MCPLow riskUnclaimed

hypruse

Computer use for Hyprland: semantic desktop state over IPC, plus vision and native input

IlyasKhalloukiilyaskhallouki/hypruse★ 33Updated Oct 8, 2026

server.json

{
  "$schema": "https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json",
  "name": "io.github.IlyasKhallouki/hypruse",
  "description": "Computer use for Hyprland: semantic desktop state over IPC, plus vision and native input",
  "title": "hypruse",
  "repository": {
    "url": "https://github.com/IlyasKhallouki/hypruse",
    "source": "github",
    "id": "1302513522"
  },
  "version": "0.12.0",
  "websiteUrl": "https://github.com/IlyasKhallouki/hypruse#readme",
  "packages": [
    {
      "registryType": "pypi",
      "registryBaseUrl": "https://pypi.org",
      "identifier": "hypruse",
      "version": "0.12.0",
      "runtimeHint": "uvx",
      "transport": {
        "type": "stdio"
      },
      "environmentVariables": [
        {
          "description": "How captures are returned: 'file' writes to XDG_RUNTIME_DIR and returns the path, 'image' returns the image inline. Use 'image' for clients that render MCP images but cannot read files, such as Claude Desktop.",
          "default": "file",
          "choices": [
            "file",
            "image"
          ],
          "name": "HYPRUSE_SCREENSHOT_MODE"
        },
        {
          "description": "Set to 1 to expose only the observation tools (desktop, screenshot, zoom, ui, marks, binds, wait_for). The agent can see and narrate but cannot click, type, or launch.",
          "default": "0",
          "name": "HYPRUSE_READONLY"
        },
        {
          "description": "Restrict input to a scope of windows and refuse everything outside it: 'launched' (only windows hypruse opened this session), 'class:firefox,kitty', or 'workspace:3,special:notes'. Unset means no confinement.",
          "placeholder": "launched",
          "name": "HYPRUSE_CONFINE"
        },
        {
          "description": "Refuse to click or type into system authentication dialogs (polkit, keyring prompts). On by default; 'strict' also refuses password fields in ordinary windows; 0 disables it.",
          "default": "1",
          "choices": [
            "1",
            "strict",
            "0"
          ],
          "name": "HYPRUSE_AUTH_GUARD"
        },
        {
          "description": "Set to 1 to refuse to act when the cursor or focused window moved since hypruse's last action, so the agent must re-read the desktop before retrying.",
          "default": "0",
          "name": "HYPRUSE_STRICT"
        },
        {
          "description": "Set to 1 to make the agent's presence legible: tag every window it opens 'hypruse-owned' and flash an on-screen notice when it opens a window or captures the screen.",
          "default": "0",
          "name": "HYPRUSE_MARK"
        },
        {
          "description": "Set to 1 to register the opt-in clipboard tool (never in read-only mode). Off by default because clipboards hold passwords.",
          "default": "0",
          "name": "HYPRUSE_CLIPBOARD"
        },
        {
          "description": "Record every tool call, refusals included, as one NDJSON line: 1 writes to XDG_STATE_HOME/hypruse/journal.ndjson, or give a path. Read it back with 'hypruse journal'. Off by default.",
          "default": "0",
          "name": "HYPRUSE_JOURNAL"
        },
        {
          "description": "Rotate the journal once it reaches this size, keeping one previous generation alongside it. Set 0 to never rotate.",
          "default": "8388608",
          "name": "HYPRUSE_JOURNAL_MAX_BYTES"
        },
        {
          "description": "Set to 1 to record typed and copied text in the journal verbatim instead of as a length plus digest. Off by default because keystrokes are passwords; needed only to replay typing.",
          "default": "0",
          "name": "HYPRUSE_JOURNAL_TEXT"
        },
        {
          "description": "Set to 1 for a rehearsal: every acting tool validates its arguments and runs every trust guard, then reports what it would have done and delivers no input.",
          "default": "0",
          "name": "HYPRUSE_DRYRUN"
        }
      ]
    }
  ]
}

Permissions

DeclaredDetected
Runs code—python
Installs—pypi:hypruse@0.12.0
Runs install scripts—None
NetworkNoneNone
Needs credentialsNoneNone
Outside the workspace—None
Agent tools—None

Checks

Low risk · Nothing worth a warning was found.

Not reviewed by a person · Checked by rules; the model review is not switched on yet.

Versions

  1. #20.12.0latestOct 8, 2026
  2. #10.11.0Oct 7, 2026