Remote Pc Mcp

io.github.raghibrmv0.5.0更新于 Oct 8, 2026

Drive a PC over MCP: shell, files, processes, system stats, screenshots, mouse and keyboard.

概览

AI 生成的概览

让助手通过 HTTP 远程在 PC 上执行 shell 命令、管理文件与进程、读取系统信息、截图,并控制鼠标和键盘。

功能
通过 streamable HTTP 把主机暴露给任意 MCP 客户端。工具包括 shell_exec 执行任意命令、read_file、write_file、list_directory、system_info、start_process、get_process_output、kill_process、download_file、take_screenshot、click、move_mouse、type_text、press_key 和 scroll。每个请求都是自包含的,因此服务器重启不会中断已连接的客户端。
适用场景
适合从另一台机器远程操作家庭服务器、台式机、构建机、媒体服务器、工作站或树莓派,让代理运行命令、管理文件、启动后台任务、截图并操作桌面界面。
运行要求
作为本地 Python 3.10+ 进程运行,支持 Windows 10/11 或带 systemd 的 Linux,也可从 PyPI 安装。需要 REMOTE_PC_MCP_TOKEN 环境变量,可选 REMOTE_PC_MCP_HOST 和 REMOTE_PC_MCP_PORT。界面工具需要交互式桌面会话;Linux 截图需要 scrot、gnome-screenshot 或 ImageMagick import。客户端通过 HTTP 携带 Bearer 令牌连接。
安装前请注意
shell_exec 会以启动服务器的用户身份执行任意命令,README 称该 bearer 令牌等同于 root 凭据。write_file、download_file、kill_process 和界面工具会改动主机。不要在无 TLS 和反向代理的情况下暴露到公网;在不可信网络上绑定 0.0.0.0 有风险。令牌应只放在 .env 中并当作密码保管。

安装

在 SourceWeft 中

  1. 打开 控制台中的 Remote Pc Mcp,将其添加到工作区。
  2. 为需要使用其工具的对话启用该服务。

Desktop only,通过 STDIO。 STDIO 服务会启动本地进程,因此需要 SourceWeft 桌面宿主。

其他 MCP 客户端

参照 仓库 中的启动说明。

README

remote-pc-mcp

Expose any PC's capabilities — shell, filesystem, background processes, system stats, screenshots, UI control, and file transfer — to any MCP client (Claude Desktop, Claude Code, Cursor, Cline, Continue, Windsurf, custom agents — anything that speaks the Model Context Protocol) over streamable HTTP.

Drop it on any machine you want to drive remotely: a home server, a desktop, a build/CI box, a media server, a workstation, a Raspberry Pi. From a separate machine, your AI agent of choice can run commands on it, manage files, launch and monitor background jobs, take screenshots, and drive the desktop UI.

[remote-pc-mcp demo: an agent calling system_info, running a background job polled by PID, and taking a screenshot on a remote machine]

The transport is the mcp SDK's streamable HTTP (stateless_http=True), so a server restart does not break already-connected clients. Each request is self-contained — there is no in-memory session to go stale.

⚠️ shell_exec runs arbitrary commands on the host as the user that started the server. The bearer token is a root-equivalent credential. See Security before exposing the server.

Tools

ToolDescription
shell_execRun any shell command — returns stdout, stderr, exit code
read_fileRead a file as text or base64 (binary fallback)
write_fileWrite text or binary content to a file
list_directoryList files and directories, optionally recursive
system_infoOS, CPU, RAM, and GPU stats (NVIDIA GPUs via nvidia-smi; absent on non-GPU hosts)
start_processStart a long-running command in the background — returns a PID
get_process_outputPoll stdout/stderr of a background process by PID
kill_processTerminate a process by PID
download_fileDownload a URL directly to this machine
take_screenshotCapture the primary display — returns base64-encoded PNG
clickClick at screen coordinates (x, y) — left / right / middle, single or multi-click
move_mouseMove cursor to (x, y), optionally animated
type_textType a string into the focused window
press_keyPress a single key or hotkey combo (e.g. enter, f11, ctrl+c, win+d)
scrollScroll the mouse wheel up or down, optionally at a specific point

Requirements

  • Python 3.10+
  • Windows 10/11, or Linux with systemd (for autostart)

Install

On the machine you want to control:

bash
git clone https://github.com/raghibrm/remote-pc-mcpcd remote-pc-mcpcp .env.example .env

Set a strong token in .env:

REMOTE_PC_MCP_TOKEN=your-long-random-token-here

Generate one:

bash
# Windowspython -c "import secrets; print(secrets.token_hex(32))"
# Linux / macOSopenssl rand -hex 32

Then run the installer:

bash
# Windowsinstall.bat
# Linuxchmod +x install.sh./install.sh

That's it — one command. The installer:

  • installs Python dependencies
  • registers the server to launch hidden on every login (Startup-folder shortcut on Windows, systemd user unit on Linux)
  • starts it now
  • supervises it with exponential backoff on crash (5→10→20→40→60 seconds, resets after 5 minutes of uptime)
  • survives reboots — set once, runs forever

Verify it's up

bash
curl http://localhost:8765/health# {"status":"ok","server":"remote-pc-mcp","version":"0.5.0"}

When to rerun the installer

install.bat / install.sh are idempotent and self-healing. Rerun any time after:

  • You move the repo to a different folder
  • You reinstall or upgrade Python to a different path
  • You rebuild the machine and want to restore autostart

For day-to-day operation you never need to think about it.

After a reboot

Autostart fires when you sign in to Windows. A reboot that sits at the lock screen will NOT start the daemon until somebody logs in. This is intentional — enabling Windows auto-logon to make reboots fully hands-off would let anyone with physical access to the machine get a logged-in desktop, which is the wrong trade-off for a remote-control tool.

If you need to bring the daemon back up after a reboot without walking to the PC, sign in remotely via Remote Desktop or Tailscale SSH. Once you're logged in, the Startup shortcut fires and the daemon starts.

Linux is different: install.sh --linger runs sudo loginctl enable-linger $USER so the systemd user unit runs across reboots without any logon. systemd's user services don't share the auto-logon security problem because they don't grant interactive desktop access — they just keep your user-scoped daemons alive.

Uninstall

bash
# Windowsinstall.bat --uninstall
# Linux./install.sh --uninstall

Removes the autostart entry and stops the running server + supervisor.

Foreground run (development)

For a one-off run with visible console output and no autostart:

bash
python server.py

That's it — no special script. Use install.bat / install.sh for the normal supervised setup.

Or install from PyPI

bash
pip install remote-pc-mcpremote-pc-mcp          # run the server in the foregroundremote-pc-mcp-daemon   # supervised: restarts the server on crash

A pip install gives you the server and supervisor commands but does not register autostart. For autostart on sign-in, use the clone and install-script path above. .env, logs, and .state/ live in REMOTE_PC_MCP_HOME (default: the working directory).

Adding to your MCP client

Most MCP clients use the same JSON schema; the file just lives in different places. Example:

json
{  "mcpServers": {    "remote-pc": {      "type": "http",      "url": "http://YOUR_PC_IP_OR_HOSTNAME:8765/mcp",      "headers": {        "Authorization": "Bearer your-long-random-token-here"      }    }  }}

Where to put it:

ClientConfig file
Claude Code.mcp.json in the project root (or ~/.claude.json for user-wide)
Claude Desktopclaude_desktop_config.json (Settings → Developer → Edit Config)
Cursor.cursor/mcp.json
Cline / Continue / Windsurfeach has its own MCP servers panel — paste the JSON there
Custom agentswherever your agent reads MCP server definitions

For Tailscale users, the magic-DNS hostname works in the URL:

json
"url": "http://your-pc.tail12345.ts.net:8765/mcp"

Restart (or reload) your client. The tools appear automatically. The "remote-pc" key is just a label — pick whatever name you want.

Security

shell_exec runs any command on the host as the user that started the server. That is intentional — it is what makes the server useful for remote-driving a PC. It also means:

  • The bearer token is a root-equivalent credential. Generate a 32-byte hex token, store it only in .env (which is git-ignored), and treat it like a password.
  • Never expose the server to the public internet without TLS and a reverse proxy (nginx, Caddy, Cloudflare Tunnel).
  • Use Tailscale (strongly recommended): bind to your Tailscale IP (set REMOTE_PC_MCP_HOST=100.x.x.x in .env) so the listener is only reachable from devices in your tailnet.
  • LAN-only deployments with REMOTE_PC_MCP_HOST=0.0.0.0 are reasonable if you trust every device on the LAN and have a strong token. Don't do this on an untrusted network.

The token is compared with secrets.compare_digest (constant-time). All error messages pass through a sanitiser that strips absolute paths, the home directory, and the token before being returned to clients.

Configuration

All env vars are optional except REMOTE_PC_MCP_TOKEN.

VarDefaultDescription
REMOTE_PC_MCP_TOKEN(required)Bearer token clients must present
REMOTE_PC_MCP_HOST0.0.0.0Bind address. Set to a Tailscale IP to restrict reach
REMOTE_PC_MCP_PORT8765Listen port
REMOTE_PC_MCP_ALLOWED_HOSTS(empty)Comma-separated allowlist for DNS-rebinding protection. Empty disables it (default — wrong threat model on a tailnet)
REMOTE_PC_MCP_MAX_SHELL_TIMEOUT600 (s)Cap on per-call shell_exec timeout
REMOTE_PC_MCP_MAX_READ_BYTES50 MBread_file upper limit
REMOTE_PC_MCP_MAX_WRITE_BYTES50 MBwrite_file upper limit
REMOTE_PC_MCP_MAX_DOWNLOAD_BYTES2 GBdownload_file upper limit

After changing .env, restart the server so the new value takes effect:

bash
# Windows: easiest path is just re-run the installer (idempotent)install.bat --uninstall && install.bat
# Linuxsystemctl --user restart remote-pc-mcp

Logs and troubleshooting

Two log files in the repo root, both rotated automatically:

FileWhat's in itRotation
server.logApp events + uvicorn startup/access logs10 MB × 5
daemon.logSupervisor events (crashes, restarts, backoff)2 MB × 3

Server isn't responding?

bash
# Is the listener up locally?curl http://localhost:8765/health
# What's the supervisor seeing?tail -f daemon.log
# Linux: full journaljournalctl --user -u remote-pc-mcp -f
# Windows: is the autostart registered?explorer shell:startup    # look for remote-pc-mcp.lnk

MCP client says tools are missing after a server restart?

The streamable HTTP transport is designed so a restart does not brick clients, but the client still has to issue a request to notice the new server. First fix: invoke any tool from this server (e.g. ask your agent to run system_info) — the client will retry the connection. If that fails, reconnect the MCP server in your client (Claude Code: /mcp ; Cursor: refresh in MCP panel) or restart the client.

Stuck process / port already in use?

bash
# Windowsinstall.bat --uninstall && install.bat
# Linux./install.sh --uninstall && ./install.sh

UI-driving tools

take_screenshot, click, move_mouse, type_text, press_key, and scroll require an interactive desktop session:

  • Windows: a user must be logged in and the screen unlocked. A service running under Session 0 cannot reach the desktop. The Startup-folder install gives you exactly this — the daemon runs in your user session.
  • Linux: needs an X11 or Wayland session. For screenshots specifically, install scrot, gnome-screenshot, or ImageMagick's import — sudo apt install scrot is the easiest.

Development

Project layout:

FilePurpose
server.pyThe MCP server — tools, auth, transport
daemon.pySupervisor — spawns server, restarts on crash with backoff
_logging.pyShared logging config — one handler for app + uvicorn loggers
install.{bat,sh}Single entry point: default installs, --uninstall removes

Tests

A self-contained test suite under tests/ launches its own isolated server on a high port with an ephemeral token, exercises every tool, and verifies that a mid-run server restart does not lock the client out. It does not touch the production server you have running.

bash
pip install -r requirements-dev.txtpython -m pytest tests/ -v

License

MIT

来源:README.md,提交 9ce65db

工具

0
工具元数据尚未被收录。

版本历史

1
  1. v0.5.0最新Oct 8, 2026