← Back to search

io.github.tinqiao-oss/clawtouch-mcp

tinqiao-oss Scanned 2h ago

USB-HID keyboard/mouse (Pico 2, open firmware) as MCP tools; --mock runs with no hardware

B
83.6 / 100

Versions

0.3.2latest
first seen Jun 5, 2026
PermissionsTool SafetyAuthAnnotationsCode QualityStabilitySpecVuln HistoryAuthorTransparencyCommunity

Tools 7

computer_click
annotations: none low

Click something on the real screen, described in words. A vision

computer_click_sequence
annotations: none low

Click several things in order, from ONE look at the screen. Much

computer_find
annotations: none low

Locate something on the real screen WITHOUT clicking it. Use it to

computer_windows
annotations: none low

List the visible windows on the real screen with their titles. Use

computer_type
annotations: none low

Type text on the real keyboard. Keystrokes go wherever the focus

computer_key
annotations: none low

Press a key or key combination on the real keyboard, e.g. Enter,

computer_scroll
annotations: none low

Scroll the real mouse wheel. Positive scrolls up, negative down.

Permissions 4

network medium
Server uses network capabilities via: fetch()
filesystem low
Server uses filesystem capabilities via: os
shell high
Server uses shell capabilities via: child_process, spawn(), subprocess
env_vars low
Server uses env_vars capabilities via: os.environ, process.env

Scan Findings 27

low
Tool 'computer_click' has no annotations annotation_checker · 100%
low
Tool 'computer_click_sequence' has no annotations annotation_checker · 100%
low
Tool 'computer_find' has no annotations annotation_checker · 100%
low
Tool 'computer_windows' has no annotations annotation_checker · 100%
low
Tool 'computer_type' has no annotations annotation_checker · 100%
low
Tool 'computer_key' has no annotations annotation_checker · 100%
low
Tool 'computer_scroll' has no annotations annotation_checker · 100%
info
Sandbox failed to start for behavioral verification behavioral_verifier · 100%
medium
Buffer.from base64 in tinqiao-oss-clawtouch-mcp-69e0f13/adapters/dsh/plugin/probe.js:126 entropy_analyzer · 75%
info
package.json metadata manifest_parser · 100%
info
pyproject.toml metadata manifest_parser · 100%
info
Tool: computer_click manifest_parser · 75%
info
Tool: computer_click_sequence manifest_parser · 75%
info
Tool: computer_find manifest_parser · 75%
info
Tool: computer_windows manifest_parser · 75%
info
Tool: computer_type manifest_parser · 75%
info
Tool: computer_key manifest_parser · 75%
info
Tool: computer_scroll manifest_parser · 75%
info
Transport: stdio manifest_parser · 90%
info
Required env vars (7) manifest_parser · 80%
info
Sandbox failed to start for output poisoning scan output_poisoning · 100%
medium
Permission: network access detected permission_analyzer · 70%
low
Permission: filesystem access detected permission_analyzer · 70%
high
Permission: shell access detected permission_analyzer · 95%
low
Permission: env_vars access detected permission_analyzer · 90%
info
No dependency files found for SBOM generation sbom_generator · 100%
medium
No build provenance detected (SLSA L0) slsa_assessor · 90%