PluginBench
MCP Server
Active
MIT

io.github.ObscuritySRL/umbriel MCP Server

io.github.ObscuritySRL/umbriel

What is the io.github.ObscuritySRL/umbriel MCP server?

See and drive a whole Windows machine from Bun — apps, input, screen, OCR, registry, OS — via MCP.

How to install io.github.ObscuritySRL/umbriel

Copy-paste configuration for popular MCP clients.

transport: stdio
Config generated by PluginBench — verify against the source before use.
Environment / auth
  • UMBRIEL_PROFILE

    Capability profile: 'readonly' (inspect/read only), 'safe' (read + input + window — default), or 'full' (also os + fs tools).

  • UMBRIEL_OS

    Set to '1' to allow the 'os' tools (launch_app/run_program/open_path, kill_process, manage_process, control_service, set_env, registry_get/registry_list/registry_set) AND the 'fs' tools (read_file/write_file/list_dir/stat_path/make_dir/copy_file/move_file/delete_file) regardless of profile.

  • UMBRIEL_ALLOW

    Comma-separated tool names or categories to additionally allow on top of the profile.

  • UMBRIEL_DENY

    Comma-separated tool names or categories to deny, overriding the profile and UMBRIEL_ALLOW.

  • UMBRIEL_CURSOR

    Set to 'never' to forbid the real-cursor fallback entirely (strictly cursor-free). By default clicks/drags are cursor-free but fall back to the real hardware cursor when no cursor-free path exists.

  • UMBRIEL_FS_ROOT

    Sandbox root directory that the fs-category file tools (read_file/write_file/list_dir/stat_path/make_dir/copy_file/move_file/delete_file) are confined to when fs tools are enabled; open_path's path argument is honored too.

  • UMBRIEL_TRACE

    File path to journal every mutating tool call as JSON Lines (tool, category, masked args, ok, observation); secret-bearing args and values are redacted. Unset = no trace.

  • UMBRIEL_FFI_TRACE

    File path to a flush-before-call diagnostic journal of every COM vcall (slot, this-pointer, arg count). Each line is written and flushed to the OS BEFORE the native call, so after an uncatchable crash the last line names the faulting call. Has per-call overhead; unset = off. For debugging native faults only.

  • UMBRIEL_AUDIT

    Controls the default-on stderr audit of mutating tool calls. 'off' is the explicit opt-out (reported at startup); 'verbose' also audits reads.

  • UMBRIEL_REDACT

    Credential masking (default on). 'off' opts out; a regex value overrides the built-in secret shapes masked in clipboard/env/registry reads and the trace journal.

Claude Desktop
~/Library/Application Support/Claude/claude_desktop_config.json
{
  "mcpServers": {
    "umbriel": {
      "command": "bunx",
      "args": [
        "-y",
        "umbriel"
      ],
      "env": {
        "UMBRIEL_PROFILE": "<YOUR_UMBRIEL_PROFILE>",
        "UMBRIEL_OS": "<YOUR_UMBRIEL_OS>",
        "UMBRIEL_ALLOW": "<YOUR_UMBRIEL_ALLOW>",
        "UMBRIEL_DENY": "<YOUR_UMBRIEL_DENY>",
        "UMBRIEL_CURSOR": "<YOUR_UMBRIEL_CURSOR>",
        "UMBRIEL_FS_ROOT": "<YOUR_UMBRIEL_FS_ROOT>",
        "UMBRIEL_TRACE": "<YOUR_UMBRIEL_TRACE>",
        "UMBRIEL_FFI_TRACE": "<YOUR_UMBRIEL_FFI_TRACE>",
        "UMBRIEL_AUDIT": "<YOUR_UMBRIEL_AUDIT>",
        "UMBRIEL_REDACT": "<YOUR_UMBRIEL_REDACT>"
      }
    }
  }
}
Cursor
~/.cursor/mcp.json
{
  "mcpServers": {
    "umbriel": {
      "command": "bunx",
      "args": [
        "-y",
        "umbriel"
      ],
      "env": {
        "UMBRIEL_PROFILE": "<YOUR_UMBRIEL_PROFILE>",
        "UMBRIEL_OS": "<YOUR_UMBRIEL_OS>",
        "UMBRIEL_ALLOW": "<YOUR_UMBRIEL_ALLOW>",
        "UMBRIEL_DENY": "<YOUR_UMBRIEL_DENY>",
        "UMBRIEL_CURSOR": "<YOUR_UMBRIEL_CURSOR>",
        "UMBRIEL_FS_ROOT": "<YOUR_UMBRIEL_FS_ROOT>",
        "UMBRIEL_TRACE": "<YOUR_UMBRIEL_TRACE>",
        "UMBRIEL_FFI_TRACE": "<YOUR_UMBRIEL_FFI_TRACE>",
        "UMBRIEL_AUDIT": "<YOUR_UMBRIEL_AUDIT>",
        "UMBRIEL_REDACT": "<YOUR_UMBRIEL_REDACT>"
      }
    }
  }
}
Windsurf
~/.codeium/windsurf/mcp_config.json
{
  "mcpServers": {
    "umbriel": {
      "command": "bunx",
      "args": [
        "-y",
        "umbriel"
      ],
      "env": {
        "UMBRIEL_PROFILE": "<YOUR_UMBRIEL_PROFILE>",
        "UMBRIEL_OS": "<YOUR_UMBRIEL_OS>",
        "UMBRIEL_ALLOW": "<YOUR_UMBRIEL_ALLOW>",
        "UMBRIEL_DENY": "<YOUR_UMBRIEL_DENY>",
        "UMBRIEL_CURSOR": "<YOUR_UMBRIEL_CURSOR>",
        "UMBRIEL_FS_ROOT": "<YOUR_UMBRIEL_FS_ROOT>",
        "UMBRIEL_TRACE": "<YOUR_UMBRIEL_TRACE>",
        "UMBRIEL_FFI_TRACE": "<YOUR_UMBRIEL_FFI_TRACE>",
        "UMBRIEL_AUDIT": "<YOUR_UMBRIEL_AUDIT>",
        "UMBRIEL_REDACT": "<YOUR_UMBRIEL_REDACT>"
      }
    }
  }
}
VS Code
.vscode/mcp.json
{
  "servers": {
    "umbriel": {
      "type": "stdio",
      "command": "bunx",
      "args": [
        "-y",
        "umbriel"
      ],
      "env": {
        "UMBRIEL_PROFILE": "<YOUR_UMBRIEL_PROFILE>",
        "UMBRIEL_OS": "<YOUR_UMBRIEL_OS>",
        "UMBRIEL_ALLOW": "<YOUR_UMBRIEL_ALLOW>",
        "UMBRIEL_DENY": "<YOUR_UMBRIEL_DENY>",
        "UMBRIEL_CURSOR": "<YOUR_UMBRIEL_CURSOR>",
        "UMBRIEL_FS_ROOT": "<YOUR_UMBRIEL_FS_ROOT>",
        "UMBRIEL_TRACE": "<YOUR_UMBRIEL_TRACE>",
        "UMBRIEL_FFI_TRACE": "<YOUR_UMBRIEL_FFI_TRACE>",
        "UMBRIEL_AUDIT": "<YOUR_UMBRIEL_AUDIT>",
        "UMBRIEL_REDACT": "<YOUR_UMBRIEL_REDACT>"
      }
    }
  }
}
Claude Code
claude mcp add umbriel --env UMBRIEL_PROFILE=<YOUR_UMBRIEL_PROFILE> --env UMBRIEL_OS=<YOUR_UMBRIEL_OS> --env UMBRIEL_ALLOW=<YOUR_UMBRIEL_ALLOW> --env UMBRIEL_DENY=<YOUR_UMBRIEL_DENY> --env UMBRIEL_CURSOR=<YOUR_UMBRIEL_CURSOR> --env UMBRIEL_FS_ROOT=<YOUR_UMBRIEL_FS_ROOT> --env UMBRIEL_TRACE=<YOUR_UMBRIEL_TRACE> --env UMBRIEL_FFI_TRACE=<YOUR_UMBRIEL_FFI_TRACE> --env UMBRIEL_AUDIT=<YOUR_UMBRIEL_AUDIT> --env UMBRIEL_REDACT=<YOUR_UMBRIEL_REDACT> -- bunx -y umbriel

Related MCP servers

Playwright for the Windows desktop, from Bun — drive native GUIs via UI Automation + MCP.

16
TypeScript
View repository →