Atlas / MCP servers / chrispulman / UIInspect.MCP

UIInspect.MCPSAFE

mcp/chrispulman/uiinspect-mcp

A Windows UI Automation MCP Server for WPF, WinUI, Avalonia & WinForms UIInspect.MCP is a MCP server that gives AI agents and developer tools semantic access to Windows desktop applications. Instead of brittle pixel‐based automation, UIInspect.MCP exposes a rich, structured view of the UI

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
—
Transport
stdio
License
MIT
Stars
3
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

UIInspect.MCP.Server is a consent-gated NuGet MCP server that gives AI agents semantic access to Windows applications through UI Automation 3 (UIA3). It discovers accessible application windows, returns bounded control trees, and performs deterministic actions against opaque element references instead of relying on screenshots or pixel coordinates.

The package runs as a local stdio server on .NET 10. WPF, WinForms, WinUI 3, Avalonia, and .NET MAUI Windows are directly tested against deterministic UI Automation fixtures.

Quick Install

Once the package is available on NuGet.org, click to install it in your preferred environment:

[](https://vscode.dev/redirect/mcp/install?name=uiinspect-mcp&config=%7B%22type%22%3A%22stdio%22%2C%22command%22%3A%22dnx%22%2C%22args%22%3A%5B%22UIInspect.MCP.Server%400.%2A%22%2C%22--prerelease%22%2C%22--yes%22%5D%7D) [](https://insiders.vscode.dev/redirect/mcp/install?name=uiinspect-mcp&config=%7B%22type%22%3A%22stdio%22%2C%22command%22%3A%22dnx%22%2C%22args%22%3A%5B%22UIInspect.MCP.Server%400.%2A%22%2C%22--prerelease%22%2C%22--yes%22%5D%7D&quality=insiders) [](https://vs-open.link/mcp-install?%7B%22name%22%3A%22UIInspect.MCP.Server%22%2C%22type%22%3A%22stdio%22%2C%22command%22%3A%22dnx%22%2C%22args%22%3A%5B%22UIInspect.MCP.Server%400.%2A%22%2C%22--prerelease%22%2C%22--yes%22%5D%7D)

Note:

  • Th
Read from source at commit f2c51c694ba3OBSERVED · 2026-10-08
02

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (1 observation(s))
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (4)

LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
docs/security.md:16
- The dialog is single-flight and shown at most once per client and exact process instance during one server session. Concurrent or repeated calls share the first terminal decision, and cancellation d
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
docs/security.md:67
UIA normally requires the server and target to share an interactive Windows session. A non-elevated server cannot automate higher-integrity/elevated targets. Secure desktop and protected processes rem
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWInventory / provenance · mcp.no_tools_extracted · CWE-1104
.mcp/server.json
Why it matters. the tool list is enumerated at runtime by tools/list, not declared in source
Fix. the page says so rather than showing an empty table
INFOInventory / provenance · inv.oversize · CWE-1104
images/ReadmeHero.png
images/ReadmeHero.png
Why it matters. 1185540 bytes not read

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha f2c51c694ba3full audit observations/trust-audit/mcp-server/chrispulman__uiinspect.mcp.json · Report an issue / request a re-scan
03

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08f2c51c694ba3SAFEB89first audit
04

Questions

What is the UIInspect.MCP MCP server?

A Windows UI Automation MCP Server for WPF, WinUI, Avalonia & WinForms UIInspect.MCP is a MCP server that gives AI agents and developer tools semantic access to Windows desktop applications. Instead of brittle pixel‐based automation, UIInspect.MCP exposes a rich, structured view of the UI

Is UIInspect.MCP safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does UIInspect.MCP need?

No credential environment variables were found in its source, so it appears to need none.

How does UIInspect.MCP run?

It speaks stdio, so it runs as a local process your client starts.

How current is this page?

The grade is for one exact copy of the source (f2c51c694ba3), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement