agent-computer-use
Provides desktop automation on macOS via Accessibility and Screen Capture, enabling AI agents to control allowed applications with policy enforcement, audit logging, crash recovery, and task journaling.
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@agent-computer-useOpen Calculator and calculate 5 + 7"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
π₯οΈ /agent-computer-use
Enterprise-grade Safety, Policy Enforcement, and Crash Recovery Middleware for Desktop AI Agents on macOS
agent-computer-use is an open-source, high-reliability Model Context Protocol (MCP) proxy server built on top of Cua Driver.
While raw computer-use drivers provide the low-level capability to click and type, agent-computer-use provides the missing enterprise safety layer: strict per-application bundle ID access control, fail-closed enforcement, instant kill-switches, sanitized audit logging, crash recovery, and durable task journaling for autonomous agents.
ποΈ Architecture
graph TD
classDef client fill:#1e293b,stroke:#3b82f6,stroke-width:2px,color:#f8fafc;
classDef proxy fill:#0f172a,stroke:#6366f1,stroke-width:2px,color:#f8fafc;
classDef module fill:#1e1b4b,stroke:#818cf8,stroke-width:1px,color:#e0e7ff;
classDef driver fill:#064e3b,stroke:#10b981,stroke-width:2px,color:#ecfdf5;
classDef app fill:#450a0a,stroke:#ef4444,stroke-width:2px,color:#fef2f2;
Client["<b>AI Agent / MCP Client</b><br/>Antigravity IDE Β· Claude Code Β· Codex Β· Cursor"]:::client
subgraph ACU ["agent-computer-use (Proxy Server)"]
direction TB
subgraph Safety ["Security & Observability Layer"]
Enforcer["<b>PolicyEnforcer</b><br/>β’ Fail-Closed Bundle Allowlist<br/>β’ Hardcoded Denylist Priority<br/>β’ Live STOP File Kill-Switch"]:::module
Audit["<b>AuditLogger</b><br/>β’ Masked Typed Text<br/>β’ Binary/Screenshot Stripping<br/>β’ JSONL 10MB Auto-Rotation"]:::module
Journal["<b>JournalManager</b><br/>β’ Session Task Journaling<br/>β’ Context Loss Recovery"]:::module
end
Recovery["<b>AppRecoveryManager</b><br/>β’ ensure_app_running self-healing<br/>β’ autoRelaunch detection"]:::module
end
Driver["<b>Cua Driver (stdio daemon)</b><br/>macOS Accessibility (AXUIElement) Β· Screen Capture"]:::driver
Apps["<b>Target Desktop Applications</b><br/>Calculator Β· Browsers Β· Enterprise Apps"]:::app
Client <-->|"stdio (JSON-RPC)"| ACU
Safety --> Recovery
ACU <-->|"stdio (JSON-RPC)"| Driver
Driver <-->|"AXEvents (Background Delivery Mode)"| AppsRelated MCP server: Daimon
β¨ Key Features
Capability | What It Does | Why It Matters |
π Fail-Closed Security | Blocks all GUI interactions unless an app is explicitly added to | Prevents rogue AI agents from wandering into arbitrary desktop windows. |
β Protected App Denylist | Hard-blocks password managers (1Password, Bitwarden, Keychain), System Settings, and Terminals. | Denylist takes absolute priority even if wildcards ( |
π Instant Kill-Switch | Creates | Halts runaway agents on the fly without needing to kill IDE processes. |
π€« Private Audit Log | Writes JSONL events with masked keystrokes ( | Full compliance and security audit trails without leaking secrets or filling disks. |
π Self-Healing Recovery | Custom | Agents recover automatically without throwing raw OS errors or getting stuck. |
π Durable Task Journal | Persistent JSONL journal ( | Survives agent memory loss, context compaction, and IDE restarts. |
β‘ Minimal Tool Profile | Downsamples Cua Driver's 58 tools into 16 focused, reliable primitives. | Keeps agent prompt context small, prevents tool confusion, and improves LLM reasoning. |
π Quick Start
1. Prerequisites
OS: macOS 13+ (Sonoma, Sequoia, or newer; Apple Silicon & Intel).
Node.js: v20+ (v22 LTS recommended).
Cua Driver: Installed via the official one-liner:
/bin/bash -c "$(curl -fsSL https://cua.ai/driver/install.sh)"
2. Installation
git clone https://github.com/waniyaro/agent-computer-use.git
cd agent-computer-use
npm install
npm run build3. Run System Diagnostics (acu doctor)
node dist/bin/acu.js doctorThe doctor verifies macOS version, Cua Driver binary, Accessibility & Screen Recording permissions, policy schema validity, and client integrations:
======================================================
agent-computer-use Doctor Report
======================================================
--- 1. macOS Environment ---
[OK] Operating System: macOS 26.6.2 (arm64)
--- 2. Cua Driver ---
[OK] Binary executable: ~/.local/bin/cua-driver (cua-driver 0.34.0)
--- 3. macOS Permissions ---
[OK] TCC Grants: Accessibility: granted, Screen Recording: granted
--- 4. Policy Configuration ---
[OK] policy.json validation: Valid (toolProfile='minimal', allowedApps=1)
--- 5. Kill-Switch Status ---
[OK] Emergency STOP file: Inactive (normal operation)
--- 6. Client Integrations ---
[OK] Antigravity IDE: Configured in ~/.gemini/config/mcp_config.json
[OK] Claude Code: Configured in ~/.claude.json
------------------------------------------------------
Overall Status: [OK]
======================================================4. Connect to Your MCP Client (acu install)
Install into your AI IDE with safe dry-run preview and automatic timestamped backups:
# Preview configuration (safe dry-run)
node dist/bin/acu.js install --client antigravity --dry-run
# Write configuration (creates .bak copy and preserves all other MCP servers)
node dist/bin/acu.js install --client antigravity --writeSupported clients:
antigravity(Google Antigravity IDE)claude-code(Anthropic Claude Code CLI)codex(Codex CLI)
π‘οΈ Policy Configuration (policy.json)
Location: ~/.config/agent-computer-use/policy.json
{
"allowedApps": [
"com.apple.calculator"
],
"deniedApps": [
"com.1password.1password",
"com.agilebits.onepassword7",
"com.bitwarden.desktop",
"com.apple.keychainaccess",
"com.apple.systempreferences",
"com.apple.Terminal",
"com.googlecode.iterm2",
"1Password",
"Bitwarden",
"Keychain",
"System Settings",
"Terminal",
"iTerm"
],
"maxActionsPerSession": 200,
"toolProfile": "minimal",
"allowForeground": false,
"logTypedText": false,
"autoRelaunch": false
}Configuration Reference
Option | Type | Default | Description |
|
|
| Whitelist of application bundle IDs or names. When empty, all action tools are blocked (Fail-Closed). |
|
|
| Blacklist of sensitive apps. Always evaluated before |
|
|
| Safety cap preventing infinite loops or hallucinated repetitive clicks. |
|
|
|
|
|
|
| When |
|
|
| When |
|
|
| Automatically restarts the target application when a crash is detected. |
Emergency Kill-Switch
To instantly freeze all actions without restarting your IDE:
touch ~/.config/agent-computer-use/STOPTo resume:
rm ~/.config/agent-computer-use/STOPπ οΈ Custom Proxy Tools
In addition to proxying Cua Driver primitives (click, type_text, scroll, get_window_state), agent-computer-use introduces 4 high-level reliability tools:
ensure_app_running
Verifies whether an application process and window exist. If closed or crashed, launches it in the background, waits for window initialization, and updates process caches.
{
"bundle_id": "com.apple.calculator",
"timeout_ms": 5000
}task_journal_append
Appends a milestone, observation, or status update to the session's JSONL journal (~/.config/agent-computer-use/journal/<task_id>.jsonl).
{
"note": "Calculated 17 * 23 = 391",
"status": "completed"
}task_journal_read
Reads past checkpoints so an agent can resume trajectories after compaction or restart.
{
"task_id": "session-20261007-152252-87a2df"
}task_journal_list
Lists all historical and active task journals with summary statistics.
π§ͺ Testing
The test suite runs with Vitest and validates proxy resilience, policy enforcement, audit sanitization, and CLI commands:
npm test β tests/cli.test.ts (9 tests)
β tests/policy.test.ts (6 tests)
β tests/proxy.test.ts (4 tests)
β tests/recovery.test.ts (4 tests)
Test Files 4 passed (4)
Tests 23 passed (23)π€ Contributing
Contributions are warmly welcome! Please review CONTRIBUTING.md and SECURITY.md before opening a pull request.
π License
This project is licensed under the MIT License.
Underlying desktop automation powered by Cua Driver (MIT License).
This server cannot be deployed
Maintenance
Related MCP Connectors
Zero-secret MCP gateway for AI agents: risk-scored, audited calls with human-in-the-loop approval.
Security gateway for AI agents: policy, approval, and audited execution, no secrets shared.
Supervised API-write gateway for AI agents with policy, human approval and execution receipts.
Operate Linux, macOS and Windows from your LLM. Every action runs through an auditable allowlist.
Related MCP Servers
- AlicenseNot gradedqualityDmaintenanceAn MCP server for macOS that enables AI agents to control the desktop GUI through keyboard input, mouse actions, and screen captures. It provides stable low-level primitives for UI automation and agent-driven desktop workflows.MIT
- AlicenseNot gradedqualityCmaintenanceA local daemon for macOS that gives any MCP-capable AI client eyes, hands, and a face β screen capture, accessibility tree, mouse/keyboard actions, and an overlay β with a built-in security ceiling.2AGPL 3.0
- AlicenseNot gradedqualityDmaintenanceA secure, constraint-based macOS OS-level automation MCP server for AI assistants.MIT
- AlicenseAqualityDmaintenanceA macOS computer-use MCP server that grants AI agents mouse, keyboard, and screen control with a robust security model including permission profiles, app deny-lists, and audit logging.22MIT