PeekabooBLOCK
Peekaboo is a macOS CLI & optional MCP server that enables AI agents to capture screenshots of applications, or the entire system, with optional visual question answering through local or remote AI models.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://github.com/openclaw/Peekaboo/actions/workflows/macos-ci.yml) [](https://www.npmjs.com/package/@steipete/peekaboo) [](https://github.com/openclaw/Peekaboo/releases/latest) [](docs/platform-support.md) [](https://swift.org/) [](https://nodejs.org/) [](LICENSE) [](https://github.com/openclaw/homebrew-tap) [](https://deepwiki.com/openclaw/Peekaboo)
Peekaboo is a macOS CLI and menu-bar app for screen capture, accessibility inspection, and native UI automation. Use it directly, let its agent plan multi-step work, or expose the same toolset to MCP clients.
Install
The released CLI and app require macOS 15 or later.
CLI with Homebrew
brew install openclaw/tap/peekaboo
MCP package with npm
The npm package requires Node.js 22 or later and includes the CLI plus its MCP launcher.
npx -y @steipete/peekaboo --version
See MCP setup to connect it to Codex, Claude Code, Cursor, or another MCP client.
Mac app
Download the signed DMG from the
8eb7fd4bade9OBSERVED · 2026-09-22Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add peekaboo --env APP_STORE_CONNECT_API_KEY_P8=${APP_STORE_CONNECT_API_KEY_P8} --env CODESIGN_KEYCHAIN=${CODESIGN_KEYCHAIN} --env MAC_RELEASE_CODESIGN_KEYCHAIN=${MAC_RELEASE_CODESIGN_KEYCHAIN} -- npx -y @steipete/[email protected]{
"mcpServers": {
"peekaboo": {
"command": "npx",
"args": [
"-y",
"@steipete/[email protected]"
],
"env": {
"APP_STORE_CONNECT_API_KEY_P8": "${APP_STORE_CONNECT_API_KEY_P8}",
"CODESIGN_KEYCHAIN": "${CODESIGN_KEYCHAIN}",
"MAC_RELEASE_CODESIGN_KEYCHAIN": "${MAC_RELEASE_CODESIGN_KEYCHAIN}"
}
}
}
}Exposed tools (1)
1 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
peekaboo_structured_fixture | read | Exercises the real pinned ToolHandler structured-content gate |
Trust audit
BLOCKgrade F · trust 55/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | FAIL |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (7 observation(s))
- Network
- declared (3 observation(s))
- Shell
- declared (7 observation(s))
- Dependencies
- pinned
- Secrets in source
- found
Findings (25)
terminal-dmg-payload.mjs
test-terminal-dmg-payload.mjs
'const value = new Function("return 6 * 7")(); if (value !== 42) process.exit(1);' || \return exec(command, {errorDescription: "Invalid --browser-url. Expected http://127.0.0.1:<port>, " +
envelopeHint: "Run `peekaboo browser connect --browser-url http://127.0.0.1:9222 --foreground`."
let secret = "sk-testSECRET123456789"
test_audio.wav
.crabbox.yaml
.envrc
.gitmodules
.mac-release-terminal.env
.mac-release.env
const accept = createHash('sha1')python3 ../../scripts/test-see-config-environment.py
parent_config: ../../.swiftlint-rules.yml
python3 ../../scripts/setup-swift-workspace.py run -- swift build -c release 2>&1 | pipe_build_output
import { aggregateSHA256 as multiTargetAggregateSHA256 } from '../../finalize-multi-target-certification.mjs';swiftBuildOutput = execSync('python3 scripts/setup-swift-workspace.py setup && cd Apps/CLI && swift package reset && python3 ../../scripts/setup-swift-workspace.py run --release -- swift build --arch let baseURL: String? = "http://127.0.0.1:9/v1"
let baseURL: String? = "http://127.0.0.1:9/v1"
message: "Invalid --browser-url. Expected http://127.0.0.1:<port>, " +
const text = 'e\u0301👨👩👧👦';
- Read `config credential set` secrets from no-echo prompts, stdin, or owner-only files; let `config provider add` also accept non-secret references; retain deprecated argv compatibility.
- Read `config credential set` secrets from no-echo prompts, stdin, or owner-only files; let `config provider add` also accept non-secret references; retain deprecated argv compatibility.
Gates applied: no_behavioural_pass.
8eb7fd4bade9full audit observations/trust-audit/mcp-server/steipete__peekaboo.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-22 | 8eb7fd4bade9 | BLOCK | F | 55 | source changed, verdict held |
| 2026-09-18 | f60e4ca5f2fc | BLOCK | F | 55 | first audit |
Questions
What is the Peekaboo MCP server?
Peekaboo is a macOS CLI & optional MCP server that enables AI agents to capture screenshots of applications, or the entire system, with optional visual question answering through local or remote AI models.
What tools does Peekaboo expose?
1 in total: 1 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Peekaboo safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (55/100) and found 4 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does Peekaboo need?
It reads APP_STORE_CONNECT_API_KEY_P8, CODESIGN_KEYCHAIN and MAC_RELEASE_CODESIGN_KEYCHAIN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How current is this page?
The grade is for one exact copy of the source (8eb7fd4bade9), read on 2026-09-22. The repository is watched and re-audited when it changes.