Native DevtoolsCAUTION
MCP server for computer use & browser automation - screenshot, OCR, click, type, find_text, Chrome/Electron CDP, template matching. macOS, Windows & Android. Works with Claude, Cursor, and any MCP client.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
An MCP server for computer use on native desktop and mobile apps — macOS, Windows, Android, and Chrome/Electron via CDP.
Add to your client in one click:
[](cursor://anysphere.cursor-deeplink/mcp/install?name=native-devtools&config=eyJjb21tYW5kIjogIm5weCIsICJhcmdzIjogWyIteSIsICJuYXRpdmUtZGV2dG9vbHMtbWNwIl19) [](https://insiders.vscode.dev/redirect/mcp/install?name=native-devtools&config=%7B%22name%22%3A%20%22native-devtools%22%2C%20%22command%22%3A%20%22npx%22%2C%20%22args%22%3A%20%5B%22-y%22%2C%20%22native-devtools-mcp%22%5D%7D)
Claude Code: claude mcp add native-devtools -- npx -y native-devtools-mcp
native-devtools-mcp gives AI agents and MCP clients direct control over native desktop apps, Chrome/Electron browsers, and Android devices — screenshots, OCR, accessibility-first element lookup, input simulation, window management, Chrome DevTools Protocol (CDP), and ADB — all in one local server. Works with Claude Desktop, Claude Code, Cursor, and other MCP-compatible clients.
Quickstart
npx -y native-devtools-mcp
macOS Windows
3c0d3d2b9762OBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add native-devtools-mcp -- npx -y [email protected]
Trust audit
CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (2 observation(s))
- Network
- declared (5 observation(s))
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (12)
Path::new("/usr/local/bin/native-devtools-mcp"),classify("/usr/local/bin/native-devtools-mcp"),let url = format!("http://127.0.0.1:{}", port);tar -czvf ../../../native-devtools-mcp-${{ matrix.target }}.tar.gz native-devtools-mcpCompress-Archive -Path native-devtools-mcp.exe -DestinationPath ../../../native-devtools-mcp-${{ matrix.target }}.ziplet url = format!("http://127.0.0.1:{port}/json/version");sudo mv mcp-publisher /usr/local/bin/
demo.gif
windows-demo-1.gif
curl -fsSL https://raw.githubusercontent.com/vectora-foundry/native-devtools-mcp/master/scripts/build-from-source.sh | bash
curl -fsSL https://raw.githubusercontent.com/vectora-foundry/native-devtools-mcp/master/scripts/build-from-source.sh | bash
Gates applied: no_behavioural_pass.
3c0d3d2b9762full audit observations/trust-audit/mcp-server/sh3ll3x3c__native-devtools.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 3c0d3d2b9762 | CAUTION | B | 89 | first audit |
Questions
What is the Native Devtools MCP server?
MCP server for computer use & browser automation - screenshot, OCR, click, type, find_text, Chrome/Electron CDP, template matching. macOS, Windows & Android. Works with Claude, Cursor, and any MCP client.
Is Native Devtools safe to connect to an agent?
With care. The audit graded it B (89/100) and found 12 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does Native Devtools need?
No credential environment variables were found in its source, so it appears to need none.
How does Native Devtools run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as @sh3ll3x3c/native-devtools-mcp-win32-x64 at 0.10.1.
How current is this page?
The grade is for one exact copy of the source (3c0d3d2b9762), read on 2026-10-07. The repository is watched and re-audited when it changes.