Cancellation — tool calls honor the MCP host AbortSignal: wait returns early and run_script kills its child process when the host cancels.
computer-use-mcp
Computer Use MCP is an open source high performance MCP server + client for controlling your desktop computer with AI Agents. Tools include screenshot, mouse, keyboard, clipboard, app management, and window-level…
What it gives an agent
A purpose-built capability behind one MCP connection.
The server owns its domain logic and publishes a tool contract an MCP client can discover. ADK-Rust can load that contract into an agent, normalize each schema for the chosen model provider, and keep the connection lifecycle outside the agent’s business logic.
Progress notifications — long filesystem searches emit notifications/progress when the request carries a progress token (silent otherwise).
Filesystem jail — COMPUTER_USE_FS_ROOTS confines the filesystem tool to allowlisted roots, blocking .. traversal and symlink escapes.
Native binary resolver + packaging — COMPUTER_USE_NATIVE_PATH override → optional per-platform package → bundled binary; installs never fail on the native layer.
MCP modernization — tool annotations, structuredContent + outputSchema, server instructions, prompts, resources, and init-time tool profiles (COMPUTER_USE_PROFILE).
Deprecation — the [focusRequired: X] description suffix is off by default (focusRequired remains in _meta / get_tool_metadata); restore it with COMPUTER_USE_LEGACY_FOCUS_TAG=true.
Architecture
How computer-use-mcp fits into an agent system.
The model never needs the implementation details or credentials of the system behind the server. It sees reviewed tool definitions. The MCP client handles discovery and calls, while the server keeps ownership of validation, policy, and communication with its domain system.
ADK-Rust agent
Chooses a capability from the reviewed tool catalog.
MCP client
Discovers schemas, sends calls, and receives typed content.
computer-use-mcp
Validates the request and owns 64 documented tool contracts.
Domain system
Keeps the API, data, credentials, and business rules behind the server.
This repository does not currently publish a dedicated architecture SVG. The integration diagram above is generated from its documented transport and server boundary; use the official README for implementation-specific details.
Tool catalog
What can an agent ask computer-use-mcp to do?
Each tool has a stable name, a human-readable purpose, and a JSON input contract discovered during MCP initialization. Risk classes come from the project’s registry manifest when one is available.
The README documents 64 tools as grouped capabilities.
Open the official API reference or README below for the authoritative tool names and input schemas.
Governance
Understand the effect of every tool.
A server connection inherits the authority of its credentials and deployment environment. The declarations below come from this project’s README and MCP registry manifest; your application still decides which tools an agent receives and where approval is required.
- See everything on your screen
- Type into any application
- Click anything
- Read and write your clipboard
- Open, hide, and manage any application
- Input validation at two layers: Zod schemas at the MCP boundary, plus runtime guards in the session layer. Malformed inputs return errors rather than crashing.
MCP surface
What the current documentation declares.
MCP can carry tools, resources, prompts, structured results, progress, cancellation, and long-running work. This record highlights the modern protocol features explicitly mentioned by this repository.
Install and connect
Follow the project’s documented starting point.
Install the server in the environment that owns its credentials and domain access. Add it to your MCP host, verify the discovered tools, and narrow the toolset before giving it to a production agent.
npx --yes --prefer-offline @zavora-ai/computer-use-mcp{
"mcpServers": {
"computer-use": {
"command": "npx",
"args": ["--yes", "--prefer-offline", "@zavora-ai/computer-use-mcp"]
}
}
}Commands and configuration are extracted from the public README. Confirm prerequisites, environment variables, and release-specific options in the official documentation before deployment.
Official documentation
Continue with the project maintainers’ source of truth.
This page provides an approachable map of the server. The repository remains authoritative for exact schemas, prerequisites, configuration, examples, tests, releases, and security updates.
Keep exploring
More in developer tools.
Source record
Release and repository metadata for this catalog entry.
- Version
- Source release
- License
- See LICENSE
- Tools
- 64
- Revision
- e199e4188159
- Updated
- Jul 10, 2026