Atlas / MCP servers / non906 / Omniparser Autogui

Omniparser AutoguiSAFE

mcp/non906/omniparser-autogui

Automatic operation of on-screen GUI.

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
9 6r · 2w · 1d
Transport
—
License
MIT
Stars
72
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

(日本語版はこちら)

This is an MCP server that analyzes the screen with OmniParser and automatically operates the GUI. Confirmed on Windows.

License notes

This is MIT license, but Excluding submodules and sub packages. OmniParser's repository is CC-BY-4.0. Each OmniParser model has a different license (reference).

Installation

  1. Please do the following:
git clone --recursive https://github.com/NON906/omniparser-autogui-mcp.git
cd omniparser-autogui-mcp
uv sync
set OCR_LANG=en
uv run download_models.py

(Other than Windows, use `export instead of set.) (If you want langchain_example.py to work, uv sync --extra langchain` instead.)

  1. Add this to your `claude_desktop_config.json`:
{
"mcpServers": {
"omniparser_autogui_mcp": {
"command": "uv",
"args": [
"--directory",
"D:\\CLONED_PATH\\omniparser-autogui-mcp",
"run",
"omniparser-autogui-mcp"
],
"env": {
"PYTHONIOENCODING": "utf-8",
"OCR_LANG": "en"
}
}
}
}

(Replace `D:\\CLONED_PATH\\omniparser-autogui-mcp` with the directory you cloned.)

`env` allows for the following additional configurations:

  • `OMNI_PARSER_BACKEND_LOAD`

If it does not work with other clients (such as LibreChat), specify `1`.

  • `TARGET_WINDOW_NAME`

If you want to specify the window to operate, please specify the window name. If not specified, operates on the entire screen.

  • `OMNI_PARSER_SERVER`

If you want OmniParser processing to be done on another device, specify the server's address and port, such as `127.0.0.1:8000. The server can be started with uv run omniparserserver`.

  • `SSE_HOST, `SSE_POR
Read from source at commit 05f6f71b206dOBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add omniparser-autogui-mcp -- uvx omniparser-autogui-mcp
claude-desktop
{
  "mcpServers": {
    "omniparser-autogui-mcp": {
      "command": "uvx",
      "args": [
        "omniparser-autogui-mcp"
      ]
    }
  }
}
03

Exposed tools (9)

6 read · 2 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
omniparser_clickreadClick on anything on the screen.
omniparser_details_on_screenreadGet the screen and analyze its details.
omniparser_dragsdestructiveDrag and drop on the screen.
omniparser_get_keys_listreadList of keyboard keys. Used in
omniparser_input_keyreadPress of keyboard keys.
omniparser_mouse_movewriteMoves the mouse cursor over the specified element.
omniparser_scrollreadThe mouse scrolling wheel behavior.
omniparser_waitreadWaits for the specified number of seconds.
omniparser_writewriteType the characters in the string that is passed.
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (1 observation(s))
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (3)

MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
omniparser_drags
Why it matters. 1 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.gitmodules
.gitmodules
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
src/mcp_autogui/mcp_autogui_main.py:120
image_bytes = base64.b64decode(dino_labled_img)

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 05f6f71b206dfull audit observations/trust-audit/mcp-server/non906__omniparser-autogui.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0705f6f71b206dSAFEB89first audit
06

Questions

What is the Omniparser Autogui MCP server?

Automatic operation of on-screen GUI.

What tools does Omniparser Autogui expose?

9 in total: 6 read-only, 2 that write, and 1 that can delete or overwrite (omniparser_drags). Every one is listed on this page with its risk.

Is Omniparser Autogui safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Omniparser Autogui need?

No credential environment variables were found in its source, so it appears to need none.

How current is this page?

The grade is for one exact copy of the source (05f6f71b206d), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement