Open-source computer use for macOS agents.
Inferred from the transports this listing declares (stdio). A client not listed here hasn’t been ruled out — it just isn’t something Forge can confirm.
Verification confirms publisher identity (repo ownership), not code safety. The security scan covers known CVEs and suspicious install scripts.
Read out of the source npm actually ships, at scan time. The package was never executed. Tools registered dynamically at runtime, or hidden inside bundled or minified code, can be missed — so this is a floor on the tool surface, not a complete census of it.
list_appsNo description publishedThis tool published no description. Forge does not invent one.
list_daemon_methodsNo description publishedThis tool published no description. Forge does not invent one.
begin_activityNo description publishedThis tool published no description. Forge does not invent one.
end_activityNo description publishedThis tool published no description. Forge does not invent one.
connect_appNo description publishedThis tool published no description. Forge does not invent one.
query_treeNo description publishedThis tool published no description. Forge does not invent one.
list_windowsNo description publishedThis tool published no description. Forge does not invent one.
clickNo description publishedThis tool published no description. Forge does not invent one.
fillNo description publishedThis tool published no description. Forge does not invent one.
wait_forNo description publishedThis tool published no description. Forge does not invent one.
press_keyNo description publishedThis tool published no description. Forge does not invent one.
press_keysNo description publishedThis tool published no description. Forge does not invent one.
screenshotNo description publishedThis tool published no description. Forge does not invent one.
extract_textNo description publishedThis tool published no description. Forge does not invent one.
get_elementNo description publishedThis tool published no description. Forge does not invent one.
dump_attributesNo description publishedThis tool published no description. Forge does not invent one.
pin_handleNo description publishedThis tool published no description. Forge does not invent one.
unpin_handleNo description publishedThis tool published no description. Forge does not invent one.
read_formNo description publishedThis tool published no description. Forge does not invent one.
select_menu_itemNo description publishedThis tool published no description. Forge does not invent one.
list_menu_barNo description publishedThis tool published no description. Forge does not invent one.
run_applescriptNo description publishedThis tool published no description. Forge does not invent one.
list_shortcutsNo description publishedThis tool published no description. Forge does not invent one.
run_shortcutNo description publishedThis tool published no description. Forge does not invent one.
list_skillsNo description publishedThis tool published no description. Forge does not invent one.
load_skillNo description publishedThis tool published no description. Forge does not invent one.
run_skill_scriptNo description publishedThis tool published no description. Forge does not invent one.
0 of 27 tools published a description.
Tool names and descriptions are written by the publisher and shown verbatim as inert text. They are the strings an MCP client passes to a model, so Forge scans them for prompt-injection patterns — any finding appears with the security scan above. “Privileged” is a keyword match on the tool name, not an audit of what the tool does: a benign-sounding name can still do anything.
Open-source computer use for macOS agents.
Linked names open Forge’s index of every entry observed exposing that tool. Browse all indexed tools.
This package was last scanned before Forge began storing the resolved tree. The next scan will record it.