NovaCAUTION
Cross-platform Rust computer-use MCP server for macOS and Windows: AX/UIA, screenshots, OCR, pointer and keyboard input, clipboard, stdio, and HTTP.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
English · 简体中文
Let any MCP agent use your real Mac or Windows apps. Nova is a single Rust binary, with no Python runtime, that gives Claude Desktop, Cursor, Codex, Claude Code and other MCP clients screenshots, native OCR, keyboard and mouse input, clipboard access, window/app control and Accessibility/UIA actions on macOS and Windows.
Releases · Part of Bodhi · Bodhi desktop app · MIT
- Your real desktop, not a VM: macOS 14+ (Apple Silicon and Intel) and
Windows x64/ARM64.
- Reads before it clicks: Accessibility/UIA controls, Apple Vision or
Windows OCR, and per-window screenshots with zoom. Clicks are given in the screenshot's pixel space and mapped back to the screen.
- Types any text: full Unicode keyboard input, including Chinese, Japanese,
Korean and emoji.
- Accessibility-first control (v0.3.0): AX-first
ax_read/ax_activate
that reject stale snapshots, a 64-step batch_actions limit with structured failure reports, the Nova.app permission owner (development preview) and an optional Chrome DevTools sidecar. Latest release: v0.3.0 — Releases.
Static image · Reproduce and inspect MCP evidence
This recording shows Nova's browser tool path (fixture page and real MCP navigation/click calls). It was captured on Linux, so it does not show native macOS/Windows desktop control or model reasoning. The reproduction notes explain the --npx adapter and isolated browser.
Install
1706bb0e4223OBSERVED · 2026-10-09Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add nova -- npx -y @bigduu/[email protected]
{
"mcpServers": {
"nova": {
"command": "npx",
"args": [
"-y",
"@bigduu/[email protected]"
]
}
}
}Trust audit
CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | WARN |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (4 observation(s))
- Network
- declared (5 observation(s))
- Shell
- declared (1 observation(s))
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (13)
The final visibility case uses the same origin with `<button style="visibility:hidden"><span style="visibility:visible">Visible caption</span></button>` and `<h2 style="display:contents">Contents head
["unsafe request ID", { requestId: "../../escape" }, "invalid_request_id"],ICON_SOURCE="$SCRIPT_DIRECTORY/../../assets/nova-app-icon.png"
cp "$SCRIPT_DIRECTORY/../../LICENSE" "$APP/Contents/Resources/LICENSE"
nova chrome-devtools --browser-url http://127.0.0.1:9222
nova chrome-devtools --browser-url http://127.0.0.1:9222
origin=`http://127.0.0.1:${servers[0].address().port}`;otherOrigin=`http://127.0.0.1:${servers[1].address().port}`;origin = `http://127.0.0.1:${servers[0].address().port}`;assets/nova-app-icon.png
docs/assets/nova-nature-hero.png
docs/demos/browser-checklist.gif
Gates applied: no_behavioural_pass.
1706bb0e4223full audit observations/trust-audit/mcp-server/bigduu__nova.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-09 | 1706bb0e4223 | CAUTION | B | 89 | first audit |
Questions
What is the Nova MCP server?
Cross-platform Rust computer-use MCP server for macOS and Windows: AX/UIA, screenshots, OCR, pointer and keyboard input, clipboard, stdio, and HTTP.
Is Nova safe to connect to an agent?
With care. The audit graded it B (89/100) and found 13 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does Nova need?
No credential environment variables were found in its source, so it appears to need none.
How does Nova run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @bigduu/nova at 0.3.0.
How current is this page?
The grade is for one exact copy of the source (1706bb0e4223), read on 2026-10-09. The repository is watched and re-audited when it changes.