OmniSAFE
Labs: a perceive-plan-act computer-use experiment. Not the OpenAdapt product. The product is openadapt-flow: a compiled program that halts unless an independent check passes.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[!IMPORTANT] Labs, not the OpenAdapt product. This repository is a perceive-plan-act computer-use experiment. It is not how OpenAdapt records, compiles, or replays a workflow. The product is openadapt-flow: a compiled program that reportsVERIFIEDonly if an independent check agrees.pip install openadapt.
[](https://github.com/OpenAdaptAI/OmniMCP/actions/workflows/ci.yml) [](https://opensource.org/licenses/MIT) [](https://www.python.org/) [](https://github.com/astral-sh/ruff)
OmniMCP provides rich UI context and interaction capabilities to AI models through Model Context Protocol (MCP) and microsoft/OmniParser. It focuses on enabling deep understanding of user interfaces through visual analysis, structured planning, and precise interaction execution.
Core Features
- Visual Perception: Understands UI elements using OmniParser.
- LLM Planning: Plans next actions based on goal, history, and visual state.
- Agent Executor: Orchestrates the perceive-plan-act loop (
omnimcp/agent_executor.py). - Action Execution: Controls mouse/keyboard via
pynput(omnimcp/input.py). - CLI Interface: Simple entry point (
cli.py) for running tasks. - Auto-Deployment: Optional OmniParser server deployment to AWS EC2 with auto-shutdown.
- Debugging: Generates timestamped visual logs per step.
Overview
cli.py uses AgentExecutor to run a perceive-plan-act loop. It captures the screen (VisualState), plans using an LLM (
f309b87be37bOBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add omnimcp -- uvx omnimcp
{
"mcpServers": {
"omnimcp": {
"command": "uvx",
"args": [
"omnimcp"
]
}
}
}Exposed tools (7)
7 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
click_element | read | Click UI element matching description. Returns immediately after action attempt. |
describe_element | read | Get rich description of UI element (Basic implementation). |
find_elements | read | Find elements matching natural query (Basic implementation). |
get_screen_state | read | Get current state of visible UI elements. |
press_key | read | Press a key or key combination. Returns immediately after action attempt. |
scroll_view | read | Scroll view in the specified direction. Returns immediately after action attempt. |
type_text | read |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (2 observation(s))
- Network
- declared (7 observation(s))
- Shell
- declared (1 observation(s))
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (3)
images/omnimcp_demo.gif
paper/omnimcp_whitepaper.pdf
Gates applied: no_behavioural_pass, no_license.
f309b87be37bfull audit observations/trust-audit/mcp-server/openadaptai__omni.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | f309b87be37b | SAFE | B | 89 | first audit |
Questions
What is the Omni MCP server?
Labs: a perceive-plan-act computer-use experiment. Not the OpenAdapt product. The product is openadapt-flow: a compiled program that halts unless an independent check passes.
What tools does Omni expose?
7 in total: 7 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Omni safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Omni need?
No credential environment variables were found in its source, so it appears to need none.
How current is this page?
The grade is for one exact copy of the source (f309b87be37b), read on 2026-10-07. The repository is watched and re-audited when it changes.