io.github.m0rvayne/mcp-osascript MCP Server
io.github.m0rvayne/mcp-osascript
18 typed tools for macOS automation: windows, menus, keyboard, clipboard, browser tabs, screenshots, and Shortcuts.
What is the io.github.m0rvayne/mcp-osascript MCP server?
The mcp-osascript MCP server gives Claude and other AI agents control over your Mac through 18 typed AppleScript and JXA tools. It enables window management, menu navigation, keyboard input, clipboard access, browser tab reading, screenshots, and Shortcut execution with built-in security guardrails, permission awareness, and self-correcting menu clicks.
mcp-osascript lets Claude automate your Mac by moving windows, clicking menus, typing text, reading clipboard, managing Safari/Chrome/Arc tabs, taking screenshots, and running Apple Shortcuts. It's designed for macOS 13+ with strong security (URL allowlist, env isolation, error sanitization, 84 integration tests, and four red-team audit passes), permission-aware error messages, and self-correcting menu navigation that retries with available options if a menu item doesn't exist.
How to install io.github.m0rvayne/mcp-osascript
Copy-paste configuration for popular MCP clients.
Tools & capabilities
Tools this server exposes to the agent.
check_permissions— Report which permissions are granted and what each unlocksrun_osascript— Execute any AppleScript or JXA scriptget_clipboard— Read clipboard as textset_clipboard— Write text to clipboardsend_notification— Show macOS notification banneropen_url— Open URL in browser (http/https/mailto only)open_app— Launch or bring app to frontget_frontmost_app— Get active app name and bundle IDget_browser_tabs— List tabs in Safari, Chrome, or Arctype_text— Type text into active app (max 500 chars)press_key— Press key with modifiers (cmd+c, return, f5)manage_windows— List, move, resize, minimize, fullscreen, or close windowsget_displays— List monitors with position, size, and main display infoapp_menu— List or click menu items in any appscreenshot— Capture full screen, a region, or an app windowapp_visibility— Hide, unhide, or quit an applicationfile_open— Open a file or folder, optionally in a given apprun_shortcut— List or run Apple Shortcuts
Use cases
- Automate window management and positioning on your Mac
- Navigate application menus and click menu items programmatically
- Control keyboard input and simulate key presses for automation workflows
- Read and manage browser tabs across Safari, Chrome, and Arc
- Capture screenshots of the full screen, specific regions, or individual app windows
- Trigger Apple Shortcuts from Claude for complex automation chains
io.github.m0rvayne/mcp-osascript MCP server FAQ
mcp-osascript is an MCP server that gives Claude and other AI agents 18 typed tools to automate your Mac: control windows, click menus, type text, read clipboard, manage browser tabs, take screenshots, and run Apple Shortcuts. It includes security guardrails, permission awareness, and self-correcting menu navigation.
Yes, mcp-osascript is open-source under the MIT license.
Download the latest `.mcpb` file from the GitHub releases page and double-click it, or add the config manually to Claude Desktop settings: set command to `npx` with args `["-y", "mcp-osascript"]`.
Add to your MCP config: set command to `npx` with args `["-y", "mcp-osascript"]`, then restart your editor.
Most tools need no permission. Browser tabs and frontmost app require Automation permission (macOS prompts once per browser). Keyboard, windows, and menus require Accessibility. Screenshots require Screen Recording. Run `check_permissions` to see what's granted and how to enable the rest.
Yes, it works on macOS 13+ (Ventura or later) on both Intel and Apple Silicon. Node.js 18+ is required.
README (reference)
Source of truth, from the repository.
Let Claude control your Mac. Move windows, click menus, type text, read clipboard, manage browser tabs, take screenshots, run Shortcuts — 18 typed tools with input validation and security guardrails.
Listed in the official MCP Registry as io.github.m0rvayne/mcp-osascript

Quick Start
Claude Desktop — one click. Download mcp-osascript-1.1.3.mcpb from the latest release and double-click it. Claude Desktop installs the extension itself.
Or add it to the config manually:
{
"mcpServers": {
"osascript": {
"command": "npx",
"args": ["-y", "mcp-osascript"]
}
}
}
Add this to your Claude Desktop config (Settings → Developer → Edit Config), restart Claude, and you're ready.
Cursor / VS Code (Copilot)
{
"mcpServers": {
"osascript": {
"command": "npx",
"args": ["-y", "mcp-osascript"]
}
}
}
Claude Code
claude mcp add osascript -- npx -y mcp-osascript
From source (development)
git clone https://github.com/m0rvayne/mcp-osascript.git
cd mcp-osascript && npm install
# then use: "command": "node", "args": ["/path/to/mcp-osascript/server/index.js"]
</details>
Try These Prompts
Once installed, ask Claude:
| Prompt | What happens |
|---|---|
| "Open Safari and show me what tabs I have" | Launches Safari, reads all tab titles and URLs |
| "Move the Finder window to the left half of my screen" | Resizes and positions the window |
| "Click File → Export as PDF in Keynote" | Navigates the menu bar and clicks the item |
| "Copy the URL from my active Chrome tab" | Reads browser tabs, finds the active one |
| "Type 'Hello World' into the active text field" | Simulates keyboard input |
| "Show a notification when you're done" | Displays a native macOS banner |
| "What app am I using right now?" | Returns the frontmost app name and bundle ID |
| "Press Cmd+Shift+4" | Triggers the screenshot shortcut |
| "List all items in the Edit menu of VS Code" | Introspects the menu bar |
| "Close the second window of Terminal" | Targets a specific window by index |
| "Screenshot the Safari window and save it to my Desktop" | Captures just that window, not the whole screen |
| "Which monitor is my Slack window on?" | Reads display geometry and window positions |
| "Hide everything except my editor" | Hides apps without quitting them |
| "Run my 'Daily Standup' shortcut" | Invokes an Apple Shortcut by name |
Tools
18 typed tools, each with input validation, error classification, and permission-aware error messages.
| Tool | What it does | Permission |
|---|---|---|
check_permissions | Report which permissions are granted and what each unlocks | None |
run_osascript | Execute any AppleScript or JXA script | None |
get_clipboard | Read clipboard as text | None |
set_clipboard | Write text to clipboard | None |
send_notification | Show macOS notification banner | None |
open_url | Open URL in browser (http/https/mailto only) | None |
open_app | Launch or bring app to front | None |
get_frontmost_app | Get active app name + bundle ID | Automation |
get_browser_tabs | List tabs in Safari, Chrome, or Arc | Automation |
type_text | Type text into active app (max 500 chars) | Accessibility |
press_key | Press key with modifiers (cmd+c, return, f5) | Accessibility |
manage_windows | List / move / resize / minimize / fullscreen / close | Accessibility |
get_displays | List monitors — position, size, which is main | None |
app_menu | List or click menu items in any app | Accessibility |
screenshot | Capture full screen, a region, or an app window | Screen Recording |
app_visibility | Hide, unhide, or quit an application | Accessibility |
file_open | Open a file or folder, optionally in a given app | None |
run_shortcut | List or run Apple Shortcuts | None |
Self-Correcting Menus
When Claude tries to click a menu item that doesn't exist, the server automatically returns the list of available items at that level — so Claude can retry with the correct name. No other MCP server does this.
User: "Click File → Export as PDF in Preview"
Claude: calls app_menu click ["File", "Export as PDF"]
Server: "Menu item 'Export as PDF' not found in 'File'.
Available: ['New from Clipboard', 'Open...', 'Close', 'Save',
'Duplicate', 'Rename...', 'Export...', 'Export as PDF...']"
Claude: calls app_menu click ["File", "Export as PDF..."]
Server: "Clicked: File > Export as PDF..."
Why mcp-osascript?
| mcp-osascript | steipete (880★) | peakmojo (464★) | |
|---|---|---|---|
| Typed tools with validation | 18 | 2 (generic) | 1 (generic) |
| URL scheme allowlist | http/https/mailto | No | No |
| Env isolation (child process) | PATH+HOME+LANG only | Full process.env | Full process.env |
| Process group kill (no orphans) | SIGTERM→SIGKILL | No | No |
| Error sanitization (paths, tokens) | Yes | No | No |
| Prototype pollution protection | Object.create(null) | No | No |
| Self-correcting menu click | Yes | No | No |
| Integration tests | 84 | 0 | 0 |
| Runs tests in CI | Yes | No | No |
| Red-team audit passes | 4 | 0 | 0 |
| Untrusted-output fencing | Yes | No | No |
| Stdin piping (no temp files) | Yes | Temp files | Temp files |
Star counts are a popularity measure, not a quality one — both alternatives predate this project by months. The rows above are the things that differ in practice.
Security audits
Four red-team audit passes (adversarial agents run against the source, commissioned by the author — not a third-party certification), the most recent against v1.1.2 with three parallel agents
covering the shell surface, AppleScript escaping, and information disclosure. It found six real
defects, including a tool that silently annulled another tool's scheme allowlist and a
concurrency slot that could leak until the server deadlocked. Every finding is fixed and carries
a regression test. escapeAS was verified against 13 string-breakout candidates through real
osascript — none escape.
Permissions
Tools work in three tiers:
- No permission needed — clipboard, notifications, URLs, apps, files, displays, Shortcuts. Works immediately.
- Automation — browser tabs, frontmost app. macOS prompts once per browser.
- Accessibility — keyboard, windows, menus, hide/unhide. Grant once in System Settings → Privacy & Security → Accessibility.
- Screen Recording — screenshots only. Grant in System Settings → Privacy & Security → Screen Recording.
Ask Claude to run check_permissions and it will tell you which of these are already
granted, which tools each one unlocks, and exactly which settings pane to open for the
rest. The probes are read-only and never trigger a permission prompt.
When a permission is missing, the server tells you exactly what to do:
"Accessibility permission required. Grant access to 'osascript'
in System Settings > Privacy & Security > Accessibility."
Testing
npm test
84 integration tests covering all 18 tools — input validation, security boundaries (URL scheme blocking, prototype pollution, script size limits), timeout enforcement, permission error handling, and regressions for every finding of the security audit.
<details> <summary>Security & Architecture</summary>Security
run_osascriptexecutes arbitrary code — this is by design. The MCP client (Claude) is the trust boundary.- Scripts piped via stdin to
/usr/bin/osascript— no temp files, no TOCTOU race conditions. - Script size: 50 KB max. Output: 50K chars max, truncated on a UTF-8 character boundary (no mojibake in non-Latin output).
- Error messages sanitized — filesystem paths, tokens, and passwords are stripped.
- Child processes get minimal env:
PATH,HOME,LANGonly — no API keys or secrets leak. - URL scheme allowlist —
file://,smb://,vnc://,javascript:all blocked. - Handler dispatch uses
Object.create(null)— no prototype pollution. - Externally-sourced text (browser tab titles, window titles, menu items, clipboard) is returned inside an explicit
<untrusted-data>envelope, so a web page that renames itself cannot smuggle instructions into the model's context. file_openrefuses anything that parses as a URL —open(1)resolves URLs as well as paths, so without that check it would quietly annulopen_url's scheme allowlist.screenshotnever overwrites an existing file unlessoverwrite: true, and the extension must match the format.- Every list-building tool strips
|, CR and LF from app-supplied names, so a crafted window or tab title cannot forge a record.
Reliability
- Process group kill on timeout — SIGTERM → 2s grace → SIGKILL. No orphaned processes.
- Concurrency semaphore — max 5 simultaneous osascript processes.
- Graceful shutdown —
server.close()with 10s force-exit safety net. - Error classification — parses macOS error codes (-1728, -1743, -25211) into actionable messages. Supports English and Russian locales.
Requirements
- macOS 13+ (Ventura or later)
- Node.js 18+
License
MIT
Related MCP servers
Clayton Christensen persona agent for strategic advisory using disruption theory
MCP server for controlling Dyson air purifiers and fans
View repository →MCP server for Philips Hue smart lighting control
View repository →MCP server for clinical charting with Claude - document patient visits to EMR
AI-to-AI knowledge network. Agents share insights, ask questions, build reputation over MCP.
View repository →Verified directory for machine payments (x402 & MPP): check services and wallets before agents pay.


