WindowsCAUTION
MCP Server for Computer Use in Windows
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
🪟 Windows-MCP
Windows-MCP is a lightweight, open-source project that enables seamless integration between AI agents and the Windows operating system. Acting as an MCP server bridges the gap between LLMs and the Windows operating system, allowing agents to perform tasks such as file navigation, application control, UI interaction, QA testing, and more.
mcp-name: io.github.CursorTouch/Windows-MCP
Updates
- Windows-MCP reached
2M+ Usersin Claude Desktop Extensiosn. - Try out [🪟Windows-U
4501cc7c604eOBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add windows-mcp -- uvx windows-mcp==0.8.7
Exposed tools (9)
7 read · 2 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
Action | read | effects.append( |
After | read | effects.append( |
ControlStatus | read | return controller.status() |
DynamicTool | read | effects.append(current_token.get()) |
Hold | write | started.set() |
Interrupted | read | for _ in range(3): |
Next | read | effects.append( |
Other | read | return |
command | write | started.set() |
Trust audit
CAUTIONgrade B · trust 82/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | WARN |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (5 observation(s))
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (15)
return subprocess.run(["schtasks", *args], capture_output=True, text=True)
f"schtasks /Run failed:\n{run_result.stderr.strip() or run_result.stdout.strip()}"system use found in code, not declared in the description
.mcpbignore
exec(code, namespace)
"comtypes-gen-%s.lock" % hashlib.md5(sys.prefix.encode("utf-8")).hexdigest(),return subprocess.CompletedProcess(["schtasks", *args], returncode, "", "")
"http://169.254.169.254/latest/meta-data/",
f"http://127.0.0.1:{port}/mcp", log_handler=on_logyield f"http://127.0.0.1:{server.server_port}""http://127.0.0.1:7777/secret",
"http://169.254.169.254/latest/meta-data/",
"http://10.0.0.5/admin",
- Avoid running Windows-MCP with elevated privileges unless absolutely necessary
- UV (Package Manager) from Astra, install with `pip install uv` or `curl -LsSf https://astral.sh/uv/install.sh | sh`
Gates applied: no_behavioural_pass.
4501cc7c604efull audit observations/trust-audit/mcp-server/cursortouch__windows-3.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 4501cc7c604e | CAUTION | B | 82 | first audit |
Questions
What is the Windows MCP server?
MCP Server for Computer Use in Windows
What tools does Windows expose?
9 in total: 7 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Windows safe to connect to an agent?
With care. The audit graded it B (82/100) and found 15 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does Windows need?
It reads POSTHOG_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Windows run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on PyPI as windows-mcp.
How current is this page?
The grade is for one exact copy of the source (4501cc7c604e), read on 2026-10-08. The repository is watched and re-audited when it changes.