DeskbridBLOCK
Linux desktop HAL for AI agents. One daemon, one socket, every desktop action. GNOME, KDE, Hyprland, X11. Ships in one command.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
📖 Docs
mcp-name: io.github.coe0718/deskbrid
📖 Documentation | API Reference | Architecture | v1.0.0 Release Notes
The HAL your Linux desktop agents are missing.
Deskbrid is a single Rust binary that auto-detects your desktop environment and wraps it into a JSON-over-Unix-socket protocol. GNOME, Hyprland, KDE, COSMIC, Sway, Niri, Wayfire, Labwc, Cinnamon, MATE — one daemon, one protocol, one binary.
# Human
deskbrid windows list
deskbrid clipboard read
# Agent (same socket)
{"action": "windows.list"} → [{"title": "VS Code", "app_id": "code", ...}]Table of Contents
- Why Deskbrid
- [Supported Desktops](#supporte
0dc12f0c7bd7OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add deskbrid:1.4.0 -- docker run -i --rm ghcr.io/coe0718/deskbrid:1.4.0:None
Trust audit
BLOCKgrade F · trust 47/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | FAIL |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (12 observation(s))
- Network
- declared (7 observation(s))
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- found
Findings (25)
"ghp_aBcDeFgHiJkLmNoPqRsTuVwXyZ0123456789ABCD"
"ghs_aBcDeFgHiJkLmNoPqRsTuVwXyZ0123456789ABCD"
"-----BEGIN RSA PRIVATE KEY-----\nMIIEowIBAAKCAQEA...\n-----END RSA PRIVATE KEY-----";
"-----BEGIN RSA PRIVATE KEY-----\nMIIEowIBAAKCAQEA\n-----END RSA PRIVATE KEY-----";
D-Bus calls bypass most of Deskbrid's safety layer — use with caution.
curl -s -o /dev/null -w "%{http_code}" http://127.0.0.1:20129let url = format!("http://127.0.0.1:{port}/json");const PORTAL_SCREENSHOT_SCRIPT: &str = include_str!("../../../../scripts/screenshot_portal.py");let traversal = "/tmp/../../../etc/passwd";
"../../../etc/passwd traversal should be blocked"
let traversal = "/tmp/../../../etc/shadow";
let result = expand_path("~/../../../etc/passwd").await;base_url: String, // "https://192.168.1.100:8006/api2/json"
<span class="output">→ Dashboard: http://127.0.0.1:20129</span><br>
<span class="output">→ Dashboard: http://127.0.0.1:20129</span><br>
- `browser.evaluate` can execute arbitrary JavaScript, which has full access to the page's DOM, cookies, localStorage, and network. This is **privileged access** — treat it with the same caution as a
- Processes run with the full permissions of the daemon user — there is no sandboxing. Spawning `sudo` or privileged commands will only work if the daemon user has password-less sudo or the appropriat
- Starting, stopping, enabling, or disabling services and timers requires **elevated permissions** (user's systemd bus access). The daemon must either run as root or the user must have sudo/PolKit pri
| **Ticket** | POST `/api2/json/access/ticket` → cookie `PVEAuthCookie` + `CSRFPreventionToken` header | Full root access, requires password |
**What's Missing:** No way to read or modify environment variables in the
Provide agents secure access to stored credentials (GNOME Keyring, KDE KWallet) through the Deskbrid protocol. Agents need this for authenticated API calls, GitHub tokens, etc. — without storing secre
**Secret/keyring service** — read back credentials via `secret-tool` / Secret Service; gated by confirmation.
5. **Check VT assignment.** `sudo fgconsole` tells you the active VT. `journalctl -u sddm --since '30 seconds ago'` tells you which VT SDDM started on. If they don't match, tell the user to switch VTs
"curl -fsSL https://deskbrid.patchhive.dev/install.sh | bash"
curl -fsSL https://deskbrid.patchhive.dev/install.sh | bash
Gates applied: critical_finding, instruction_override, no_behavioural_pass.
0dc12f0c7bd7full audit observations/trust-audit/mcp-server/coe0718__deskbrid.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 0dc12f0c7bd7 | BLOCK | F | 47 | first audit |
Questions
What is the Deskbrid MCP server?
Linux desktop HAL for AI agents. One daemon, one socket, every desktop action. GNOME, KDE, Hyprland, X11. Ships in one command.
Is Deskbrid safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (47/100) and found 5 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does Deskbrid need?
It reads DESKBRID_TCP_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Deskbrid run?
It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as deskbrid.
How current is this page?
The grade is for one exact copy of the source (0dc12f0c7bd7), read on 2026-10-08. The repository is watched and re-audited when it changes.