20cf326bd1
Live-tested against the real cua-driver 0.19.3 binary (Linux x86_64): - bounded serve flags corrected: the daemon accepts --session-policy/--approve-session-policy, not the docs' --capability-manifest names (which it rejects). Verified end-to-end: a bounded daemon with a real policy file starts and reports running. - browser-approve verified real but interactive-only (refuses without a TTY) and its token is a legacy compatibility path disabled by default on current drivers (per the live browser_prepare schema). Kept as a passthrough; no longer presented as the primary route. - NEW primary standard-mode route, verified live: launch the runtime with cua-driver's trusted-launcher grant. config opt-in computer_use.grant_existing_profile: true appends --grant existing-profile to the standard-mode MCP spawn (MCP initialize verified accepting the flag). Default false = attachment keeps failing closed. Never applied to bounded/unrestricted daemons. - Skill, system prompt, tool schema, and docs updated to the verified ladder: config grant > bounded manifest > YOLO; token = legacy.