Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
23 commits
Select commit Hold shift + click to select a range
6bc27b7
docs(forside): ny forside - scenen bag dit vindue, loglinjer som bevi…
Oct 1, 2026
6a20932
docs(forside): kort udgave + 24 sekunders film af vaerktoejerne + Git…
Oct 2, 2026
fda2434
side: filmen til højre for teksten, og en menneskelig arbejdsgang
Oct 2, 2026
f09d008
side: use cases hvor intet API når frem, og en film der kun viser mål…
Oct 2, 2026
1db17e5
logo: laptop med en blå knap der trykkes, din markør foran og urørt
Oct 2, 2026
8715618
side: filmen viser nu alle fire use cases (32 s)
Oct 2, 2026
73c08d5
side: filmen viser de 19 brugsscenarier vi tester, med ærlig stilling
Oct 2, 2026
0ca5231
side: hvert kort i filmen ligner det rigtige program
Oct 2, 2026
30c41e9
side: skakbrættet rettet, 11 kort på 3 s, værktøjslinjen i billedteksten
Oct 2, 2026
9a7ee0a
side: mange side om side + lever på din Mac, mere ægte programmer, en…
Oct 2, 2026
ede577d
side: tavlen stram: 10 bevist, 5 delvist, 4 ikke testet
Oct 2, 2026
874fcc8
side: ret efter to uafhængige gennemlæsninger (7 bevist, 9 delvist, 3…
Oct 2, 2026
282d9ff
security: søgemaskine-verifikation ligger på siden, ikke i DNS
Oct 2, 2026
b9ea59c
side: stjernetallet sættes ind når siden bygges (slået fra indtil vid…
Oct 2, 2026
440df62
side: hero-videoen med i repoet (den globale gitignore spærrede *.mp4)
Oct 2, 2026
f2fa9c1
kanaler: README på GitHub/npm vises rigtigt, llms.txt siger sandt, ko…
Oct 2, 2026
8e54e4f
Merge release-grenen ind i forsiden (a46c6a3: sync-tal-rettelsen)
Oct 2, 2026
0f01355
Merge release-grenen (ac7da21) ind i forsiden igen
Oct 2, 2026
8363376
side: den tegnede film tilbage øverst, optagelsen ned som bevis
Oct 2, 2026
2fa43d5
side: stjernerne fra 1, ærlig optagelsestekst, lokal socket nævnt
Oct 2, 2026
fd20db8
side: «Made by Gustav Louv» fra PR #5 med på den nye forside
Oct 2, 2026
4441a36
side+README: ret de fund Opus-gennemgangen 3/10 fandt før live
Oct 3, 2026
6439c6d
claims 42b tæller programmer, ikke bundle-ID'er; npm-README afledt igen
Oct 3, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
50 changes: 50 additions & 0 deletions .github/workflows/side.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,50 @@
name: side

# Udgiver computermcp.dev fra docs/ og sætter GitHub-stjernerne ind, mens siden bygges
# (scripts/stjerner.py). Ingen script og intet tredjepartskald i browseren: tallet står
# i HTML'en. Det opdateres ved hvert skub til main og én gang i døgnet.
#
# SLÅET FRA indtil to ting er gjort, begge af en der ejer repoet:
# 1. Settings > Pages > Source = «GitHub Actions» (i dag: «Deploy from a branch», main /docs)
# 2. Repo-variablen SIDE_VIA_ACTIONS = true (Settings > Secrets and variables > Actions > Variables)
# Uden variablen springes jobbet over (ikke rødt), og den klassiske udgivelse kører som før.
# Tilbage: sæt variablen til false og Source tilbage til «Deploy from a branch».

on:
push:
branches: [main]
paths: ['docs/**', 'scripts/stjerner.py', '.github/workflows/side.yml']
schedule:
- cron: '17 5 * * *'
workflow_dispatch:

permissions:
contents: read
pages: write
id-token: write

concurrency:
group: pages
cancel-in-progress: false

jobs:
udgiv:
if: vars.SIDE_VIA_ACTIONS == 'true'
runs-on: ubuntu-latest
environment:
name: github-pages
url: ${{ steps.udgiv.outputs.page_url }}
steps:
- uses: actions/checkout@v4
- name: Stjernerne ind i siden
env:
GH_TOKEN: ${{ github.token }}
run: |
n=$(gh api "repos/${{ github.repository }}" --jq .stargazers_count)
python3 scripts/stjerner.py docs/index.html "$n"
- uses: actions/configure-pages@v5
- uses: actions/upload-pages-artifact@v3
with:
path: docs
- id: udgiv
uses: actions/deploy-pages@v4
1 change: 1 addition & 0 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -18,6 +18,7 @@ videos/*/.hyperframes/
# blev TAVST holdt uden for repoet - sitet ville faa en <video> uden fil, og
# lokalt saa alting rigtigt ud fordi filen laa paa disken.
!docs/demo.mp4
!docs/hero-10.mp4
.dialog-kvittering

# MCPB-bundle build-output (bygges on demand med scripts/build-mcpb.sh)
Expand Down
28 changes: 15 additions & 13 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,7 @@ A macOS computer-use MCP server built for the part everyone skips: what happens
in the hours you are not watching.

- **It runs in every MCP client, not one app.** Claude Code, Cursor, VS Code,
Codex, Windsurf, Zed, or your own agent - one `npx` line, the same server
Codex, or your own agent - one `npx` line, the same server
everywhere. It is not tied to a single vendor's desktop app or plan.
- **It does not take over your Mac.** It presses buttons and fills fields in
windows that stay behind the one you are in, and it leaves your pointer where
Expand All @@ -21,8 +21,8 @@ in the hours you are not watching.
- **Several can run at once.** No session lock, no one-at-a-time limit. Writes
to the shared log take a short file lock, so two servers cannot break the
chain between them.
- **It will not go near your passwords.** Keychain, 1Password and seven others
ask every time, in every mode, and password fields are blacked out while the
- **It will not go near your passwords.** Keychain, 1Password and five others
are refused in the default mode (with `CMCP_BACKGROUND=0` they ask every time), and password fields are blacked out while the
screenshot is still in memory. A screen recording leaves password managers
out, but does not black out password fields.
- **You can read back what it did.** Every call lands in an append-only log,
Expand Down Expand Up @@ -83,11 +83,12 @@ through - so both are checked.
**2. The dangerous places ask first.** By default the agent works without
interrupting you - that is what lets it run while you do something else - and
every write is logged. What never goes through on its own: password managers and
Keychain ask *every single time*, in every mode, and that one is not
configurable. Terminals and editors, where a keystroke can be a command, ask once
Keychain are refused in the default mode, because the menu bar cannot show what
would be typed (with `CMCP_BACKGROUND=0` they ask *every single time*, in every
mode), and that one is not configurable. Terminals and editors, where a keystroke can be a command, ask once
per app per session. Quitting an app, closing a window, switching Space,
destructive-looking menu items and any action whose target app cannot be
identified ask every time. The gate judges the app an action lands in: an
and destructive-looking menu items ask every time; an action whose target app
cannot be identified is refused in the default mode. The gate judges the app an action lands in: an
app opened some other way - Spotlight, a shortcut - is guarded by what the
agent then tries to do in it. Want a dialog before the first write too? Set
`CMCP_MODE=ask`. If nobody answers, the answer is no.
Expand Down Expand Up @@ -155,8 +156,8 @@ the client and check `computer_permissions` again.
| `CMCP_MODE` | Behaviour |
|---|---|
| `readonly` | Write tools are not even listed. The agent can look and cannot touch. |
| `ask` | The first write opens a dialog; one yes grants the session. Password managers still ask every time, terminals and editors once per session. |
| `allow` | **Default.** Writes proceed without asking, still logged. Password managers *still* ask every time, terminals and editors once per session, and in background mode anything that would need a dialog waits in the menu bar instead. |
| `ask` | The first write opens a dialog; one yes grants the session. Password managers are refused (with `CMCP_BACKGROUND=0` they ask every time), terminals and editors ask once per session. |
| `allow` | **Default.** Writes proceed without asking, still logged. Password managers are *still* refused (with `CMCP_BACKGROUND=0` they ask every time), terminals and editors ask once per session, and in background mode anything that would need a dialog waits in the menu bar instead. |

`CMCP_ASK_TIMEOUT` (seconds, default 60) controls how long a dialog waits before
it refuses.
Expand All @@ -167,8 +168,9 @@ it refuses.
default, and the agent uses them without asking - the same way a browser tool
drives a browser. Two gates survive that, and they are the two that matter:

- **Password managers ask every time.** Keychain, 1Password and seven others,
in every mode, even after you have said yes. That is the whole difference
- **Password managers are refused.** Keychain, 1Password and five others, in
every mode, even after you have said yes; with `CMCP_BACKGROUND=0` they ask
every time instead. That is the whole difference
between *you may work* and *you may have my passwords*.
- **Anything that deletes or clears asks every time**, recognised from the words
in the action itself.
Expand Down Expand Up @@ -282,9 +284,9 @@ Two or more matches is a refusal, not a guess - the agent gets the candidates
and has to narrow it down, because pressing the first plausible button is
exactly the kind of almost-right action nobody notices afterwards.

The consent dialog still comes to the front, and the apps on the always-ask list
The consent question still reaches you (in the menu bar by default), and the apps on the always-ask list
still ask every time. `computer_press` names its target app, and that name is
what the gate judges - so pressing something in 1Password asks even when
what the gate judges - so pressing something in 1Password is refused (with `CMCP_BACKGROUND=0`: asks) even when
1Password is nowhere near the front.

**Claude Code's auto mode and the screen tools.** Measured on 1 Oct: after the
Expand Down
Binary file modified docs/apple-touch-icon.png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
2 changes: 1 addition & 1 deletion docs/blog/driving-macos-from-an-ai-agent.html
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,7 @@
<link rel="icon" type="image/x-icon" href="/favicon.ico">
<link rel="apple-touch-icon" href="/apple-touch-icon.png">
<meta name="theme-color" content="#0d1117">
<meta name="description" content="Five things that decide whether an AI agent can reliably operate Mac apps: the accessibility tree over pixels, the full-screen Space trap, duplicate names in Electron apps, secure-field subroles, and why an error message that lies costs you a day.">
<meta name="description" content="Five things that decide whether an AI agent can operate Mac apps: the accessibility tree, full-screen Spaces, Electron duplicates and secure fields.">
<link rel="canonical" href="https://computermcp.dev/blog/driving-macos-from-an-ai-agent.html">
<meta property="og:url" content="https://computermcp.dev/blog/driving-macos-from-an-ai-agent.html">
<meta name="twitter:card" content="summary_large_image">
Expand Down
2 changes: 1 addition & 1 deletion docs/blog/screenshot-password-leak.html
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,7 @@
<link rel="icon" type="image/x-icon" href="/favicon.ico">
<link rel="apple-touch-icon" href="/apple-touch-icon.png">
<meta name="theme-color" content="#0d1117">
<meta name="description" content="Every screenshot an AI agent takes of your Mac can contain a password field mid-type, a vault mid-unlock, or a token in a terminal. Here is what actually leaks, why the usual fixes do not work, and how to close it.">
<meta name="description" content="A screenshot an AI agent takes of your Mac can hold a password mid-type or a terminal token. What leaks, why the usual fixes fail, and how to close it.">
<link rel="canonical" href="https://computermcp.dev/blog/screenshot-password-leak.html">
<meta property="og:url" content="https://computermcp.dev/blog/screenshot-password-leak.html">
<meta name="twitter:card" content="summary_large_image">
Expand Down
2 changes: 1 addition & 1 deletion docs/docs/capability-matrix/index.html
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,7 @@
<link rel="icon" type="image/x-icon" href="/favicon.ico">
<link rel="apple-touch-icon" href="/apple-touch-icon.png">
<meta name="theme-color" content="#0d1117">
<meta name="description" content="Every wall an agent hits on macOS, and which side of it we are on: measured, by design, not yet, or we will not cross it. thirty-two tools, and an honest list of what they cannot reach.">
<meta name="description" content="Every wall an agent hits on macOS, and which side of it we are on: measured, by design, not yet, or never. An honest list of what the tools cannot reach.">
<link rel="canonical" href="https://computermcp.dev/docs/capability-matrix/">
<meta property="og:type" content="article">
<meta property="og:url" content="https://computermcp.dev/docs/capability-matrix/">
Expand Down
4 changes: 2 additions & 2 deletions docs/docs/install-claude-code/index.html
Original file line number Diff line number Diff line change
Expand Up @@ -8,11 +8,11 @@
<link rel="icon" type="image/x-icon" href="/favicon.ico">
<link rel="apple-touch-icon" href="/apple-touch-icon.png">
<meta name="theme-color" content="#0d1117">
<meta name="description" content="Three steps, about two minutes. Claude Code drives your real Mac with password fields blacked out before any screenshot is written, and it works without asking - except password managers and anything that deletes.">
<meta name="description" content="Three steps, about two minutes: Claude Code can use your Mac in the windows behind yours, with password fields blacked out before any screenshot exists.">
<link rel="canonical" href="https://computermcp.dev/docs/install-claude-code/">
<meta property="og:type" content="article">
<meta property="og:title" content="Install Computer MCP for Claude Code">
<meta property="og:description" content="Three steps, about two minutes. Claude Code drives your real Mac with password fields blacked out before any screenshot is written, and it works without asking - except password managers and anything that deletes.">
<meta property="og:description" content="Three steps, about two minutes: Claude Code can use your Mac in the windows behind yours, with password fields blacked out before any screenshot exists.">
<meta property="og:url" content="https://computermcp.dev/docs/install-claude-code/">
<meta property="og:image" content="https://computermcp.dev/og-image.jpg">
<meta name="twitter:card" content="summary_large_image">
Expand Down
4 changes: 2 additions & 2 deletions docs/docs/install-claude-desktop/index.html
Original file line number Diff line number Diff line change
Expand Up @@ -8,11 +8,11 @@
<link rel="icon" type="image/x-icon" href="/favicon.ico">
<link rel="apple-touch-icon" href="/apple-touch-icon.png">
<meta name="theme-color" content="#0d1117">
<meta name="description" content="Three steps, about two minutes. Claude Desktop drives your real Mac with password fields blacked out before any screenshot is written, and it works without asking - except password managers and anything that deletes.">
<meta name="description" content="Three steps, about two minutes: Claude Desktop can use your Mac in the windows behind yours, with password fields blacked out before any screenshot exists.">
<link rel="canonical" href="https://computermcp.dev/docs/install-claude-desktop/">
<meta property="og:type" content="article">
<meta property="og:title" content="Install Computer MCP for Claude Desktop">
<meta property="og:description" content="Three steps, about two minutes. Claude Desktop drives your real Mac with password fields blacked out before any screenshot is written, and it works without asking - except password managers and anything that deletes.">
<meta property="og:description" content="Three steps, about two minutes: Claude Desktop can use your Mac in the windows behind yours, with password fields blacked out before any screenshot exists.">
<meta property="og:url" content="https://computermcp.dev/docs/install-claude-desktop/">
<meta property="og:image" content="https://computermcp.dev/og-image.jpg">
<meta name="twitter:card" content="summary_large_image">
Expand Down
4 changes: 2 additions & 2 deletions docs/docs/install-codex/index.html
Original file line number Diff line number Diff line change
Expand Up @@ -8,11 +8,11 @@
<link rel="icon" type="image/x-icon" href="/favicon.ico">
<link rel="apple-touch-icon" href="/apple-touch-icon.png">
<meta name="theme-color" content="#0d1117">
<meta name="description" content="Three steps, about two minutes. Codex drives your real Mac with password fields blacked out before any screenshot is written, and it works without asking - except password managers and anything that deletes.">
<meta name="description" content="Three steps, about two minutes: Codex can use your Mac in the windows behind yours, with password fields blacked out before any screenshot exists.">
<link rel="canonical" href="https://computermcp.dev/docs/install-codex/">
<meta property="og:type" content="article">
<meta property="og:title" content="Install Computer MCP for OpenAI Codex">
<meta property="og:description" content="Three steps, about two minutes. Codex drives your real Mac with password fields blacked out before any screenshot is written, and it works without asking - except password managers and anything that deletes.">
<meta property="og:description" content="Three steps, about two minutes: Codex can use your Mac in the windows behind yours, with password fields blacked out before any screenshot exists.">
<meta property="og:url" content="https://computermcp.dev/docs/install-codex/">
<meta property="og:image" content="https://computermcp.dev/og-image.jpg">
<meta name="twitter:card" content="summary_large_image">
Expand Down
4 changes: 2 additions & 2 deletions docs/docs/install-copilot/index.html
Original file line number Diff line number Diff line change
Expand Up @@ -8,11 +8,11 @@
<link rel="icon" type="image/x-icon" href="/favicon.ico">
<link rel="apple-touch-icon" href="/apple-touch-icon.png">
<meta name="theme-color" content="#0d1117">
<meta name="description" content="Three steps, about two minutes. Copilot in VS Code drives your real Mac with password fields blacked out before any screenshot is written, and it works without asking - except password managers and anything that deletes.">
<meta name="description" content="Three steps, about two minutes: Copilot in VS Code can use your Mac in the windows behind yours, with password fields blacked out first.">
<link rel="canonical" href="https://computermcp.dev/docs/install-copilot/">
<meta property="og:type" content="article">
<meta property="og:title" content="Install Computer MCP for GitHub Copilot">
<meta property="og:description" content="Three steps, about two minutes. Copilot in VS Code drives your real Mac with password fields blacked out before any screenshot is written, and it works without asking - except password managers and anything that deletes.">
<meta property="og:description" content="Three steps, about two minutes: Copilot in VS Code can use your Mac in the windows behind yours, with password fields blacked out first.">
<meta property="og:url" content="https://computermcp.dev/docs/install-copilot/">
<meta property="og:image" content="https://computermcp.dev/og-image.jpg">
<meta name="twitter:card" content="summary_large_image">
Expand Down
4 changes: 2 additions & 2 deletions docs/docs/install-cursor/index.html
Original file line number Diff line number Diff line change
Expand Up @@ -8,11 +8,11 @@
<link rel="icon" type="image/x-icon" href="/favicon.ico">
<link rel="apple-touch-icon" href="/apple-touch-icon.png">
<meta name="theme-color" content="#0d1117">
<meta name="description" content="Three steps, about two minutes. Cursor drives your real Mac with password fields blacked out before any screenshot is written, and it works without asking - except password managers and anything that deletes.">
<meta name="description" content="Three steps, about two minutes: Cursor can use your Mac in the windows behind yours, with password fields blacked out before any screenshot exists.">
<link rel="canonical" href="https://computermcp.dev/docs/install-cursor/">
<meta property="og:type" content="article">
<meta property="og:title" content="Install Computer MCP for Cursor">
<meta property="og:description" content="Three steps, about two minutes. Cursor drives your real Mac with password fields blacked out before any screenshot is written, and it works without asking - except password managers and anything that deletes.">
<meta property="og:description" content="Three steps, about two minutes: Cursor can use your Mac in the windows behind yours, with password fields blacked out before any screenshot exists.">
<meta property="og:url" content="https://computermcp.dev/docs/install-cursor/">
<meta property="og:image" content="https://computermcp.dev/og-image.jpg">
<meta name="twitter:card" content="summary_large_image">
Expand Down
4 changes: 2 additions & 2 deletions docs/docs/install-vscode/index.html
Original file line number Diff line number Diff line change
Expand Up @@ -8,11 +8,11 @@
<link rel="icon" type="image/x-icon" href="/favicon.ico">
<link rel="apple-touch-icon" href="/apple-touch-icon.png">
<meta name="theme-color" content="#0d1117">
<meta name="description" content="Three steps, about two minutes. VS Code drives your real Mac with password fields blacked out before any screenshot is written, and it works without asking - except password managers and anything that deletes.">
<meta name="description" content="Three steps, about two minutes: VS Code can use your Mac in the windows behind yours, with password fields blacked out before any screenshot exists.">
<link rel="canonical" href="https://computermcp.dev/docs/install-vscode/">
<meta property="og:type" content="article">
<meta property="og:title" content="Install Computer MCP for VS Code">
<meta property="og:description" content="Three steps, about two minutes. VS Code drives your real Mac with password fields blacked out before any screenshot is written, and it works without asking - except password managers and anything that deletes.">
<meta property="og:description" content="Three steps, about two minutes: VS Code can use your Mac in the windows behind yours, with password fields blacked out before any screenshot exists.">
<meta property="og:url" content="https://computermcp.dev/docs/install-vscode/">
<meta property="og:image" content="https://computermcp.dev/og-image.jpg">
<meta name="twitter:card" content="summary_large_image">
Expand Down
4 changes: 2 additions & 2 deletions docs/docs/uninstall/index.html
Original file line number Diff line number Diff line change
Expand Up @@ -8,11 +8,11 @@
<link rel="icon" type="image/x-icon" href="/favicon.ico">
<link rel="apple-touch-icon" href="/apple-touch-icon.png">
<meta name="theme-color" content="#0d1117">
<meta name="description" content="Three steps to remove it, the one file it ever writes, what each macOS permission is for, and the thing that matters most: it makes no network calls at all, and you can check that yourself in one command.">
<meta name="description" content="Remove it in three steps: the one file it writes, what each macOS permission is for, and one command that shows it makes no network calls.">
<link rel="canonical" href="https://computermcp.dev/docs/uninstall/">
<meta property="og:type" content="article">
<meta property="og:title" content="Uninstalling Computer MCP, and exactly what data it touches">
<meta property="og:description" content="Three steps to remove it, the one file it ever writes, what each macOS permission is for, and the thing that matters most: it makes no network calls at all, and you can check that yourself in one command.">
<meta property="og:description" content="Remove it in three steps: the one file it writes, what each macOS permission is for, and one command that shows it makes no network calls.">
<meta property="og:url" content="https://computermcp.dev/docs/uninstall/">
<meta property="og:image" content="https://computermcp.dev/og-image.jpg">
<meta name="twitter:card" content="summary_large_image">
Expand Down
Loading
Loading