Bigarrow Gives Coding Agents a Mac Arrow That Points but Never Clicks
Software / news
Bigarrow Gives Coding Agents a Mac Arrow That Points but Never Clicks
The MIT-licensed Swift tool drew 284 Hacker News points, 313 GitHub stars and an argument about whether an overlay can mislead the person it is guiding.
Bigarrow, a macOS command-line tool by GitHub user franzenzenhofer, lets Claude Code or Codex draw a large arrow and a text sign over any window, so a person can see which button an agent means. Its README says it "never clicks, types or captures anything. It only points."
The repository is MIT licensed and shows 313 stars, 5 forks and 107 commits. A Hacker News thread on it reached 284 points.
What the person at the keyboard sees
The case for it is a specific moment: an agent has walked you to a settings pane and says "click Allow," and the pane has six buttons. Bigarrow draws the arrow over the right one. Clicks pass through to the app underneath, and the arrow removes itself.
Three commands do the work: point, start and stop. By default a point arrow expires after 8 seconds and a start arrow after 300 seconds, or sooner if the agent process that drew it exits. Clicking the sign or the shaft also removes it. Every command takes --json, and exit codes separate bad input (2), target not found (3) and missing permission (4).
Install is brew install franzenzenhofer/tap/bigarrow, then bigarrow install-skill to add the agent-facing skill in Agent Skills format. Building from source needs Xcode 16 or newer and macOS 14 or newer. The README says CI runs on macOS 15 and that tests also passed on macOS 26 and 27.
Which permissions it asks for
The README says permissions go to the parent app, such as the terminal, not to bigarrow itself.
| Use | macOS permission needed |
|---|---|
| Draw at screen coordinates | None |
--element, elements, --until-click, --app App:title | Accessibility |
--window App:title | Screen Recording, plus Accessibility to raise the window unless --no-raise is set |
The README describes it as "one Swift binary: no daemon, no menu-bar icon, no account, no telemetry." The page does not mention code signing or notarization, and does not mention MCP, the protocol many agent tools use; the integration here is a command line plus a skill. The skill half uses the Agent Skills format covered in the piece on the skills repository with 280.7k stars.
The objection the README already answers
The obvious worry is an overlay that lies. A Hacker News commenter, hn8726, asked what stops the tool drawing over a permission prompt to hide the word Decline or change the text on Approve. The README concedes an agent could draw over a button, and argues this adds no capability beyond what an agent that can run shell commands already has. Another commenter, SwtCyber, made the same argument.
A commenter named hannasanarion put it more bluntly: "A tool that lets your ai do something doesn't also let it do anything." The harder line came from tilemarch: "An arrow on the screen solves 'where do I click'; it doesn't solve 'should this happen'." The README, as fetched, argues about capability rather than intent.
The project's author, franze, appears once in the thread. franze wrote that Claude refuses some actions, such as entering passwords, changing security settings and creating accounts on outside services, even in permissive mode on a test Mac. That is a statement about one model on one machine, and the README does not make it.
Is the arrow worth a skill
The thread was split on value. mistersquid tried it with Claude walking through Apple's Compressor.app. m-s-y argued a plain prompt asking Claude for numbered arrows achieves the same thing without a skill. socializer wrote that in the first screenshot "three of the five arrows are obviously and badly misaligned."
There is also a sandboxing angle. NVIDIA's OpenShell restricts what an agent can touch. Bigarrow restricts what it can do to your screen: nothing but point.
The repository has a CHANGELOG.md but the page shows no version number, and the README describes macOS only. The next thing to watch is whether the open issues, which the page does not count, ask for either.
Sources
More in Software
- 01Python 3.15.0 Ships October 9 After Lazy-Import Bugs Forced an Unplanned Third CandidateThe release team had called rc2 final on September 1. Late blockers in PEP 810 added an rc3 on October 2 and pushed the stable build to October 9.
- 02LiteLLM's Rust Gateway Claims 15x Throughput, but Its Docs List Four Routes and No BenchmarksA June 22 blog post promised OCR, chat and a router by mid-September. The beta docs page read on October 10 shows a narrower path and a Docker image that is not published.
- 03Diagram Design Passes 47,900 Stars, and Its README Tells Git Users to Pick MermaidThe agent skill draws 44 diagram types as a single HTML file. Its own README admits layouts vary between runs, and five export bugs were filed on October 6.
- 04Anthropic's Knowledge-Work Plugins Have 28,300 Stars, a Datadog URL Due to Break and a Contribution Guide the CI OverridesThe 11-plugin repo is Apache-2.0 and trending. Its README asks for pull requests, a workflow closes them, and 76 issues sit open.