open-compute-mcp
Enables screen capture and computer-use control of Blender on Windows, including GPU-composited Blender windows via the Windows.Graphics.Capture fallback.
Enables screen capture and computer-use control of Roblox Studio on Windows, including GPU-composited Roblox Studio windows via the Windows.Graphics.Capture fallback.
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@open-compute-mcpcapture screen"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
open-compute-mcp
npm launcher for the open-compute MCP server β model-agnostic computer-use tools exposed over the Model Context Protocol (MCP).
Local stdio only. Real capture and input require an interactive Windows desktop session on the MCP client's own host. This launcher is not Glama-hostable; a hosted "Deploy Server" flow cannot access your desktop. Install it in a local MCP client instead.
EN | DE
π¦ View on npm β β’ π Security Policy β’ βοΈ Licenses β’ π€ LLM Context (llms.txt)
Quick Navigation
3. π Quick Start & Prerequisites (Use with an MCP Client)
18. π Statutory Notice (Β§ 521 BGB) & 48h Security Response SLA
Direct Document References | π‘οΈ Security Policy β’ βοΈ Third-Party Licenses β’ π Marketing Log β’ π€ LLM Context β’ π Canonical Notice |
AI Assistant / Agent Integration: This repository contains an llms.txt file providing structured, machine-readable specifications of tools, safety modes (OC_SAFETY_MODE), and client configuration examples for RAG crawlers and autonomous agent frameworks.
The MCP client is the reasoner (no API key, model-agnostic): it calls capture
to see the screen, then acts with do / click_name / invoke. This is the keyless
Mode-A loop of open-compute, but as native tool-calls.
1. Architecture
graph TD
A["AI Reasoner<br/>(Claude / Antigravity / Cursor)"] -- "MCP stdio (JSON-RPC)" --> B["npx open-compute-mcp<br/>(Node.js Launcher)"]
B -- "Spawns via uvx" --> C["open-compute Python Engine<br/>(GitHub @ main)"]
C -- "Screenshots / WGC" --> D["Windows Display"]
C -- "UIA / Mouse / Keys" --> E["Windows Desktop Apps"]
C -- "Glowing Border & Cursor" --> F["Signal Overlay UI"]
subgraph Safety Gate
C -. "OC_SAFETY_MODE<br/>(confirm / read_only / allow_all)" .-> C
C -. "OC_DENY<br/>(hard action blacklist)" .-> C
endThis package is a thin launcher. It contains no server logic β it spawns the Python open-compute server (pulled from GitHub) and pipes MCP stdio through. Real screen capture and input require the interactive Windows desktop session.
Related MCP server: computer-use-mcp
2. Key Capabilities & Invariants
State-bound Perception & Window Targeting: Captures/trees return one-shot observation IDs; window enumeration returns stable window/process IDs and issued tokens. WGC remains the GPU-window fallback.
Fail-closed Action Execution: Coordinates consume one observation and exact window binding; UIA names resolve exact-first; text is segmented with focus checks and character-count postconditions.
Leased Signal Overlay & Abort Control: The glowing border/cursor signal has owner/session metadata, a bounded TTL, turn-end cleanup, and immediate human abort.
Multimodal Collaboration & Voice Notes: Push-to-talk voice recording (
talk), screen chat messaging (chat), directory monitoring (watch_dir), and macro replay (rec_replay).
3. Quick Start & Prerequisites
Prerequisites
Python 3.10+ and uv on the host. The default launch uses
uvxto fetch open-compute (with themcpextra) from GitHub on first run β themcpextra tracks the GitHub repo, so this works regardless of PyPI release timing.Windows for real capture/input (mss + UIA). Other platforms import the tools but cannot drive a desktop.
Use with an MCP client
Via this npm launcher (npx):
{
"mcpServers": {
"open-compute": {
"command": "npx",
"args": ["-y", "open-compute-mcp"]
}
}
}Directly via Python (uvx), no npm:
{
"mcpServers": {
"open-compute": {
"command": "uvx",
"args": ["--from", "open-compute[mcp,local,uia] @ git+https://github.com/ellmos-ai/open-compute.git", "open-compute-mcp"]
}
}
}4. MCP Tool Reference (16)
Tool | Purpose |
| Return one-shot observation metadata plus an image (optionally one exact window). |
| Execute a safety-gated action; coordinates require |
| Return UIA elements and a one-shot observation ID for their coordinates. |
| Exact-first, ambiguity-safe click in a required issued window, with score/alternatives. |
| Exact-first, click-free UIA activation in a required issued window. |
| List stable window/process IDs, exact titles, issued tokens, rects and centers. |
| Virtual-desktop geometry + per-monitor breakdown (read-only). |
| Watch directories for file-system changes. |
| Feed-manager status (read-only). |
| Replay a |
| Show a configurable pre-action color/text countdown, then the mode-colored overlay, with owner/session lease and bounded TTL. |
| Hide the signal overlay. |
| Owner/session/mode/visible/expires_at + pending abort message. |
| Ask the human for a short abort reason; the message is returned for the model. |
| Humanβmodel message about screen content, optionally with screenshot. |
| Push-to-talk voice note β WAV path (hold key, speak, release; STT/TTS model-side). |
All coordinates are normalized 0..1 relative to the virtual desktop. Tool
descriptions are localized in six languages (de/en/es/ja/ru/zh) via OC_LANGUAGE.
do also accepts the hold primitives mouse_down / mouse_up / key_down /
key_up for press-and-hold sequences (rubber-band selection, modifier-held
clicking, game input); anything still held is released when the server stops.
capture(window=...) falls back to Windows.Graphics.Capture when a plain grab of
a hardware-composited window (Roblox Studio, Blender, a GPU-accelerated browser)
comes back all-black β install the wgc extra for that.
5. Configuration (Environment Variables)
Variable | Effect |
| Path to a |
| Full command override (whitespace-split), e.g. |
| Git ref (branch/tag/sha) to pin for the uvx launch (default: the repo's default branch). |
| Extras for the default |
| Language of the tool descriptions: |
|
|
| Comma-separated action types always denied (e.g. |
| Resize factor for every capture, |
| Cap the longest edge in pixels (default off). Setting it suppresses the scale default, so the two never shrink twice. |
|
|
| Hard overlay lease limit in seconds (default 120). |
| Additional idle timeout for explicitly kept auto-signals (default 60). |
| Pre-action countdown duration (default 20; |
| Signal JSON containing |
Capture size β why this launcher halves it by default
A vision model is billed per pixel, and every frame stays in the conversation, so a full-HD grab is charged again on each following request. The cost of a session therefore grows with the square of the number of screenshots, not linearly.
Because open-compute's coordinates are normalized 0..1, shrinking the image costs
nothing in click accuracy β do works in fractions of the image either way. Only
legibility drops, and at 0.5 buttons and field borders stay clearly identifiable; small
body text is what gets hard to read.
Setting | 1920Γ1080 grab | Cost |
| full resolution | ~1600 tokens |
| 960Γ540 | ~690 tokens |
| 768Γ432 | ~440 tokens |
The Python library itself defaults to full resolution β its callers are not necessarily paying per pixel. Only this launcher, which exists to serve agents, opts into the smaller frame and prints a one-line notice when it does.
What saves more than any scale factor: prefer tree where
the accessibility model carries the content β note that in browsers it usually exposes only
the browser chrome, not the page; and use capture(window=β¦) rather than the full desktop.
Coordinate actions deliberately follow observe β one action β automatic refresh;
do not batch multiple coordinate steps against one stale frame.
6. Safe Interaction & Signal Lifecycle
The v0.8 Python engine enforces observe β one action β automatic refresh. Keep
the full descriptor or window_token from list_windows, then pass it as
expected_window together with the latest observation_id from capture or
tree. click_name/invoke require that issued window too. Reuse, changed
state, focus mismatch, covered windows, and ambiguous UIA targets are rejected
before input. type returns requested/sent character
counts and complete/partial status without echoing the text. Signals have a
hard TTL and are removed at action turn end unless keep_signal=true.
An explicit signal_show starts the engine's configured pre-action grace
period. The static grace color is distinct from the mode color and the visible
text counts down Start in N Sekunden once per second. At zero, both phase and
color switch once to active. signal_status exposes the same phase, remaining
seconds, current color, and screenreader label. Duration, grace color, and text
template come from OC_SIGNAL_GRACE_SECONDS / OC_SIGNAL_CONFIG; 0 skips the
countdown. The design uses no flashing, pulsing, or motion animation.
sequenceDiagram
autonumber
actor Reasoner as AI Reasoner (Claude / AGY)
participant Launcher as Node.js Launcher (open-compute-mcp)
participant Engine as Python Engine (open-compute)
participant UI as Windows Desktop / UIA
actor Operator as Human Operator
Note over Reasoner,Operator: Phase 1: Visual Perception & State Inspection
Reasoner->>Launcher: capture(window?) / tree()
Launcher->>Engine: Forward stdio JSON-RPC
Engine->>UI: Grab Screen (mss/WGC) or Read UIA Tree
UI-->>Engine: Frame Image / Semantic Element Tree
Engine-->>Launcher: Observation ID + normalized response/image
Launcher-->>Reasoner: State-bound visual observation
Note over Reasoner,Operator: Phase 2: Signal Overlay Activation
Reasoner->>Launcher: signal_show(mode="control")
Launcher->>Engine: Invoke Signal Overlay
Engine->>UI: Render static grace color + Start in N seconds
UI-->>Operator: Text countdown + accessible window name
Engine->>UI: At zero, switch once to the mode color
Note over Reasoner,Operator: Phase 3: Action Request & Safety Gate
Reasoner->>Launcher: do(one action, window token, observation_id) / click_name(target)
Launcher->>Engine: Process Action Payload
alt OC_SAFETY_MODE == "confirm" (Default)
Engine-->>Launcher: Status "needs_confirmation" (Report Only)
Launcher-->>Reasoner: Human confirmation needed
else OC_SAFETY_MODE == "allow_all" (Isolated VM)
Engine->>UI: Execute Mouse/Keyboard / Hold Primitives
UI-->>Engine: Action Completed
Engine-->>Launcher: Post-observation + window/modal/text postconditions
Launcher-->>Reasoner: Action completed - old observation invalid
end
Note over Reasoner,Operator: Phase 4: Emergency Abort or Completion
opt Operator Triggers Emergency Abort
Operator->>Engine: Hotkey Pressed (Abort Signal)
Engine->>UI: Auto-release all held keys/mouse buttons
Engine-->>Reasoner: signal_abort message returned
end
Engine->>UI: Remove overlay on turn end/error/abort (unless keep_signal=true)7. Target Personas & Discoverability
open-compute-mcp is architected for four technical personas across autonomous AI operations, system engineering, accessibility assurance, and multimodal human-in-the-loop workflows:
Target Persona | Core Operational Needs | Pain Points Solved | Target Discovery Terms |
Autonomous AI Agents & Swarms (Claude Code, Antigravity, Cursor, Windsurf) | Reliable desktop perception, normalized coordinates (0..1), state-bound observation tokens | Stale-frame hallucination; blind multi-action execution; coordination drift across agent turns |
|
Enterprise AI Safety & SecOps Teams | Fail-closed operator safety ceiling ( | Runaway autonomous agents; remote cloud telemetry leakage; unverified privilege escalation |
|
Windows GUI QA & Accessibility Engineers | Semantic element targeting via UI Automation (UIA), click-free activation, exact-first matching | Fragile optical/OCR coordinate clicking; broken resolution scaling; brittle UI test automation |
|
Multimodal Human-in-the-Loop Operators | Leased visual signal overlay with countdown, emergency human abort hotkey, push-to-talk voice/chat | Silent background tampering; inability to stop runaway models; disjointed human-agent feedback loops |
|
8. High-Intent Search Term Matrix (SEO & Discoverability)
High-Intent Search Term Matrix (SEO & Discoverability)
Category | Primary Search Terms (English) | PrimΓ€re Suchbegriffe (Deutsch) |
MCP & Agent Tooling |
|
|
UI Automation & Targeting |
|
|
Safety & Governance |
|
|
Visual Signals & Feedback |
|
|
9. 10-Dimension Comparative Matrix vs. Alternatives
open-compute-mcp delivers a model-agnostic, safety-bounded bridge between LLM reasoners and the Windows desktop environment. The following matrix illustrates how open-compute-mcp compares with alternative desktop interaction patterns across 10 operational dimensions:
Evaluation Dimension |
| Direct OS Shell (PowerShell/Win32) | Proprietary Cloud Computer-Use | Heavyweight Vision Frameworks (PyAutoGUI/Selenium) | Standard Ungated MCP Tools |
1. Primary Interface & Transport | PASS (Model Context Protocol JSON-RPC over stdio) | β Raw CLI / PowerShell stdio | β Proprietary SaaS REST / WebSockets | β Python scripts / ad-hoc bindings | β οΈ Generic unstandardized stdio |
2. Safety Ceiling & Guardrails | PASS (Enforced | β 0 guardrails (arbitrary code execution) | β οΈ Opaque vendor-side moderation | β 0 guardrails (direct OS API hooks) | β Unchecked direct tool invocation |
3. State Binding & Observation Lifespan | PASS (One-shot | β Stateless; requires manual polling | β οΈ Ephemeral cloud session state | β Stale coordinate drift; no invalidation | β No coordinate or frame binding |
4. Dual Targeting Precision | PASS (Exact-first UIA + Normalized 0..1 vision coordinates) | β οΈ HWND and Process ID lookups only | β οΈ Pure vision pixel heuristics | β Raw pixel coordinates / web DOM only | β Parameter passing without UI tree |
5. Visual Signal & Countdown | PASS (Leased glowing border, grace timer & screenreader label) | β Invisible background activity | β οΈ Browser/Dashboard canvas preview only | β Silent cursor movements | β No visual user notification |
6. Emergency Abort & Auto-Release | PASS (Global hotkey abort + auto-release of all held keys/mouse) | β Ctrl+C terminates but may leave keys stuck | β οΈ Web UI disconnect button | β οΈ Manual corner flick (keys often get stuck) | β Client disconnect only |
7. Multimodal Feedback | PASS (Built-in push-to-talk WAV recording & screen chat) | β Text stdout/stderr only | β οΈ Web chat textbox | β None | β JSON schema text only |
8. Token Economy Optimization | PASS (0.5x default scale: ~690 tokens vs ~1600 tokens full HD) | N/A (no native vision capabilities) | β Metered cloud token surcharges | β Full-resolution uncompressed dumps | β οΈ Variable uncompressed frame transfers |
9. Privacy & Zero-Egress | PASS (100% offline, zero network telemetry: | β οΈ Local unless script calls external endpoints | β Screen frames streamed to remote cloud | β οΈ Telemetry packages often bundled | β οΈ Dependent on backend transport |
10. Governance & Security SLA | PASS (10 Invariants, 48h Security Response & 5d Triage SLA) | β OS vendor lifecycle | β Proprietary closed-source Terms of Service | β οΈ Community best-effort maintenance | β οΈ Heterogeneous author quality |
10. Governance & Runtime Invariants
Invariant ID | Rule & Principle | Enforcement & Architectural Guarantee |
| Zero-Egress & Local Stdio | All screen capture, mouse/keyboard automation, and signal overlays execute strictly locally over stdio JSON-RPC; 0 telemetry, 0 external analytics, 0 network transmissions. |
| Fail-Closed Safety Ceiling |
|
| One-Shot Observation Lifespan | Every |
| Strict Window Binding | Coordinate actions require verified |
| Leased Signal Overlay & Immediate Abort | Visual signal overlay ( |
| Exact-First Semantic Resolution |
|
| Unprivileged RunAsInvoker Mode | Operates strictly with standard user privileges ( |
| Multi-OS Stdio Protocol Parity | Strict Model Context Protocol (MCP) JSON-RPC adherence tested across Ubuntu, Windows, and macOS on Node.js 18.x, 20.x, 22.x, and 24.x. |
| Multi-Agent Lock & Conflict Discipline | Defensive file system ignore patterns and fail-closed lock checks prevent concurrent workspace pollution and protect cloud synchronization integrity. |
| 48h Security Response & 5-Day Triage SLA | Documented commitment to acknowledge vulnerability disclosures within 48 hours and deliver preliminary triage within 5 business days. |
11. ellmos-ai Ecosystem & Sibling Matrix
This MCP server is part of the ellmos-ai ecosystem β AI infrastructure, MCP servers, and intelligent tools.
MCP Server Family
Server | Tools | Focus | npm |
46 | Filesystem, process management, interactive sessions, cloud-lock-safe operations | ||
22 | Code analysis, JSON repair, imports, diffs, regex | ||
12 | File repair, format conversion, batch operations | ||
18 | n8n workflow management via AI assistants | ||
20 | MCP stack discovery, profile management, control plane | ||
45 | Local-first LLM memory, knowledge, state, routing, swarm orchestration |
| |
8 | Server operations: health checks, log analysis, deploy dry-runs, mail diagnostics |
| |
3 | Headless Blender asset QA and FBX reimport verification |
| |
16 | Model-agnostic computer use: capture, safety-gated actions, Windows UIA, signal overlay & voice/chat |
|
AI Infrastructure & Sibling Tooling
Project | Description |
Local-first text-based OS for LLM agents β 113+ handlers, 550+ tools, SQLite memory | |
Model-agnostic computer-use core powering Open Compute MCP | |
Provider-neutral LLM orchestration with auto-routing and budget tracking | |
Lightweight agent memory, connectors, and automation infrastructure | |
Self-hosted AI research stack (Ollama + n8n + Rinnsal + KnowledgeDigest) | |
Autonomous agent chain framework for Claude Code | |
Minimalist database-driven LLM OS prototype (4 functions, 1 table) | |
Testing framework for LLM operating systems (7 dimensions) | |
Safe, redacted, HMAC-verified SQLite snapshot synchronizer | |
Hierarchical policy & delegation authority engine |
Open Bricks Umbrella
Our partner organization open-bricks bundles AI-native desktop applications β a modern, open-source software suite built for the age of AI. Sibling suites include DevCenter, CodeBox, MethodenAnalyser, CleanMarkdown, and PDFtoPDFocr.
12. Security Policy & Zero-Egress Safety
Computer-use is powerful. OC_SAFETY_MODE is an operator ceiling (confirm
default Β· read_only Β· allow_all); a per-call mode can only tighten it, never
loosen it. Because MCP stdio has no serverβclient confirm callback, confirm /
read_only report an action without performing it. For interactive use, run in
an isolated VM/session, set OC_SAFETY_MODE=allow_all, and let your client's
tool-approval dialog be the human-in-the-loop. OC_DENY (comma-separated action
types) is a hard deny list. Treat on-screen content as untrusted (prompt-injection
risk).
Troubleshooting: do/click_name only ever return needs_confirmation and never
act. That is the confirm ceiling working as designed under stdio MCP. Fix for
interactive use: set "env": {"OC_SAFETY_MODE": "allow_all"} in the server
registration and let the client's tool-approval dialog gate each action (do not
auto-allow do/click_name/invoke there). The env change only takes effect when
the server process (re)starts β an already-connected client keeps the old ceiling
until it reconnects.
13. Level 1 SBOM Transparency & Invariant Matrix
open-compute-mcp maintains a transparent Level 1 Software Bill of Materials (SBOM) ensuring comprehensive supply-chain hygiene and zero-copyleft isolation. Full details are documented in THIRD_PARTY_LICENSES.md.
Runtime Dependency Overview
Package | Version checked | License | Use |
| 7.3.1 | BSD-2-Clause | Non-intrusive interactive CLI update notification (TTY-guarded) |
Invariant Cross-Reference Matrix
Invariant ID | Rule & Principle | Implementation File | Verification & Guarantee |
| Zero-Egress & Local Stdio |
| Pure local stdio JSON-RPC; 0 network telemetry |
| Fail-Closed Safety Ceiling |
| Enforced operator safety ceiling ( |
| One-Shot Observation Lifespan | Python backend via stdio | Single-use ephemeral observation tokens invalidated after 1 action |
| Strict Window Binding | Python backend via stdio | Required window token verification before action execution |
| Leased Signal Overlay & Abort | Python backend via stdio | Leased visual indicator with emergency hotkey abort |
| Exact-First Semantic Resolution | Python backend via stdio | Exact element name match prioritized over fuzzy match |
| Unprivileged RunAsInvoker Mode |
| Operates strictly with standard user privileges; 0 admin elevation |
| Multi-OS Stdio Protocol Parity |
| Tested across Ubuntu, Windows, and macOS on Node 18, 20, 22, 24 |
| Multi-Agent Lock & Conflict Discipline |
| Rejection of cloud locks, sync conflicts, temporary tokens |
| 48h Security Response & 5-Day Triage SLA |
| Binding 48h acknowledgement and 5-day triage commitment |
Non-Elevation Certification (RunAsInvoker)
The launcher and spawned processes are certified to run entirely under standard user permissions (RunAsInvoker). They never request or require administrator or UAC elevation.
Zero-Copyleft Isolation Guarantee
No GPL, AGPL, LGPL, or other copyleft-licensed dependencies are included or linked. All code is distributed under permissive MIT and BSD licenses.
14. Testing & Verification Suite
The repository features a comprehensive automated test suite validating contract invariants, manifest parity, and repository hygiene:
# Run all automated tests
npm test
# Run repository hygiene and secret leakage checks
npm run test:hygiene
# Verify packaging integrity
npm pack --dry-runAll pull requests and commits are verified through GitHub Actions CI (.github/workflows/ci.yml) with automated matrix builds on Ubuntu, Windows, and macOS across Node.js 18.x, 20.x, 22.x, and 24.x.
15. Registry Manifests & Schema Parity
open-compute-mcp adheres to multi-registry standard specifications:
Manifest | Schema / Specification | Purpose |
npm package format (CommonJS) | Defines launcher executable, keywords, and distribution files whitelist | |
MCP Server Schema | Canonical Model Context Protocol registry definition | |
Glama server schema | Informational registry manifest; explicitly documents local-only execution requirements | |
Smithery deployment schema | Defines command-line launch invocation | |
LLM context specification | Machine-readable context index for AI agents and RAG indexers |
16. Quality Gates & Pre-Release Checklist
Every commit and pull request must satisfy rigorous defensive quality gates:
Clean Working Tree: No untracked scratch files, temporary logs, or conflict copies in repository root.
UTF-8 Cleanliness: All documentation files encoded in UTF-8 without BOM or replacement characters (
U+FFFD).Plan D Lock Discipline: Fail-closed verification of multi-agent lock status (
lock_status.py) prior to mutations.Manifest Parity: Version, description, and repository URLs strictly harmonized across
package.json,server.json, andglama.json.Release Decoupling (T-20260920-167562623): Pfad A/B discoverability and hygiene runs strictly preserve the version field without unauthorized bumps.
100% Automated Test Pass Rate: Full test suite passing across all platforms.
17. Licensing & Canonical Attribution
Distributed under the MIT License. See LICENSE for full legal text.
Part of the ellmos-ai family under the open-bricks open-source umbrella. Canonical attribution and dependency inventory are documented in NOTICE and THIRD_PARTY_LICENSES.md.
18. Statutory Notice (Β§ 521 BGB) & 48h Security Response SLA
Statutory Disclaimer under German Law (Β§ 521 BGB)
The software is provided free of charge as an open-source courtesy gift (GefΓ€lligkeit / Schenkung gem. Β§ 516 BGB). In accordance with Β§ 521 BGB, liability is strictly limited to intentional misconduct (Vorsatz) and gross negligence (grobe FahrlΓ€ssigkeit).
48h Security Response & 5-Day Triage SLA
The ellmos-ai / open-bricks team provides a binding commitment to acknowledge all security disclosures within 48 hours and deliver preliminary triage within 5 business days. Reports should be submitted to security@ellmos.ai, support@lukasgeiger.com, or security@open-bricks.org in accordance with SECURITY.md.
This server cannot be deployed
Maintenance
Related MCP Connectors
- WauldoOAuthcom.wauldo
Stateless agentic tools over MCP: concept extraction, long-context, knowledge graph, planning.
OCR, transcription, file extraction, and image generation for AI agents via MCP.
- mcpOAuthcom.screenshotink
Screenshot, diff, audit and sitemap-capture any web page β 5 MCP tools for AI agents.
Free public MCP for AI agents β 193 tools, 44 workflows. No API key.
Related MCP Servers
- FlicenseNot gradedqualityCmaintenanceEnables LLMs to take full control of your device by providing screen automation tools for capturing, clicking, typing, and scrolling, ideal for automation and education.54-
- AlicenseNot gradedqualityCmaintenanceA framework-agnostic computer-use MCP server that exposes core desktop operations (screen capture, mouse, keyboard, and file access) as standard MCP tools, enabling any MCP-compatible agent to drive a computer.460 npmMIT
- AlicenseNot gradedqualityBmaintenanceProvides desktop automation capabilities (e.g., click, browser snapshot) as MCP tools for DSH agents, enabling computer use via natural language.106 npm4MIT
- AlicenseNot gradedqualityBmaintenanceEnables AI agents to operate local desktops and Chromium browsers through MCP tools, unifying accessibility trees, physical input, screenshots, DOM/ARIA, visual grounding, and result verification.460 npmMIT