Are you the author? Sign in to claim
npm launcher for the open-compute MCP server: model-agnostic computer-use (screenshot, safety-gated actions, Windows UIA
npm launcher for the open-compute MCP server — model-agnostic computer-use tools exposed over the Model Context Protocol (MCP).
EN | DE
[!NOTE] AI Assistant / Agent Integration: This repository contains an
llms.txtfile providing structured, machine-readable specifications of tools, safety modes (OC_SAFETY_MODE), and client configuration examples for RAG crawlers and autonomous agent frameworks.
The MCP client is the reasoner (no API key, model-agnostic): it calls capture
to see the screen, then acts with do / click_name / invoke. This is the keyless
Mode-A loop of open-compute, but as native tool-calls.
graph TD
A["AI Reasoner<br/>(Claude / Antigravity / Cursor)"] -- "MCP stdio (JSON-RPC)" --> B["npx open-compute-mcp<br/>(Node.js Launcher)"]
B -- "Spawns via uvx" --> C["open-compute Python Engine<br/>(GitHub @ main)"]
C -- "Screenshots / WGC" --> D["Windows Display"]
C -- "UIA / Mouse / Keys" --> E["Windows Desktop Apps"]
subgraph Safety Gate
C -. "OC_SAFETY_MODE<br/>(confirm / read_only / allow_all)" .-> C
end
This package is a thin launcher. It contains no server logic — it spawns the Python open-compute server (pulled from GitHub) and pipes MCP stdio through. Real screen capture and input require the interactive Windows desktop session.
uvx to fetch open-compute (with the mcp extra) from GitHub on
first run — the mcp extra tracks the GitHub repo, so this works regardless of
PyPI release timing.| Tool | Purpose |
|---|---|
capture | Screenshot the screen → returned as an image (optionally a single window). |
do | Execute one canonical action or a batch (click/type/key/scroll/drag/hold/…). |
tree | List UI elements via Windows UIA (name/role/center_norm). |
click_name | Resolve an element by name and click it. |
invoke | Click-free activation of an element via UIA patterns. |
list_windows | List open windows with exact titles, rects and normalized centers (read-only). |
get_screen_size | Virtual-desktop geometry + per-monitor breakdown (read-only). |
watch_dir | Watch directories for file-system changes. |
push_status | Feed-manager status (read-only). |
rec_replay | Replay a .clirec macro (needs the optional clirec package). |
All coordinates are normalized 0..1 relative to the virtual desktop. Tool
descriptions are localized in six languages (de/en/es/ja/ru/zh) via OC_LANGUAGE.
do also accepts the hold primitives mouse_down / mouse_up / key_down /
key_up for press-and-hold sequences (rubber-band selection, modifier-held
clicking, game input); anything still held is released when the server stops.
capture(window=...) falls back to Windows.Graphics.Capture when a plain grab of
a hardware-composited window (Roblox Studio, Blender, a GPU-accelerated browser)
comes back all-black — install the wgc extra for that.
Via this npm launcher (npx):
{
"mcpServers": {
"open-compute": {
"command": "npx",
"args": ["-y", "open-compute-mcp"]
}
}
}
Directly via Python (uvx), no npm:
{
"mcpServers": {
"open-compute": {
"command": "uvx",
"args": ["--from", "open-compute[mcp,local,uia] @ git+https://github.com/ellmos-ai/open-compute.git", "open-compute-mcp"]
}
}
}
| Variable | Effect |
|---|---|
OPEN_COMPUTE_PYTHON | Path to a python.exe; the launcher runs -m open_compute.mcp_server with it (use this if you installed open-compute into a specific environment). |
OPEN_COMPUTE_MCP_CMD | Full command override (whitespace-split), e.g. python -m open_compute.mcp_server. |
OPEN_COMPUTE_GIT_REF | Git ref (branch/tag/sha) to pin for the uvx launch (default: the repo's default branch). |
OPEN_COMPUTE_EXTRAS | Extras for the default uvx launch (default mcp,local,uia). |
OC_LANGUAGE | Language of the tool descriptions: de/en/es/ja/ru/zh. |
OC_SAFETY_MODE | confirm (default) · read_only · allow_all. |
OC_DENY | Comma-separated action types always denied (e.g. type,launch_app). |
Computer-use is powerful. OC_SAFETY_MODE is an operator ceiling (confirm
default · read_only · allow_all); a per-call mode can only tighten it, never
loosen it. Because MCP stdio has no server→client confirm callback, confirm /
read_only report an action without performing it. For interactive use, run in
an isolated VM/session, set OC_SAFETY_MODE=allow_all, and let your client's
tool-approval dialog be the human-in-the-loop. OC_DENY (comma-separated action
types) is a hard deny list. Treat on-screen content as untrusted (prompt-injection
risk).
Troubleshooting: do/click_name only ever return needs_confirmation and never
act. That is the confirm ceiling working as designed under stdio MCP. Fix for
interactive use: set "env": {"OC_SAFETY_MODE": "allow_all"} in the server
registration and let the client's tool-approval dialog gate each action (do not
auto-allow do/click_name/invoke there). The env change only takes effect when
the server process (re)starts — an already-connected client keeps the old ceiling
until it reconnects.
MIT — see LICENSE. Part of the open-compute project.
This MCP server is part of the ellmos-ai ecosystem — AI infrastructure, MCP servers, and intelligent tools.
| Server | Tools | Focus | npm |
|---|---|---|---|
| FileCommander | 46 | Filesystem, process management, interactive sessions, cloud-lock-safe operations | ellmos-filecommander-mcp |
| CodeCommander | 22 | Code analysis, JSON repair, imports, diffs, regex | ellmos-codecommander-mcp |
| Clatcher | 12 | File repair, format conversion, batch operations | ellmos-clatcher-mcp |
| n8n Manager | 18 | n8n workflow management via AI assistants | n8n-manager-mcp |
| ControlCenter | 20 | MCP stack discovery, profile management, control plane | ellmos-controlcenter-mcp |
| Homebase | 45 | Local-first LLM memory, knowledge, state, routing, swarm orchestration | ellmos-homebase-mcp (alpha) |
| ServerCommander | 8 | Server operations: health checks, log analysis, deploy dry-runs, mail diagnostics | ellmos-servercommander-mcp (alpha) |
| Blender Use | 3 | Headless Blender asset QA and FBX reimport verification | ellmos-blender-use-mcp (alpha) |
| Open Compute | 10 | Model-agnostic computer use: capture, safety-gated actions, Windows UIA | open-compute-mcp (alpha) |
| Project | Description |
|---|---|
| BACH | Local-first text-based OS for LLM agents — 113+ handlers, 550+ tools, SQLite memory |
| open-compute | Model-agnostic computer-use core powering Open Compute MCP |
| clutch | Provider-neutral LLM orchestration with auto-routing and budget tracking |
| rinnsal | Lightweight agent memory, connectors, and automation infrastructure |
| ellmos-stack | Self-hosted AI research stack (Ollama + n8n + Rinnsal + KnowledgeDigest) |
| MarbleRun | Autonomous agent chain framework for Claude Code |
| gardener | Minimalist database-driven LLM OS prototype (4 functions, 1 table) |
| ellmos-tests | Testing framework for LLM operating systems (7 dimensions) |
Our partner organization open-bricks bundles AI-native desktop applications — a modern, open-source software suite built for the age of AI. Categories include file management, document tools, developer utilities, and more.
Run Claude Code as an MCP server so any agent can delegate coding tasks to it
Browser automation using accessibility snapshots instead of screenshots
Google's universal MCP server supporting PostgreSQL, MySQL, MongoDB, Redis, and 10+ databases
Official GitHub integration for repos, issues, PRs, and CI/CD workflows