Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, get in touch and we’ll put it right.

io.github.cyanheads/macos-mcp-server

NPM · @CYANHEADS/MACOS-MCP-SERVER · SCANNED AUG 7

Control macOS system settings, apps, windows, audio, displays, screenshots, and Focus mode via MCP.

+60 this week 66 Trust /100
Trust breakdown (6 categories)

How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. How we score →

Supply Chain Security86
  • No malware found by supply-chain analysis.Pass
  • Known CVEs were checked across the 125 of 132 dependencies we could resolve, so this covers what we could see, not the whole tree.Partial
  • No install/post-install scripts declared.Pass
  • Dependency health was assessed across the 125 of 132 dependencies we could resolve, so this covers what we could see, not the whole tree. View diagnostics → Partial
Provenance & Transparency45
Schema Quality & AI Usability82
  • 100% of prompts and resources have a non-trivial description (not blank, and not just the item's name).Pass
  • AI-judged instruction clarity (excellent).Pass
  • Context-footprint check failed: tool/resource definitions use about 2153 tokens (~134/item across 16 items; 13 tools + 3 resources), over budget; trim descriptions and params. See how to fix → Fail
  • Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management0
  • Stability not yet verified: not enough scan history yet (needs a 30-day window).Unverified
Tool Coverage100
  • 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
  • 100% of tool parameters carry a description.Pass
  • Structured output schemas are declared (100% of tools); any adoption earns full credit.Pass
Capabilities100
  • Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass

Unverified: 1 category

A category scored 0 because we could not verify it: a data source with nothing on this package, evidence we could not reach, or a check we could not run. We only credit what we can confirm.

Install

Add this component to your MCP client. Where a client-specific snippet is available, pick your client below and copy it straight into your config; otherwise use the connection detail shown.

npm · @cyanheads/macos-mcp-server

# add to Claude Code
claude mcp add cyanheads-macos-mcp-server -- npx -y @cyanheads/macos-mcp-server
# add to Codex CLI
codex mcp add cyanheads-macos-mcp-server -- npx -y @cyanheads/macos-mcp-server
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "cyanheads-macos-mcp-server": {
      "type": "local",
      "command": [
        "npx",
        "-y",
        "@cyanheads/macos-mcp-server"
      ],
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add cyanheads-macos-mcp-server --command npx --arg -y --arg @cyanheads/macos-mcp-server
# ~/.hermes/config.yaml
mcp_servers:
  cyanheads-macos-mcp-server:
    command: "npx"
    args: ["-y", "@cyanheads/macos-mcp-server"]
// mcp.json
{
  "mcpServers": {
    "cyanheads-macos-mcp-server": {
      "command": "npx",
      "args": [
        "-y",
        "@cyanheads/macos-mcp-server"
      ]
    }
  }
}
Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 7 Aug 26 0
    • Security disclosure: unverified → fail functional
  • 6 Aug 26 0
    • Security disclosure: fail → unverified functional
  • 5 Aug 26 +31
    • Stability: Stability not yet verified: not enough scan history yet (needs a 30-day window). security
    • Schema quality: unverified → 100 functional
    • MCP protocol: unverified → pass functional
    • Tool coverage: unverified → 100 functional
    • First check of Tool coverage: 100 functional
    • First check of Tool coverage: 100 functional
    • First check of Schema quality: fail functional
    • First check of Schema quality: excellent functional
    • First check of Schema quality: fail functional
  • 3 Aug 26 +30
    • Provenance: unverified → fail security
    • Malware scan: unverified → pass security
    • Install scripts: unverified → pass security
    • Known CVEs: unverified → partial security
    • Stability: Stability not yet verified: our sandbox run of this package did not complete, so we have no schema to compare. security
    • Maintenance: unverified → pass functional
    • License: unverified → pass functional
    • Dependency health: unverified → partial functional
    • Schema quality: Schema quality not yet verified: our sandbox run of this package did not complete, so we have no schema to assess. functional
    • Capabilities: Protocol version not yet verified: our sandbox run of this package did not complete, so we never saw its MCP handshake. functional
    • Tool coverage: Tool coverage not yet verified: our sandbox run of this package did not complete, so we have no tool definitions to assess. functional
    • Licence: Apache-2.0 functional
  • 2 Aug 26 −15
    • Malware scan: pass → unverified security
    • Stability: Stability not yet verified: we do not have a sandbox capture of the MCP schema this version of the package serves yet. security
    • Tool coverage: Tool coverage not yet verified: we do not have a sandbox capture of the tool definitions this version of the package serves yet. functional
    • Schema quality: Schema quality not yet verified: we do not have a sandbox capture of the MCP schema this version of the package serves yet. functional
    • Capabilities: Protocol version not yet verified: we do not have a sandbox capture of the MCP handshake this version of the package performs yet. functional
  • 1 Aug 26 +14
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 31 Jul 26 −19
    • Malware scan: pass → unverified security
    • Security disclosure: unverified → fail functional
    • Dependency health: partial → unverified functional
    • Tool coverage: Tool coverage not yet verified: our sandbox run of this package did not complete, so we have no tool definitions to assess. functional
    • Schema quality: Schema quality not yet verified: our sandbox run of this package did not complete, so we have no schema to assess. functional
  • 29 Jul 26 +1
    • Security disclosure: fail → unverified functional
    • Dependency health: unverified → partial functional
    • Tool coverage: Tool coverage not yet verified: we do not have a sandbox capture of the tool definitions this version of the package serves yet. functional
    • Schema quality: Schema quality not yet verified: we do not have a sandbox capture of the MCP schema this version of the package serves yet. functional
Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 7 Aug 2026 · Analysed npm/@cyanheads/[email protected]

Provenance No attestation

The registry publishes no build provenance for this version, so there is nothing to verify.

Result No attestation
Ecosystem npm
Dependencies 125 packages
Packages resolved 125
Deprecated 125
Stale 39
Tree resolution Partial

The dependency tree was only partially resolved, so these counts may be incomplete.

MCP tools · 13 exposed · ~1,995 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability.

Tool Tokens
macos_check_permissions ~78

Reports which macOS permissions relevant to this server are currently granted for the calling process: Accessibility (required for window manipulation, app hide/show), Screen Recording (required for window screenshots), Automation > Finder (required for Finder selection), and Notifications. Use this tool before attempting operations that require elevated permissions to confirm prerequisites without triggering an OS permission prompt.

Input schema present but exposes no named parameters.

NameTypeReqDescription
accessibilitybooleanyesTrue when Accessibility permission is granted.
automation_finderbooleanyesTrue when Automation > Finder permission is granted.
calling_processstringyesName of the process that launched this server (e.g. "ghostty", "node").
notificationsbooleanyesTrue when notifications can be posted via osascript.
screen_recordingbooleanyesTrue when Screen Recording permission is granted.

No examples provided.

macos_control_appearance ~111

Get or set the system appearance (dark mode or light mode). The get action returns the current mode. The set action accepts mode="dark", "light", or "toggle". Setting "dark" or "light" is idempotent — calling twice produces the same state. "toggle" flips the current mode on each call.

NameTypeReqDescription
actionstringyesget returns the current appearance; set applies the specified mode.
modestringTarget appearance mode. Required for action=set.
NameTypeReqDescription
dark_modebooleanyesTrue when dark mode is currently active.

No examples provided.

macos_control_audio ~158

Manage audio device routing: list all input and output devices, get the current default input and output devices, or switch the default input or output device. Device names support case-insensitive partial matching — "MacBook" matches "MacBook Pro Microphone". Volume level control is separate (use macos_control_volume). Requires SwitchAudioSource CLI (brew install switchaudio-osx).

NameTypeReqDescription
actionstringyeslist — all devices; current — default input and output; switch_output/switch_input — change the default device.
devicestringPartial or full device name for switch_output/switch_input. Case-insensitive substring match.
typestringFilter by device type for action=list. Defaults to "all".
NameTypeReqDescription
actionstringyesThe action that was performed.
deviceobjectThe device that is now the default. Present for switch actions.
devicesarrayAll audio devices matching the type filter. Present for action=list.
inputobjectCurrent default input device. Present for action=current.
outputobjectCurrent default output device. Present for action=current.
successbooleanTrue when the switch completed. Present for switch actions.

No examples provided.

macos_control_system ~86

System-level power controls: lock the screen (⌃⌘Q shortcut via Accessibility; falls back to ScreenSaverEngine binary if Accessibility is not granted) or put the display to sleep immediately. Both operations are immediate and user-reversible (wake/unlock with any input).

NameTypeReqDescription
actionstringyeslock — lock the screen immediately. sleep_display — turn off all displays.
NameTypeReqDescription
actionstringyesThe action that was performed.
successbooleanyesTrue when the operation completed.

No examples provided.

macos_control_volume ~146

Get or set the system output volume level (0–100) and mute state. The get action returns the current level and mute state. The set action accepts level (0–100), muted (true/false), or both. Setting level=0 does not mute — use muted=true for explicit muting.

NameTypeReqDescription
actionstringyesget returns current state; set applies provided level and/or muted values.
levelnumberOutput volume level from 0 (silent) to 100 (maximum). Only used with action=set.
mutedbooleanMute state. true=mute output, false=unmute. Only used with action=set.
NameTypeReqDescription
levelnumberyesCurrent output volume level (0–100).
mutedbooleanyesTrue when the output is currently muted.

No examples provided.

macos_get_info ~67

Returns a snapshot of the current macOS system state: battery level and charging status, power source (AC/Battery), Wi-Fi SSID, hostname, macOS version, uptime in seconds, and connected display count. All fields reflect live system state at the time of the call.

Input schema present but exposes no named parameters.

NameTypeReqDescription
batteryyesBattery info, or null on desktops with no battery.
display_countnumberyesNumber of currently connected displays.
hostnamestringyesMachine hostname.
macos_versionstringyesmacOS product version string, e.g. "15.1.0".
uptime_secondsnumberyesSeconds since last boot.
wifiobjectyesWi-Fi connection status.

No examples provided.

macos_manage_apps ~189

Manage application lifecycle: list all running user-facing apps, get the frontmost app, launch or activate an app, gracefully quit or force-quit a process, or hide/show an app. Launch activates the app if already running; use hidden=true to start in the background without bringing it forward. Force-quit terminates immediately (SIGKILL) without saving. Hide and show require Accessibility permission.

NameTypeReqDescription
actionstringyesOperation to perform on the application.
app_namestringApplication name, e.g. "Safari", "Visual Studio Code". Required for launch, quit, force_quit, hide, show.
bundle_idstringBundle identifier, e.g. "com.apple.Safari". Alternative to app_name for launch.
hiddenbooleanlaunch only: when true, start the app in the background without bringing it to the foreground.
NameTypeReqDescription
actionstringyesThe action that was performed.
appobjectFrontmost application details. Present for action=frontmost.
app_namestringThe application acted upon. Present for write actions.
appsarrayRunning user-facing applications. Present for action=list.
successbooleanTrue when the operation completed successfully. Present for write actions.

No examples provided.

macos_manage_displays ~155

List connected displays with their current layout (resolution, position, rotation, scaling) and optionally apply a pre-configured display layout by name. Requires displayplacer CLI (brew install jakehilborn/jakehilborn/displayplacer). Layouts are pre-configured in the MACOS_DISPLAY_LAYOUTS environment variable as a JSON object mapping names to displayplacer argument strings. Layout application only accepts named presets — raw displayplacer args are never accepted from the user.

NameTypeReqDescription
actionstringyeslist — enumerate connected displays; apply_layout — activate a saved layout.
layout_namestringName of the display layout to apply. Must match a key in MACOS_DISPLAY_LAYOUTS. Required for action=apply_layout.
NameTypeReqDescription
actionstringyesThe action that was performed.
current_configstringThe current displayplacer command that would reproduce the active arrangement. Present for action=list.
displaysarrayConnected display inventory. Present for action=list.
layout_namestringName of the layout that was applied. Present for action=apply_layout.
successbooleanTrue when the layout was applied. Present for action=apply_layout.

No examples provided.

macos_manage_finder ~179

Finder integration: get the path of the frontmost Finder window, get the current Finder selection, reveal a file or folder in Finder, open a path with a specific app, or move a path to the Trash (recoverable — goes to Trash, not rm). Frontmost path and reveal work without any special permissions. get_selection requires Automation > Finder permission. trash moves files to Trash, not permanent deletion.

NameTypeReqDescription
actionstringyesfrontmost_path — path of the Finder window in focus; get_selection — selected items; reveal — show path in Finder; open_with — open path using a named app; trash — move path to Trash.
app_namestringApplication name for open_with, e.g. "TextEdit".
pathstringAbsolute path for reveal, open_with, and trash actions.
NameTypeReqDescription
actionstringyesThe action that was performed.
countnumberNumber of selected items. Present for action=get_selection.
pathPOSIX path of the frontmost Finder window, or null when no window is open. Present for frontmost_path and write actions.
pathsarrayPOSIX paths of selected items in Finder. Present for action=get_selection.
successbooleanTrue when the operation completed. Present for write actions.

No examples provided.

macos_manage_focus ~188

Get or set Do Not Disturb / Focus mode. The get action is best-effort — macOS 13+ protects the Focus state database and the returned status may be "unknown" on some configurations. The set action requires the built-in "Set Focus" shortcut to exist in the Shortcuts app (present on macOS 12+). Mode names must exactly match configured Focus profiles (e.g. "Do Not Disturb", "Work", "Personal").

NameTypeReqDescription
actionstringyesget — query current Focus status (best-effort); set — enable or disable a Focus mode.
enabledbooleanFor action=set: true=enable the mode, false=disable it. Defaults to true.
modestringFocus mode name for action=set, e.g. "Do Not Disturb", "Work". Must match a configured Focus profile exactly.
NameTypeReqDescription
actionstringyesThe action that was performed.
modeActive Focus mode name, or null when inactive or unknown. Present for action=get and action=set.
reasonstringExplanation when status is "unknown". Present for action=get.
statusstringCurrent Focus status. Present for action=get. "unknown" when macOS cannot be queried without entitlements.
successbooleanTrue when the Focus mode was applied. Present for action=set.

No examples provided.

macos_manage_windows ~232

Window operations across all visible apps: list all windows with their bounds, focus an app window, move or resize a window, minimize/restore, toggle fullscreen, or close. List and focus do not require Accessibility; all other operations do. When app_name and window_title are both given, window_title takes precedence.

NameTypeReqDescription
actionstringyesOperation to perform.
app_namestringTarget application name. Targets the frontmost window of this app.
fullscreenbooleanFor fullscreen: true=enter fullscreen, false=exit fullscreen.
heightnumberWindow height in pixels for resize/move_resize.
minimizedbooleanFor minimize: true=minimize, false=restore from Dock.
widthnumberWindow width in pixels for resize/move_resize.
window_titlestringExact window title. Takes precedence over app_name when both are provided.
xnumberLeft edge x-coordinate for move/move_resize. Screen coordinates.
ynumberTop edge y-coordinate for move/move_resize. Screen coordinates.
NameTypeReqDescription
actionstringyesThe action that was performed.
successbooleanTrue when the operation completed. Present for write actions.
windowobjectWindow state after the operation. Present for write actions.
windowsarrayAll visible windows across all apps. Present for action=list.

No examples provided.

macos_send_notification ~130

Post a notification to macOS Notification Center via osascript. The notification appears immediately and uses the calling process's notification settings. Title is required; body, subtitle, and sound are optional. Each call creates a new notification (not idempotent). Do Not Disturb does not suppress notifications sent via osascript.

NameTypeReqDescription
bodystringNotification body text.
soundbooleanWhen true, plays the default notification sound. Defaults to false.
subtitlestringNotification subtitle (appears below the title).
titlestringyesNotification title (required).
NameTypeReqDescription
successbooleanyesTrue when the notification was posted successfully.

No examples provided.

macos_take_screenshot ~276

Capture a screenshot of the full screen, a specific display (by 0-based index), a named app window, or a pixel region. Always saves a full-resolution PNG to disk (defaulting to ~/Desktop). Optionally returns a downscaled JPEG preview (max 1024px wide) as base64 for agent visual analysis — keeping response size manageable. Window capture requires Screen Recording permission; all other targets do not.

NameTypeReqDescription
app_namestringApp name for target=window, e.g. "Safari". App must be running and not minimized.
display_indexnumber0-based display index for target=display. 0 is the primary display.
include_databooleanWhen true, returns a downscaled JPEG preview as base64 in the response for agent visual analysis. Defaults to false.
pathstringAbsolute path for the output PNG. Defaults to MACOS_SCREENSHOT_DIR/<timestamp>.png (~/Desktop if not configured). Must be within ~/Desktop, /tmp, or the home directory.
regionobjectPixel region to capture. Required for target=region.
targetstringyesscreen — full screen; window — a named app window (requires Screen Recording); display — a specific connected display; region — a pixel rectangle.
NameTypeReqDescription
heightnumberyesFull-resolution image height in pixels.
pathstringyesAbsolute path to the full-resolution PNG written to disk.
previewstringBase64-encoded JPEG preview (max 1024px wide, ~70% quality). Present only when include_data=true.
preview_heightnumberPreview image height in pixels. Present when include_data=true.
preview_widthnumberPreview image width in pixels. Present when include_data=true.
widthnumberyesFull-resolution image width in pixels.

No examples provided.