vnc

A command that prints connection details for viewing or controlling a remote desktop through VNC, a system for remotely displaying and interacting with another computer.

In plain words
What is it for?
Use it to connect to a desktop-capable lease or inspect an existing VNC service on an SSH host.
Why use it?
It provides the local endpoint and tunnel information needed to connect while keeping unavailable or incomplete credentials out of the output.

Command

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add commands/openclaw/crabbox/vnc
Clone the repo
git clone --depth 1 https://github.com/openclaw/crabbox
Per session 0 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 3,838 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00000 $0.03838
Opus 5 $0.00000 $0.01919
Sonnet 5 $0.00000 $0.00768
Haiku 4.5 $0.00000 $0.00384

Measured 2d ago against content hash 95aa50e68d36, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

vnc scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

docs/commands/vnc.md · 366 lines

How it starts

The opening of the file, as written. The whole thing — 366 lines — stays where its author put it; the contents beside it link to each section on GitHub.

vnc

crabbox vnc prints (or opens) the connection details for a desktop-capable lease. For a managed desktop lease it gives you a loopback SSH tunnel and a local VNC endpoint. Crabbox-bootstrapped desktops also print their generated per-lease password; External desktops keep operator-owned passwords out of normal command output. For a static SSH host it describes an existing host-managed VNC service instead of pretending the host is a Crabbox-created box.

VNC and WebVNC credential reads share a 30-second operation deadline, including SSH preparation and connection attempts. An earlier caller deadline still wins. Cancellation retains the transport's bounded process and remote cleanup, so cleanup can add a short delay before the command returns. Reads retain at most 64 KiB of raw stdout and discard stderr. An oversized read or any failure, including cleanup failure, returns no credential; partial passwords never reach a viewer or command output. This is a transport budget, not VNC's eight-byte DES key limit: longer macOS/ARD account passwords remain intact. Existing optional-credential and managed None-auth behavior is unchanged.

Use it when you want to view or manually drive the visible desktop inside a lease:

crabbox warmup --desktop
crabbox vnc --id blue-lobster
crabbox vnc --id blue-lobster --network tailscale
crabbox vnc --id blue-lobster --open

The lease must have been warmed with --desktop; crabbox vnc does not add a desktop to an existing lease. See warmup and Interactive desktop and VNC.

Synopsis

crabbox vnc --id <lease-id-or-slug> [flags]

You can also pass the lease id or slug as the first positional argument instead of --id.

Flags

--id <lease-id-or-slug>      Target lease (or pass it as the first argument).
--provider <name>            Provider for the lease/target. Defaults to config.
--target linux|macos|windows OS of the target box.
--windows-mode normal|wsl2   Windows session mode.
--static-host <host>         Static SSH host (provider=ssh).
--static-user <user>         Static SSH user.
--static-port <port>         Static SSH port.
--static-work-root <path>    Static work root.
--network auto|tailscale|public  Network path used to reach the box.
--local-port <port>          Local tunnel port. Auto-picks 5901-5999 if unset.
--open                       Start the tunnel (if needed) and open a VNC client.
--native-handoff             Emit one JSON handoff and own its foreground tunnel.
--host-managed               Allow --open against a static host-managed VNC.
--reclaim                    Claim this lease for the current repo.

Read the full file on GitHub · 366 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 366 lines · 0 tokens per session scan A 95aa50e68d36

Subscribe to this mod's changes

vnc is a command published in the GitHub repository openclaw/crabbox (1,343 stars, last pushed 2d ago), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 3,838 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.