go-mcp-computer-use

MCP server for Windows desktop computer use

Download as .zip Download as .tar.gz View on GitHub

Security

⚠️ DANGEROUS CAPABILITIES

This executable can fully control the Windows machine it runs on. It exposes these capabilities to any connected AI agent:

Treat this binary with the same caution as a remote-admin tool. Only connect it to MCP clients you trust. The AI agent receiving these tools has equivalent access to a logged-in user at the keyboard. Do not expose it over a network without authentication, and never run it on a machine where you wouldn’t let a remote user operate the mouse and keyboard.

Elevation & UIPI (Admin vs Non-Admin)

Windows UIPI (User Interface Privilege Isolation) silently blocks input from non-elevated processes targeting elevated (Administrator) windows.

If you run an app as Administrator (game installers, system tools, some games like HTGame.exe): → You must also run mcp-server.exe as Administrator for mouse clicks and keyboard input to reach it.

Without elevation:

To run elevated: right-click your terminal/launcher → “Run as Administrator” → start mcp-server.exe. Or set your MCP client config to launch it through an admin shell.

The good news: this is a Windows security feature, not a bug. Normal (non-admin) applications work fine without elevation — browsers, terminals, editors, chat apps, file explorers, most games. You only need admin mode when targeting admin windows.

Data Collection & Privacy Controls

The server has no telemetry, no network calls, no data exfiltration. All collected data stays in %APPDATA%/go-mcp-computer-use/training/. But users have full runtime control:

Goal How
Stop all screenshot saving set_config with training_enabled: false — disables auto-saves from actions AND the background watcher instantly
Re-enable data collection set_config with training_enabled: true
Stop the background watcher set_config with watcher_enabled: false — or onnx_watch_stop
Start the background watcher set_config with watcher_enabled: true — uses interval from config or watcher_interval_seconds
Change watcher frequency set_config with watcher_interval_seconds: 10 — restarts watcher with new interval if running
Disable ML prior learning set_config with prior_adjustment: false
Hide dangerous tools from AI set_config with tool_denylist: ["shutdown", "restart", "hibernate"] — removes tools entirely so the AI never sees them
Auto-prune old training data set_config with retention_days: 30 — background pruner runs every 6 hours, deletes samples older than N days
Delete noise samples training_cleanup_noise with max_age_hours: 0 — purges low-quality frames
Clear cached element data memory_forget with scope: ui — removes cached ONNX detection positions
Inspect collected data training_stats — see counts, sources, disk usage
Export collected data export_yolo_dataset — dump all images + labels to a directory
Persistent disable Set "training_enabled": false in ~/.config/go-mcp-computer-use/config.json

The set_config tool can be called by the AI agent or directly by the user via their MCP client. All changes persist to disk and survive server restarts.

For maximum privacy: set training_enabled: false in config before starting the server.

Transformer Model Privacy

The Go-native transformer engine (ml/ module) trains from your local training_pairs table only. No data leaves the machine.

Concern Control
Model file model.gob in data directory — local only, never transmitted
Training data Reads from local SQLite training_pairs table
No network calls Gorgonia trains entirely in-process, no external APIs
Disable training Set training_enabled: false — stops collecting new training pairs
Delete model Delete model.gob to reset learned behavior
ONNX vs Transformer ONNX models are pre-trained (downloaded). Transformer is trained from YOUR data. Both stay local.

Agent Configuration

{
  "mcpServers": {
    "computer-use": {
      "command": "C:\\tools\\mcp-server.exe",
      "env": {
        "ASSUME_NO_MOVING_GC_UNSAFE_RISK_IT_WITH": "go1.26"
      }
    }
  }
}

The env field sets ASSUME_NO_MOVING_GC_UNSAFE_RISK_IT_WITH=go1.26 for the Gorgonia transformer engine (required on Go 1.26+). See reference/mcp-client-configs.md for per-agent config examples.