified source prototype and is absent from public runtime
payloads, installation and generated helper mappings. Do not install or enable
it as part of this preview. No Screen Capture grant or Apple capability approval
is provided by this installation.
