Atlas / MCP servers / mario-andreschak / Windows Desktop Automation

Windows Desktop AutomationBLOCK

mcp/mario-andreschak/windows-desktop-automation

A Model Context Protocol (MCP) server for Windows desktop automation using AutoIt.

Verdict
BLOCK
Grade
D
Trust score
69 /100
Exposed tools
50 48r · 2w · 0d
Transport
stdio · streamable-http
License
MIT
Stars
118
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

A trusted-owner MCP server for an interactive Windows x64 desktop. Version 2 retains the original 50 AutoIt tools and seven prompts, adds actual PNG screenshots, and supports MCP 2026-07-28 through SDK 2.0.0. Explicit compatibility serves legacy 2025-11-25 clients.

Run

Requires Node.js 22 or newer. Install this repository or its reviewed release artifact, then run the installed command:

npm ci
npm run build
node dist/index.js --transport=stdio
# After installing the package:
mcp-windows-desktop-automation --transport=stdio

Stdio stdout contains only MCP JSON messages. Diagnostics, including verbose operation names, go to stderr without argument values. Closing stdin closes the server and its native helper.

Native operations require Windows x64 and the logged-in user's interactive desktop. Enumeration and protocol handling also run on Linux, where native calls return an explicit platform error. ARM64, services in session 0, headless Windows sessions, other users' sessions, and elevated windows beyond the server's privileges are not supported. No provider account or model is involved.

Transports and ownership

Stdio is the default. For HTTP, set:

  • MCP_AUTH_TOKEN: a random owner bearer token of at least 32 characters.
  • MCP_FILE_ROOTS: a JSON array of existing local directories, for example ["C:\\Users\\me\\Documents"].
  • Optional MCP_ALLOWED_HOSTS: comma-separated exact Host values, including port when used.
  • Optional MCP_ALLOWED_ORIGINS: comma-separated exact origins.

Then launch mcp-windows-desktop-automation --transport=streamable-http --port=3000. The endpoint is http://127.0.0.1:3000/mcp; --host=ADDRESS explicitly changes the loopback default. Authorization is required for every endpoint request. Host and Origin are checked exactly; forwarded headers are not trusted, and permissive CORS is not enabled. Use a trusted TLS reverse proxy for remote deployment.

This is one owner per process,

Read from source at commit f6f17b1bdcc2OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add mcp-windows-desktop-automation --env MCP_AUTH_TOKEN=${MCP_AUTH_TOKEN} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "mcp-windows-desktop-automation": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "MCP_AUTH_TOKEN": "${MCP_AUTH_TOKEN}"
      }
    }
  }
}
03

Exposed tools (50)

48 read · 2 write · 0 destructive.

ToolRiskDescription
autoItSetOptionread
clipGetread
clipPutread
controlClickread
controlClickByHandleread
controlCommandread
controlFocusread
controlGetHandleread
controlGetPosread
controlGetTextread
controlHideread
controlMoveread
controlSendread
controlSetTextread
controlShowread
mouseClickread
mouseClickDragread
mouseDownread
mouseGetCursorread
mouseGetPosread
mouseMoveread
mouseUpread
mouseWheelread
optread
processCloseread
processExistsread
processSetPriorityread
processWaitread
processWaitCloseread
runwrite
runAsread
runAsWaitread
runWaitread
sendwrite
shutdownread
toolTipread
winActivateread
winActivateByHandleread
winActiveread
winCloseread
winExistsread
winGetHandleread
winGetPosread
winGetTextread
winGetTitleread
winMoveread
winSetStateread
winWaitread
winWaitActiveread
winWaitCloseread
04

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (1 observation(s))
Shell
declared (1 observation(s))
Dependencies
pinned
Secrets in source
none-found

Findings (3)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
scripts/package-acceptance.mjs:9
const npm=(args,options={})=>exec(process.execPath,[process.env.npm_execpath,...args],{...options,maxBuffer:10*1024*1024});
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:30
Then launch `mcp-windows-desktop-automation --transport=streamable-http --port=3000`. The endpoint is `http://127.0.0.1:3000/mcp`; `--host=ADDRESS` explicitly changes the loopback default. Authorizati
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
README.md:34
HTTP supports current Streamable HTTP and deliberate stateless legacy requests. Current clients must send the standard matching MCP protocol, method, and name headers. There is no historical SSE sessi
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha f6f17b1bdcc2full audit observations/trust-audit/mcp-server/mario-andreschak__windows-desktop-automation.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07f6f17b1bdcc2BLOCKD69first audit
06

Questions

What is the Windows Desktop Automation MCP server?

A Model Context Protocol (MCP) server for Windows desktop automation using AutoIt.

What tools does Windows Desktop Automation expose?

50 in total: 48 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Windows Desktop Automation safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.

What credentials does Windows Desktop Automation need?

It reads MCP_AUTH_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Windows Desktop Automation run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as mcp-windows-desktop-automation at 2.0.0.

How current is this page?

The grade is for one exact copy of the source (f6f17b1bdcc2), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement