Omniparser AutoguiSAFE
Automatic operation of on-screen GUI.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
(日本語版はこちら)
This is an MCP server that analyzes the screen with OmniParser and automatically operates the GUI. Confirmed on Windows.
License notes
This is MIT license, but Excluding submodules and sub packages. OmniParser's repository is CC-BY-4.0. Each OmniParser model has a different license (reference).
Installation
- Please do the following:
git clone --recursive https://github.com/NON906/omniparser-autogui-mcp.git cd omniparser-autogui-mcp uv sync set OCR_LANG=en uv run download_models.py
(Other than Windows, use `export instead of set.) (If you want langchain_example.py to work, uv sync --extra langchain` instead.)
- Add this to your `
claude_desktop_config.json`:
{
"mcpServers": {
"omniparser_autogui_mcp": {
"command": "uv",
"args": [
"--directory",
"D:\\CLONED_PATH\\omniparser-autogui-mcp",
"run",
"omniparser-autogui-mcp"
],
"env": {
"PYTHONIOENCODING": "utf-8",
"OCR_LANG": "en"
}
}
}
}(Replace `D:\\CLONED_PATH\\omniparser-autogui-mcp` with the directory you cloned.)
`env` allows for the following additional configurations:
- `
OMNI_PARSER_BACKEND_LOAD`
If it does not work with other clients (such as LibreChat), specify `1`.
- `
TARGET_WINDOW_NAME`
If you want to specify the window to operate, please specify the window name. If not specified, operates on the entire screen.
- `
OMNI_PARSER_SERVER`
If you want OmniParser processing to be done on another device, specify the server's address and port, such as `127.0.0.1:8000. The server can be started with uv run omniparserserver`.
- `
SSE_HOST,`SSE_POR
05f6f71b206dOBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add omniparser-autogui-mcp -- uvx omniparser-autogui-mcp
{
"mcpServers": {
"omniparser-autogui-mcp": {
"command": "uvx",
"args": [
"omniparser-autogui-mcp"
]
}
}
}Exposed tools (9)
6 read · 2 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
omniparser_click | read | Click on anything on the screen. |
omniparser_details_on_screen | read | Get the screen and analyze its details. |
omniparser_drags | destructive | Drag and drop on the screen. |
omniparser_get_keys_list | read | List of keyboard keys. Used in |
omniparser_input_key | read | Press of keyboard keys. |
omniparser_mouse_move | write | Moves the mouse cursor over the specified element. |
omniparser_scroll | read | The mouse scrolling wheel behavior. |
omniparser_wait | read | Waits for the specified number of seconds. |
omniparser_write | write | Type the characters in the string that is passed. |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (1 observation(s))
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (3)
omniparser_drags
.gitmodules
image_bytes = base64.b64decode(dino_labled_img)
Gates applied: no_behavioural_pass.
05f6f71b206dfull audit observations/trust-audit/mcp-server/non906__omniparser-autogui.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 05f6f71b206d | SAFE | B | 89 | first audit |
Questions
What is the Omniparser Autogui MCP server?
Automatic operation of on-screen GUI.
What tools does Omniparser Autogui expose?
9 in total: 6 read-only, 2 that write, and 1 that can delete or overwrite (omniparser_drags). Every one is listed on this page with its risk.
Is Omniparser Autogui safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Omniparser Autogui need?
No credential environment variables were found in its source, so it appears to need none.
How current is this page?
The grade is for one exact copy of the source (05f6f71b206d), read on 2026-10-07. The repository is watched and re-audited when it changes.