go-mcp-computer-use

MCP server for Windows desktop computer use

Download as .zip Download as .tar.gz View on GitHub

go-mcp-computer-use — Plan & Progress

Goal

A closed-loop embodied agent for Windows — an MCP server in Go that exposes desktop computer use tools (screenshot, mouse, keyboard, window management, OCR, ONNX ML detection, Go-native transformer engine, memory store, data logging, adaptive engine) to AI agents via the Model Context Protocol. The system implements perception, action prediction, memory, and self-improvement layers, trending toward a locally-hosted autonomous desktop agent.

Architecture Layers

User Goal
     │
     ▼
Strategic Planner (LLM in AI client)
     │
     ▼
Skill Library (Macros) — NEXT SLICE
     │
     ├── Install Software
     ├── Configure Settings
     ├── Edit Document
     ├── Browse Website
     └── ...
     │
     ▼
Action Executor (MCP Server)
     │
      ├── Mouse • Keyboard • Vision (OCR/ONNX/UIA)
      ├── Window Management • Browser • Explorer
      ├── Chain Tool — sequential step execution
      ├── Keylogger — input recording/replay
      └── Transformer Engine — Go-native action prediction (14K params, self-improving)
     │
     ▼
Verification & Feedback (OCR, ONNX, UIA)
     │
     ▼
Memory & Learning
      ├── Data Logging (commands, OCR, chains, training pairs)
      ├── Adaptive Engine (timing stats, success rates, sequence predictions)
      ├── Go-Native Transformer (Gorgonia 14K-param model, OCR→action prediction, `model.gob`)
      ├── SQLite Memory Store (facts, sequences, templates)
      └── Training Data Pipeline (screenshot + label export)
     │
     ▼
Post-Task Introspection — NEXT SLICE
     ├── What worked? What slowed me down?
     ├── Which macro was reused? Which element took too long?
     └── Generalize into reusable skills

Personal Security System

Five-layer defense for protecting user data during AI-driven automation:

Layer 1: Identity Awareness (who am I, what can I do)

Layer 2: Input Sanitization (what gets captured)

Layer 3: Source Filtering (what gets captured from where)

Layer 4: Storage Security (what happens after capture)

Layer 5: Retention & Cleanup (data lifecycle)

Data flow

Screenshot taken
  → [L3] App/URL exclusion check → skip if excluded
  → [L2] OCR text extracted → PII regex scan → redact matches
  → [L2] Screenshot region masking → blank detected areas
  → [L4] Encrypt before write to disk
  → Training DB + image file saved

What’s done vs. what’s next

| Layer | Feature | Status | |——-|———|——–| | L1 | tool_denylist | ✅ v0.2.37 | | L5 | retention_days | ✅ v0.2.37 | | L5 | training_cleanup_noise | ✅ manual | | L1 | is_admin / get_username / list_tools | NEXT — P0 | | L2 | set_sensitive_content_filter (PII regex) | NEXT — P1 | | L3 | App/URL exclusion list | NEXT — P2 | | L3 | Private browsing detection | NEXT — P3 | | L4 | Encryption at rest | FAR — P4 | | L4 | Audit log | FAR — P5 |

Design Principles

Current State: v0.2.56 — Verified Window Focus + DPI Awareness

All tools registered in internal/server/server.go, auto-documented in docs/reference/tools.md. Adaptive engine now includes timing stats, success rates, coordinate prediction, and full OCR-bridge training pair coverage across all 11 action tools.

Chain system integrated with UIA: mouse steps auto-capture element_at_point, verify_ui and if_uia step types use UIA instead of OCR for structural verification and branching.

Focus reliability hardened: FocusWindow now uses a 4-attempt fallback chain with post-call verification via GetForegroundWindow. Chain steps accept focus_handle (direct handle, no title re-resolve) and support auto_verify_focus to re-check foreground before input tools. Desktop awareness layer extended with DPI-per-point lookup:

See docs/reference/tools.md for the full categorized tool listing and backlog.md for the roadmap.

Completed Work

v0.2.16 — Adaptive Engine + Data Logging

v0.2.17 — Bridge Window Fix

v0.2.20 — OCR Bridge Auto-Complete

v0.2.21 — Full Action Coverage

v0.2.22 — Real Timing Stats

v0.2.23–24 — Coordinate Prediction

v0.2.25 — Case-Insensitive Coordinate Match

v0.2.28 — Action Verification System

v0.2.38 — Desktop Awareness + Chain Integration

v0.2.27 — ONNX + OCR Fallback for Template Matching


Next Up — Prioritized

1. Post-Task Introspection Engine (COMPLETED — v0.2.18)

Extend the adaptive engine from passive stats → active self-improvement. After every task, log:

Implementation sketch:

internal/actions/introspection.go
├── TaskLogger    — record task start/end, steps, outcomes
├── SkillMiner    — analyze logs for reusable sequences
├── Suggestions   — surface improvement opportunities
└── MCP tools     — introspection_analyze, introspection_suggest

2. Keylogger Rewrite (COMPLETED — v0.2.19)

Replaced WH_MOUSE_LL + WH_KEYBOARD_LL hooks with GetAsyncKeyState polling loop (50ms ticker). Eliminates system-wide input lag. Polling runs in a goroutine — no locked OS thread, no Windows message loop.

3. Test Validation of Recent Fixes (HIGH)

The v0.2.33 changes introduced several correctness-sensitive behaviors that need unit test coverage:

Test files: internal/actions/adaptive_test.go, internal/actions/datalog_test.go (unit tests, no build tag; integration tests via //go:build integration).

4. Chain Interruption (MEDIUM)

Ability to stop mid-chain on error/state change — on_error: "stop" already exists, needs interrupt signaling.

4. Cross-platform Interface (LOW)

5. Skill Library (v0.3.0 — ML Setup Endgame)


Versioning

See docs/reference/versioning-strategy.md for the full versioning scheme, bump rules, tagging policy, and release process.


Competitive Intelligence — Features Worth Stealing

High-impact features from competing projects that fill gaps in go-mcp-computer-use, ordered by effort:

Quick Wins (low effort, high value)

Steal From Feature What It Does Where to Implement
Windows-MCP Per-tool enable/disable Config map allow/deny list per MCP tool server.go — filter registration — done v0.2.37 (tool_denylist config + server.RemoveTools)
Recall Retention policy Auto-prune training samples older than N days training/cleanup.go — done v0.2.37 (retention_days config + StartRetentionPruner)
Builtin Security tools is_admin, get_username, list_tools — identity & permission awareness internal/actions/system.go — Win32 API calls (GetTokenInformation, GetUserNameW)
Builtin Sensitive content filter Regex PII/password detection on OCR text before saving training samples internal/actions/training.go — filter hook in save pipeline

Medium Effort

Steal From Feature What It Does Where to Implement
Windows-MCP Bearer token + TLS Auth for TCP transport (needed before SSE) New transport/ package
Windows-MCP SSE transport Switchable from stdio so server can run standalone New transport/ + MCP SSE support
Windows-MCP Browser DOM mode CDP/Playwright integration for Chrome/Edge/Firefox DOM snapshots Start in actions/browseruse.go; extract to internal/browser/ if it outgrows a single file. Chrome/Edge use native CDP; Firefox via Playwright driver.
Agent-S In-context RL Track last-N action outcomes per session, surface as reflection context actions/introspection.go — session-scoped outcome buffer

High Effort (architectural)

Steal From Feature What It Does Where to Implement
Cua Background control SendInput/UIA instead of cursor-steal for clicks actions/click.go — new input backend
Cua VM sandboxing QEMU/Docker target instead of host OS New sandbox/ package
Recall Semantic indexing Vector embeddings for screenshot search New memory/vector/ package + embedding model
DesktopCtl GPU-accelerated OCR Swap WinRT OCR for GPU-backed ocr/ — new backend

Constraints

Key Decisions