MCPLow riskUnclaimed
umbriel
See and drive a whole Windows machine from Bun — apps, input, screen, OCR, registry, OS — via MCP.
ObscuritySRLobscuritysrl/umbriel
server.json
{
"$schema": "https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json",
"name": "io.github.ObscuritySRL/umbriel",
"description": "See and drive a whole Windows machine from Bun — apps, input, screen, OCR, registry, OS — via MCP.",
"repository": {
"url": "https://github.com/ObscuritySRL/umbriel",
"source": "github"
},
"version": "1.14.0",
"packages": [
{
"registryType": "npm",
"identifier": "umbriel",
"version": "1.14.0",
"runtimeHint": "bunx",
"transport": {
"type": "stdio"
},
"environmentVariables": [
{
"description": "Capability profile: 'readonly' (inspect/read only), 'safe' (read + input + window — default), or 'full' (also os + fs tools).",
"format": "string",
"default": "safe",
"name": "UMBRIEL_PROFILE"
},
{
"description": "Set to '1' to allow the 'os' tools (launch_app/run_program/open_path, kill_process, manage_process, control_service, set_env, registry_get/registry_list/registry_set) AND the 'fs' tools (read_file/write_file/list_dir/stat_path/make_dir/copy_file/move_file/delete_file) regardless of profile.",
"format": "string",
"name": "UMBRIEL_OS"
},
{
"description": "Comma-separated tool names or categories to additionally allow on top of the profile.",
"format": "string",
"name": "UMBRIEL_ALLOW"
},
{
"description": "Comma-separated tool names or categories to deny, overriding the profile and UMBRIEL_ALLOW.",
"format": "string",
"name": "UMBRIEL_DENY"
},
{
"description": "Set to 'never' to forbid the real-cursor fallback entirely (strictly cursor-free). By default clicks/drags are cursor-free but fall back to the real hardware cursor when no cursor-free path exists.",
"format": "string",
"name": "UMBRIEL_CURSOR"
},
{
"description": "Sandbox root directory that the fs-category file tools (read_file/write_file/list_dir/stat_path/make_dir/copy_file/move_file/delete_file) are confined to when fs tools are enabled; open_path's path argument is honored too.",
"format": "string",
"name": "UMBRIEL_FS_ROOT"
},
{
"description": "File path to journal every mutating tool call as JSON Lines (tool, category, masked args, ok, observation); secret-bearing args and values are redacted. Unset = no trace.",
"format": "string",
"name": "UMBRIEL_TRACE"
},
{
"description": "File path to a flush-before-call diagnostic journal of every COM vcall (slot, this-pointer, arg count). Each line is written and flushed to the OS BEFORE the native call, so after an uncatchable crash the last line names the faulting call. Has per-call overhead; unset = off. For debugging native faults only.",
"format": "string",
"name": "UMBRIEL_FFI_TRACE"
},
{
"description": "Controls the default-on stderr audit of mutating tool calls. 'off' is the explicit opt-out (reported at startup); 'verbose' also audits reads.",
"format": "string",
"name": "UMBRIEL_AUDIT"
},
{
"description": "Credential masking (default on). 'off' opts out; a regex value overrides the built-in secret shapes masked in clipboard/env/registry reads and the trace journal.",
"format": "string",
"name": "UMBRIEL_REDACT"
}
]
}
]
}Permissions
DeclaredDetected
Runs code—
nodeInstalls—
npm:umbriel@1.14.0Runs install scripts—None
NetworkNoneNone
Needs credentialsNoneNone
Outside the workspace—None
Agent tools—None
Checks
Low risk · Nothing worth a warning was found.
Not reviewed by a person · Checked by rules; the model review is not switched on yet.
Versions
- #11.14.0latestOct 7, 2026
umbrielOpen in Codeg