npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@dockndevai/mcp-mac-control

v0.3.1

Published

Model Context Protocol server for FULL macOS control — drive a Mac like a human: shell, AppleScript, files, processes, and human-like GUI (move, click, double/right-click, drag, scroll, type, keys). Full control by default, with an opt-in safe mode.

Readme

mcp-mac-control

npm CI licence

A Model Context Protocol server that gives an AI agent full control of a Mac — like a person sitting at it. Shell, AppleScript, files, processes, and human-like GUI control: move, click, double/right-click, drag, scroll, type, and press key combos — with a screenshot + window/screen-size perception loop.

⚠️ This server is full-control by default. It starts in admin mode with command execution, deletes, and GUI input all enabled. That is powerful and dangerous: anything the agent reads (a web page, an email, a file) could contain a prompt injection that then runs arbitrary code on your Mac. Only connect it to an agent and content you trust. Set MACCTL_SAFE_MODE=true to flip the whole thing to safe-by-default. If you want safe-by-default as the baseline, use the sibling @dockndevai/mcp-macos instead.

Part of the dockndevai MCP server suite.

What it gives an agent (26 tools)

Perceive — screenshot, get_screen_size, list_windows, get_frontmost_app, list_apps, system_info, list_directory, read_file, list_processes, get_clipboard

Operate the desktop like a human — move_mouse, click (left/right/double), drag, scroll, type_text, key_press (with ⌘/⌥/⌃/⇧), activate_app, quit_app, open, set_clipboard, notify, write_file

Full power — run_command (any program, no shell unless you ask for one), run_applescript (AppleScript/JXA — drive any scriptable app), delete_path (→ Trash), kill_process

The classic loop: screenshot → decide → click/type/drag/scroll → screenshot again.

Install

npx -y @dockndevai/mcp-mac-control

macOS only. You'll need to grant the host app (Terminal, your IDE, Claude Desktop, …) macOS permissions the first time each capability is used:

  • Screen Recording → for screenshot
  • Accessibility → for GUI input (click, type_text, drag, scroll, key_press) and list_windows
  • Automation → for AppleScript / app control
  • Mouse control uses cliclick: brew install cliclick

Configure (Claude Code)

claude mcp add mac-control -- npx -y @dockndevai/mcp-mac-control

That's it — it's full-control by default. To scope it down, add env flags (see below). See docs/CLIENTS.md for Claude Desktop / Cursor / Codex / VS Code / Windsurf, and .env.example for every variable.

Dialing the control up or down

Full control needs no configuration. Everything below is about restricting it:

| Variable | Default | Effect | |---|---|---| | MACCTL_SAFE_MODE | false | true → read-only, every power gated, confirmations on (safe-by-default) | | MACCTL_MODE | admin | read-only / read-write / admin — caps which tools are registered | | MACCTL_ALLOW_EXEC | true | shell / AppleScript / kill | | MACCTL_ALLOW_DELETE | true | delete to Trash | | MACCTL_ALLOW_INPUT | true | GUI input (mouse/keyboard) | | MACCTL_CONFIRM | false | true → destructive ops pause for human approval via MCP elicitation | | MACCTL_PATH_ALLOWLIST | (empty = anywhere) | confine file ops to these roots | | MACCTL_PROTECTED_PATHS | (empty) | roots readable but never modified/deleted | | MACCTL_COMMAND_ALLOWLIST | (empty = any) | restrict run_command to these programs | | MACCTL_DRY_RUN | false | validate + log writes without executing | | MACCTL_AUDIT_LOG | true | JSON audit line per guarded op, to stderr |

The policy engine (src/security.ts) is the same graduated model as the rest of the suite — this server just ships it wide open by default. See SECURITY.md.

AI risk guard (optional)

For an extra layer on top of the static rules, this server can consult a local laya-guard daemon before running a high-risk tool (run_command, run_applescript, delete_path). The guard classifies the actual command — deterministic patterns plus a local decision model — as allow / confirm / block. It runs after the deterministic policy and can only tighten (add a confirm or block), never grant.

| Variable | Default | Effect | |---|---|---| | MACCTL_GUARD_MODE | off | monitor (log what it would do) / enforce (block or require confirm) | | MACCTL_GUARD_URL | http://127.0.0.1:8799 | the local laya-guard daemon | | MACCTL_GUARD_TIMEOUT_MS | 2000 | per-check timeout | | MACCTL_GUARD_FAIL_CLOSED | confirm | when the daemon is unreachable in enforce mode: confirm or allow |

Run the daemon with pipx install laya-guard && laya-guard. Start in monitor to see what it catches, then switch to enforce.

Developing

npm install
npm run build
echo '{"jsonrpc":"2.0","id":1,"method":"tools/list","params":{}}' | node dist/index.js   # list tools
npm test

Licence

MIT