Skip to main content
Glama

Run a batch in the agent's own browser

host_start
Destructive

Start an authorized item batch on an agent host to run browser or API-only actions, journaling commits and holding missing write results for review.

Instructions

Runs an authorized item batch with an agent host. Browser actions require permission to execute page scripts; read-only evaluate in the current Codex app cannot run them. API-only and agent-tool batches need no browser. Returns {runId,batch,actions,note}, one tab per slot, parallel 1..4. Tools use existing MCP connections with frozen args. Commit journaled before dispatch, missing write results held for review, done keys skipped. No setup/teardown/iframe/press/extract in host mode; HTTP session:browser needs the browser runner. Follow host_next.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
paramsNo
parallelNo
workflowYes

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observedv0.1.0

TDQS

B3.4/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With annotations already declaring openWorldHint and destructiveHint, the description still adds meaningful behavior: commit is journaled before dispatch, missing write results are held for review, done keys are skipped, one tab per slot, parallel 1..4, existing MCP connections with frozen args, and unsupported operations in host mode. These go well beyond the annotations, though some statements are cryptic fragments rather than clearly actionable disclosures.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness3/5

Is the description appropriately sized, front-loaded, and free of redundancy?

It is front-loaded with the core purpose and the return shape, which is good, but the bulk is a run of telegraphic jargon fragments ('frozen args', 'done keys skipped', 'HTTP session:browser needs the browser runner') that add density rather than clarity. Appropriate length for the complexity, weaker structure.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

With no output schema, the description usefully supplies the return shape ({runId,batch,actions,note}) and covers execution semantics, permissions, and mode constraints. It is fairly complete for a destructive, open-world batch runner, though the undefined workflow/params inputs remain a gap.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters2/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 0%, so the description must carry the load, but it only echoes the parallel constraint ('parallel 1..4') that the schema already encodes and never explains what 'workflow' or 'params' contain. The required parameter and the nested-string params object are effectively undocumented.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

The first sentence states a specific verb and resource ('Runs an authorized item batch with an agent host') and contrasts browser batches against API-only/agent-tool batches that need no browser. It is reasonably clear what the tool does, but it never distinguishes itself from the closely named sibling run_start, and terms like 'agent host' and 'slot' are left undefined.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

It gives partial conditional guidance ('Browser actions require permission...', 'API-only and agent-tool batches need no browser', 'Follow host_next'), which implies when the tool is appropriate. However, it never states explicitly when to choose host_start over run_start/run_resume, nor what prerequisites or exclusions select among them.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.