UIInspect.MCPSAFE
A Windows UI Automation MCP Server for WPF, WinUI, Avalonia & WinForms UIInspect.MCP is a MCP server that gives AI agents and developer tools semantic access to Windows desktop applications. Instead of brittle pixel‐based automation, UIInspect.MCP exposes a rich, structured view of the UI
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
UIInspect.MCP.Server is a consent-gated NuGet MCP server that gives AI agents semantic access to Windows applications through UI Automation 3 (UIA3). It discovers accessible application windows, returns bounded control trees, and performs deterministic actions against opaque element references instead of relying on screenshots or pixel coordinates.
The package runs as a local stdio server on .NET 10. WPF, WinForms, WinUI 3, Avalonia, and .NET MAUI Windows are directly tested against deterministic UI Automation fixtures.
Quick Install
Once the package is available on NuGet.org, click to install it in your preferred environment:
[](https://vscode.dev/redirect/mcp/install?name=uiinspect-mcp&config=%7B%22type%22%3A%22stdio%22%2C%22command%22%3A%22dnx%22%2C%22args%22%3A%5B%22UIInspect.MCP.Server%400.%2A%22%2C%22--prerelease%22%2C%22--yes%22%5D%7D) [](https://insiders.vscode.dev/redirect/mcp/install?name=uiinspect-mcp&config=%7B%22type%22%3A%22stdio%22%2C%22command%22%3A%22dnx%22%2C%22args%22%3A%5B%22UIInspect.MCP.Server%400.%2A%22%2C%22--prerelease%22%2C%22--yes%22%5D%7D&quality=insiders) [](https://vs-open.link/mcp-install?%7B%22name%22%3A%22UIInspect.MCP.Server%22%2C%22type%22%3A%22stdio%22%2C%22command%22%3A%22dnx%22%2C%22args%22%3A%5B%22UIInspect.MCP.Server%400.%2A%22%2C%22--prerelease%22%2C%22--yes%22%5D%7D)
Note:
- Th
f2c51c694ba3OBSERVED · 2026-10-08Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (1 observation(s))
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (4)
- The dialog is single-flight and shown at most once per client and exact process instance during one server session. Concurrent or repeated calls share the first terminal decision, and cancellation d
UIA normally requires the server and target to share an interactive Windows session. A non-elevated server cannot automate higher-integrity/elevated targets. Secure desktop and protected processes rem
images/ReadmeHero.png
Gates applied: no_behavioural_pass.
f2c51c694ba3full audit observations/trust-audit/mcp-server/chrispulman__uiinspect.mcp.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | f2c51c694ba3 | SAFE | B | 89 | first audit |
Questions
What is the UIInspect.MCP MCP server?
A Windows UI Automation MCP Server for WPF, WinUI, Avalonia & WinForms UIInspect.MCP is a MCP server that gives AI agents and developer tools semantic access to Windows desktop applications. Instead of brittle pixel‐based automation, UIInspect.MCP exposes a rich, structured view of the UI
Is UIInspect.MCP safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does UIInspect.MCP need?
No credential environment variables were found in its source, so it appears to need none.
How does UIInspect.MCP run?
It speaks stdio, so it runs as a local process your client starts.
How current is this page?
The grade is for one exact copy of the source (f2c51c694ba3), read on 2026-10-08. The repository is watched and re-audited when it changes.