Atlas / MCP servers / steipete / Peekaboo

PeekabooBLOCK

mcp/steipete/peekaboo

Peekaboo is a macOS CLI & optional MCP server that enables AI agents to capture screenshots of applications, or the entire system, with optional visual question answering through local or remote AI models.

Verdict
BLOCK
Grade
F
Trust score
55 /100
Exposed tools
1 1r · 0w · 0d
Transport
—
License
MIT
Stars
5,194
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://github.com/openclaw/Peekaboo/actions/workflows/macos-ci.yml) [](https://www.npmjs.com/package/@steipete/peekaboo) [](https://github.com/openclaw/Peekaboo/releases/latest) [](docs/platform-support.md) [](https://swift.org/) [](https://nodejs.org/) [](LICENSE) [](https://github.com/openclaw/homebrew-tap) [](https://deepwiki.com/openclaw/Peekaboo)

Peekaboo is a macOS CLI and menu-bar app for screen capture, accessibility inspection, and native UI automation. Use it directly, let its agent plan multi-step work, or expose the same toolset to MCP clients.

Install

The released CLI and app require macOS 15 or later.

CLI with Homebrew

brew install openclaw/tap/peekaboo

MCP package with npm

The npm package requires Node.js 22 or later and includes the CLI plus its MCP launcher.

npx -y @steipete/peekaboo --version

See MCP setup to connect it to Codex, Claude Code, Cursor, or another MCP client.

Mac app

Download the signed DMG from the

Read from source at commit 8eb7fd4bade9OBSERVED · 2026-09-22
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add peekaboo --env APP_STORE_CONNECT_API_KEY_P8=${APP_STORE_CONNECT_API_KEY_P8} --env CODESIGN_KEYCHAIN=${CODESIGN_KEYCHAIN} --env MAC_RELEASE_CODESIGN_KEYCHAIN=${MAC_RELEASE_CODESIGN_KEYCHAIN} -- npx -y @steipete/[email protected]
claude-desktop
{
  "mcpServers": {
    "peekaboo": {
      "command": "npx",
      "args": [
        "-y",
        "@steipete/[email protected]"
      ],
      "env": {
        "APP_STORE_CONNECT_API_KEY_P8": "${APP_STORE_CONNECT_API_KEY_P8}",
        "CODESIGN_KEYCHAIN": "${CODESIGN_KEYCHAIN}",
        "MAC_RELEASE_CODESIGN_KEYCHAIN": "${MAC_RELEASE_CODESIGN_KEYCHAIN}"
      }
    }
  }
}
03

Exposed tools (1)

1 read · 0 write · 0 destructive.

ToolRiskDescription
peekaboo_structured_fixturereadExercises the real pinned ToolHandler structured-content gate
04

Trust audit

BLOCKgrade F · trust 55/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryFAIL
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (7 observation(s))
Network
declared (3 observation(s))
Shell
declared (7 observation(s))
Dependencies
pinned
Secrets in source
found

Findings (25)

HIGHInventory / provenance · inv.suspicious_name · CWE-1104
scripts/terminal-dmg-payload.mjs
terminal-dmg-payload.mjs
Why it matters. member named after an attack tool
Fix. remove or justify
HIGHInventory / provenance · inv.suspicious_name · CWE-1104
scripts/test-terminal-dmg-payload.mjs
test-terminal-dmg-payload.mjs
Why it matters. member named after an attack tool
Fix. remove or justify
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
scripts/build-terminal-artifacts.sh:1046
'const value = new Function("return 6 * 7")(); if (value !== 42) process.exit(1);' || \
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
scripts/prepare-release.js:142
return exec(command, {
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
Apps/CLI/Sources/PeekabooCLI/Commands/MCP/BrowserCommand.swift:29
errorDescription: "Invalid --browser-url. Expected http://127.0.0.1:<port>, " +
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
Apps/CLI/Sources/PeekabooCLI/Commands/MCP/BrowserCommand.swift:31
envelopeHint: "Run `peekaboo browser connect --browser-url http://127.0.0.1:9222 --foreground`."
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
Core/PeekabooCore/Tests/PeekabooAgentRuntimeTests/AgentExecutionTraceTests.swift:219
let secret = "sk-testSECRET123456789"
LOWInventory / provenance · inv.binary · CWE-1104
Core/PeekabooCore/Tests/PeekabooTests/Resources/test_audio.wav
test_audio.wav
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInventory / provenance · inv.hidden_file · CWE-1104
.crabbox.yaml
.crabbox.yaml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.envrc
.envrc
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.gitmodules
.gitmodules
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.mac-release-terminal.env
.mac-release-terminal.env
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.mac-release.env
.mac-release.env
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
tests/fixtures/devtools-websocket.mjs:27
const accept = createHash('sha1')
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
.github/workflows/macos-ci.yml:314
python3 ../../scripts/test-see-config-environment.py
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
Apps/CLI/.swiftlint.yml:1
parent_config: ../../.swiftlint-rules.yml
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
scripts/build-cli-standalone.sh:35
python3 ../../scripts/setup-swift-workspace.py run -- swift build -c release 2>&1 | pipe_build_output
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
scripts/final-qualification/test/qualification-tools.test.mjs:42
import { aggregateSHA256 as multiTargetAggregateSHA256 } from '../../finalize-multi-target-certification.mjs';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
scripts/prepare-release.js:289
swiftBuildOutput = execSync('python3 scripts/setup-swift-workspace.py setup && cd Apps/CLI && swift package reset && python3 ../../scripts/setup-swift-workspace.py run --release -- swift build --arch 
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
Apps/CLI/Tests/CLIAutomationTests/AgentCommandValidationIntegrationTests.swift:557
let baseURL: String? = "http://127.0.0.1:9/v1"
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
Apps/CLI/Tests/CLIAutomationTests/AgentCommandValidationIntegrationTests.swift:608
let baseURL: String? = "http://127.0.0.1:9/v1"
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
Apps/CLI/Tests/CLIRuntimeTests/InvalidInputOrderingCLITests.swift:129
message: "Invalid --browser-url. Expected http://127.0.0.1:<port>, " +
LOWObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
tests/multi-target-certification.test.mjs:213
const text = 'e\u0301👨👩👧👦';
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
Apps/CLI/CHANGELOG.md:94
- Read `config credential set` secrets from no-echo prompts, stdin, or owner-only files; let `config provider add` also accept non-secret references; retain deprecated argv compatibility.
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
CHANGELOG.md:104
- Read `config credential set` secrets from no-echo prompts, stdin, or owner-only files; let `config provider add` also accept non-secret references; retain deprecated argv compatibility.
Why it matters. asks the agent to read credentials

Gates applied: no_behavioural_pass.

Audited 2026-09-22 · audit v0.4.1 · source sha 8eb7fd4bade9full audit observations/trust-audit/mcp-server/steipete__peekaboo.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-228eb7fd4bade9BLOCKF55source changed, verdict held
2026-09-18f60e4ca5f2fcBLOCKF55first audit
06

Questions

What is the Peekaboo MCP server?

Peekaboo is a macOS CLI & optional MCP server that enables AI agents to capture screenshots of applications, or the entire system, with optional visual question answering through local or remote AI models.

What tools does Peekaboo expose?

1 in total: 1 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Peekaboo safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (55/100) and found 4 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does Peekaboo need?

It reads APP_STORE_CONNECT_API_KEY_P8, CODESIGN_KEYCHAIN and MAC_RELEASE_CODESIGN_KEYCHAIN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How current is this page?

The grade is for one exact copy of the source (8eb7fd4bade9), read on 2026-09-22. The repository is watched and re-audited when it changes.

Advertisement