Windows Desktop AutomationBLOCK
A Model Context Protocol (MCP) server for Windows desktop automation using AutoIt.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
A trusted-owner MCP server for an interactive Windows x64 desktop. Version 2 retains the original 50 AutoIt tools and seven prompts, adds actual PNG screenshots, and supports MCP 2026-07-28 through SDK 2.0.0. Explicit compatibility serves legacy 2025-11-25 clients.
Run
Requires Node.js 22 or newer. Install this repository or its reviewed release artifact, then run the installed command:
npm ci npm run build node dist/index.js --transport=stdio # After installing the package: mcp-windows-desktop-automation --transport=stdio
Stdio stdout contains only MCP JSON messages. Diagnostics, including verbose operation names, go to stderr without argument values. Closing stdin closes the server and its native helper.
Native operations require Windows x64 and the logged-in user's interactive desktop. Enumeration and protocol handling also run on Linux, where native calls return an explicit platform error. ARM64, services in session 0, headless Windows sessions, other users' sessions, and elevated windows beyond the server's privileges are not supported. No provider account or model is involved.
Transports and ownership
Stdio is the default. For HTTP, set:
MCP_AUTH_TOKEN: a random owner bearer token of at least 32 characters.MCP_FILE_ROOTS: a JSON array of existing local directories, for example["C:\\Users\\me\\Documents"].- Optional
MCP_ALLOWED_HOSTS: comma-separated exact Host values, including port when used. - Optional
MCP_ALLOWED_ORIGINS: comma-separated exact origins.
Then launch mcp-windows-desktop-automation --transport=streamable-http --port=3000. The endpoint is http://127.0.0.1:3000/mcp; --host=ADDRESS explicitly changes the loopback default. Authorization is required for every endpoint request. Host and Origin are checked exactly; forwarded headers are not trusted, and permissive CORS is not enabled. Use a trusted TLS reverse proxy for remote deployment.
This is one owner per process,
f6f17b1bdcc2OBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add mcp-windows-desktop-automation --env MCP_AUTH_TOKEN=${MCP_AUTH_TOKEN} -- npx -y [email protected]{
"mcpServers": {
"mcp-windows-desktop-automation": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"MCP_AUTH_TOKEN": "${MCP_AUTH_TOKEN}"
}
}
}
}Exposed tools (50)
48 read · 2 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
autoItSetOption | read | |
clipGet | read | |
clipPut | read | |
controlClick | read | |
controlClickByHandle | read | |
controlCommand | read | |
controlFocus | read | |
controlGetHandle | read | |
controlGetPos | read | |
controlGetText | read | |
controlHide | read | |
controlMove | read | |
controlSend | read | |
controlSetText | read | |
controlShow | read | |
mouseClick | read | |
mouseClickDrag | read | |
mouseDown | read | |
mouseGetCursor | read | |
mouseGetPos | read | |
mouseMove | read | |
mouseUp | read | |
mouseWheel | read | |
opt | read | |
processClose | read | |
processExists | read | |
processSetPriority | read | |
processWait | read | |
processWaitClose | read | |
run | write | |
runAs | read | |
runAsWait | read | |
runWait | read | |
send | write | |
shutdown | read | |
toolTip | read | |
winActivate | read | |
winActivateByHandle | read | |
winActive | read | |
winClose | read | |
winExists | read | |
winGetHandle | read | |
winGetPos | read | |
winGetText | read | |
winGetTitle | read | |
winMove | read | |
winSetState | read | |
winWait | read | |
winWaitActive | read | |
winWaitClose | read |
Trust audit
BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (1 observation(s))
- Shell
- declared (1 observation(s))
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (3)
const npm=(args,options={})=>exec(process.execPath,[process.env.npm_execpath,...args],{...options,maxBuffer:10*1024*1024});Then launch `mcp-windows-desktop-automation --transport=streamable-http --port=3000`. The endpoint is `http://127.0.0.1:3000/mcp`; `--host=ADDRESS` explicitly changes the loopback default. Authorizati
HTTP supports current Streamable HTTP and deliberate stateless legacy requests. Current clients must send the standard matching MCP protocol, method, and name headers. There is no historical SSE sessi
Gates applied: no_behavioural_pass.
f6f17b1bdcc2full audit observations/trust-audit/mcp-server/mario-andreschak__windows-desktop-automation.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | f6f17b1bdcc2 | BLOCK | D | 69 | first audit |
Questions
What is the Windows Desktop Automation MCP server?
A Model Context Protocol (MCP) server for Windows desktop automation using AutoIt.
What tools does Windows Desktop Automation expose?
50 in total: 48 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Windows Desktop Automation safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.
What credentials does Windows Desktop Automation need?
It reads MCP_AUTH_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Windows Desktop Automation run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as mcp-windows-desktop-automation at 2.0.0.
How current is this page?
The grade is for one exact copy of the source (f6f17b1bdcc2), read on 2026-10-07. The repository is watched and re-audited when it changes.