New:Microsoft Teams Notifications Are Now Available in Socket.Learn more →
Get Started

@dockndevai/mcp-macos

Package Overview
Dependencies
Maintainers
1
Versions
3
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install

@dockndevai/mcp-macos

Model Context Protocol server for macOS — observe and operate a Mac (files, processes, apps, screenshots, shell, AppleScript, GUI) with safe-by-default access controls.

latest
Source
npmnpm
Version
0.2.0
Version published
Weekly downloads
191
536.67%
Maintainers
1
Weekly downloads
 
Created
Source

mcp-macos

npm CI licence

A safe-by-default Model Context Protocol server that lets an agent observe and operate a Mac — read files, list processes and apps, take screenshots (read-only); write files, set the clipboard, post notifications, open things (read-write); and, behind explicit opt-ins, run commands / AppleScript, delete to Trash, kill processes and drive the GUI (admin).

It starts read-only. Every high-impact power needs both admin mode and its own flag, and the most dangerous ones ask the human to approve each call. Part of the dockndevai MCP server suite — one governance model across all of them.

Pure Node + osascript/screencapture — no native add-ons. macOS only.

What it gives an agent

The server starts read-only (see Safe by default); higher-capability tools are only registered when you raise the mode.

ToolForNeeds mode
system_infomacOS version, hardware, memory, load, uptimeread-only
list_directory / read_filebrowse & read files (path-allowlisted)read-only
list_processesrunning processes by CPU/memread-only
get_clipboardread the clipboardread-only
list_apps / get_frontmost_apprunning apps; the active oneread-only
screenshotcapture the screen as a PNGread-only
write_filecreate/overwrite a file (confirms on overwrite)read-write
set_clipboard / notify / openset clipboard, notify, open a file/URL/appread-write
run_commandrun a program (argv, no shell)admin + MACOS_ALLOW_EXEC
run_applescriptrun AppleScript / JXAadmin + MACOS_ALLOW_EXEC
kill_processsignal a processadmin + MACOS_ALLOW_EXEC
delete_pathmove a path to the Trashadmin + MACOS_ALLOW_DELETE
type_text / key_press / click / move_mousedrive the GUIadmin + MACOS_ALLOW_INPUT

Install

npx -y @dockndevai/mcp-macos

Requires macOS and Node ≥ 22. click/move_mouse also need cliclick (brew install cliclick).

Configure

{
  "mcpServers": {
    "macos": {
      "command": "npx",
      "args": ["-y", "@dockndevai/mcp-macos"],
      "env": {
        "MACOS_MODE": "read-only"
      }
    }
  }
}

See docs/CLIENTS.md for Claude Code / Cursor / Codex / VS Code / Windsurf snippets, and .env.example for every supported variable.

Safe by default

This server can drive an entire Mac, so the access model (enforced by src/security.ts) is deliberately strict — defence in depth, not documentation:

QuestionSettingDefaultNotes
What can it do at all?MACOS_MODEread-onlyread-only observes; read-write writes files/clipboard/opens; admin adds exec/delete/kill/GUI. Tools above the mode are never registered.
Which paths can it touch?MACOS_PATH_ALLOWLIST(anywhere)Comma-separated roots. When set, any file op outside them is refused.
Which paths are read-only forever?MACOS_PROTECTED_PATHSsystem + secrets/System, /usr, /bin, /sbin, /private, /Library, ~/.ssh, ~/.aws, ~/.gnupg, ~/Library/Keychains — readable, never mutated.
Can it run commands?MACOS_ALLOW_EXECfalseGates run_command, run_applescript, kill_process (on top of admin).
Restrict which programs?MACOS_COMMAND_ALLOWLIST(any)When set, run_command may only invoke these program names.
Can it delete?MACOS_ALLOW_DELETEfalseGates delete_path (moves to the Trash, recoverable).
Can it drive the GUI?MACOS_ALLOW_INPUTfalseGates type_text/key_press/click/move_mouse.
Preview without doingMACOS_DRY_RUNfalseMutating tools validate + log intent, then return.
Audit trailMACOS_AUDIT_LOGtrueJSON line to stderr per guarded operation (ALLOW/DENY/DRY_RUN).
Interactive confirmation(automatic)—run_command, run_applescript, delete_path, kill_process and file overwrites ask the human to approve via MCP elicitation before running; clients without elicitation fall back to the flags.

See SECURITY.md.

macOS permissions

The host process (your terminal / MCP client) must be granted, in System Settings → Privacy & Security:

  • Screen Recording — for screenshot.
  • Accessibility — for type_text / key_press / click / move_mouse.
  • Automation (per-app prompts) — for run_applescript and app control.
  • Files and Folders / Full Disk Access — to read/write outside the default sandbox.

You'll be prompted the first time each is needed; nothing works around a permission you haven't granted.

Developing

npm install
npm run build
MACOS_MODE=read-only node dist/index.js
# introspect the tool list:
echo '{"jsonrpc":"2.0","id":1,"method":"tools/list","params":{}}' | node dist/index.js

Licence

MIT

Keywords

mcp

FAQs

Package last updated on 29 Sep 2026

Related posts