
Remote Pc Mcp
io.github.raghibrmv0.5.0更新於 Oct 8, 2026
Drive a PC over MCP: shell, files, processes, system stats, screenshots, mouse and keyboard.
概覽
讓助理透過 HTTP 遠端在 PC 上執行 shell 指令、管理檔案與行程、讀取系統資訊、截圖,並控制滑鼠與鍵盤。
- 功能
- 透過 streamable HTTP 把主機暴露給任何 MCP 用戶端。工具包括 shell_exec 執行任意指令、read_file、write_file、list_directory、system_info、start_process、get_process_output、kill_process、download_file、take_screenshot、click、move_mouse、type_text、press_key 與 scroll。每個請求都是自包含的,因此伺服器重啟不會中斷已連線的用戶端。
- 適用情境
- 適合從另一台機器遠端操作家用伺服器、桌上型電腦、建置機、媒體伺服器、工作站或樹莓派,讓代理執行指令、管理檔案、啟動背景工作、截圖並操作桌面介面。
- 執行需求
- 以本機 Python 3.10+ 行程執行,支援 Windows 10/11 或含 systemd 的 Linux,也可從 PyPI 安裝。需要 REMOTE_PC_MCP_TOKEN 環境變數,可選 REMOTE_PC_MCP_HOST 與 REMOTE_PC_MCP_PORT。介面工具需要互動式桌面工作階段;Linux 截圖需要 scrot、gnome-screenshot 或 ImageMagick import。用戶端透過 HTTP 攜帶 Bearer 權杖連線。
安裝
在 SourceWeft 中
- 開啟 儀表板中的 Remote Pc Mcp,將其新增到工作區。
- 為需要使用其工具的對話啟用該服務。
Desktop only,透過 STDIO。 STDIO 服務會啟動本機處理程序,因此需要 SourceWeft 桌面主機。
其他 MCP 客戶端
參照 儲存庫 中的啟動說明。
README
remote-pc-mcp
Expose any PC's capabilities — shell, filesystem, background processes, system stats, screenshots, UI control, and file transfer — to any MCP client (Claude Desktop, Claude Code, Cursor, Cline, Continue, Windsurf, custom agents — anything that speaks the Model Context Protocol) over streamable HTTP.
Drop it on any machine you want to drive remotely: a home server, a desktop, a build/CI box, a media server, a workstation, a Raspberry Pi. From a separate machine, your AI agent of choice can run commands on it, manage files, launch and monitor background jobs, take screenshots, and drive the desktop UI.
The transport is the mcp SDK's streamable HTTP (stateless_http=True), so a server restart does not break already-connected clients. Each request is self-contained — there is no in-memory session to go stale.
⚠️
shell_execruns arbitrary commands on the host as the user that started the server. The bearer token is a root-equivalent credential. See Security before exposing the server.
Tools
Requirements
- Python 3.10+
- Windows 10/11, or Linux with systemd (for autostart)
Install
On the machine you want to control:
Set a strong token in .env:
Generate one:
Then run the installer:
That's it — one command. The installer:
- installs Python dependencies
- registers the server to launch hidden on every login (Startup-folder shortcut on Windows, systemd user unit on Linux)
- starts it now
- supervises it with exponential backoff on crash (5→10→20→40→60 seconds, resets after 5 minutes of uptime)
- survives reboots — set once, runs forever
Verify it's up
When to rerun the installer
install.bat / install.sh are idempotent and self-healing. Rerun any time after:
- You move the repo to a different folder
- You reinstall or upgrade Python to a different path
- You rebuild the machine and want to restore autostart
For day-to-day operation you never need to think about it.
After a reboot
Autostart fires when you sign in to Windows. A reboot that sits at the lock screen will NOT start the daemon until somebody logs in. This is intentional — enabling Windows auto-logon to make reboots fully hands-off would let anyone with physical access to the machine get a logged-in desktop, which is the wrong trade-off for a remote-control tool.
If you need to bring the daemon back up after a reboot without walking to the PC, sign in remotely via Remote Desktop or Tailscale SSH. Once you're logged in, the Startup shortcut fires and the daemon starts.
Linux is different: install.sh --linger runs sudo loginctl enable-linger $USER so the systemd user unit runs across reboots without any logon. systemd's user services don't share the auto-logon security problem because they don't grant interactive desktop access — they just keep your user-scoped daemons alive.
Uninstall
Removes the autostart entry and stops the running server + supervisor.
Foreground run (development)
For a one-off run with visible console output and no autostart:
That's it — no special script. Use install.bat / install.sh for the normal supervised setup.
Or install from PyPI
A pip install gives you the server and supervisor commands but does not register autostart. For autostart on sign-in, use the clone and install-script path above. .env, logs, and .state/ live in REMOTE_PC_MCP_HOME (default: the working directory).
Adding to your MCP client
Most MCP clients use the same JSON schema; the file just lives in different places. Example:
Where to put it:
For Tailscale users, the magic-DNS hostname works in the URL:
Restart (or reload) your client. The tools appear automatically. The "remote-pc" key is just a label — pick whatever name you want.
Security
shell_exec runs any command on the host as the user that started the server. That is intentional — it is what makes the server useful for remote-driving a PC. It also means:
- The bearer token is a root-equivalent credential. Generate a 32-byte hex token, store it only in
.env(which is git-ignored), and treat it like a password. - Never expose the server to the public internet without TLS and a reverse proxy (nginx, Caddy, Cloudflare Tunnel).
- Use Tailscale (strongly recommended): bind to your Tailscale IP (set
REMOTE_PC_MCP_HOST=100.x.x.xin.env) so the listener is only reachable from devices in your tailnet. - LAN-only deployments with
REMOTE_PC_MCP_HOST=0.0.0.0are reasonable if you trust every device on the LAN and have a strong token. Don't do this on an untrusted network.
The token is compared with secrets.compare_digest (constant-time). All error messages pass through a sanitiser that strips absolute paths, the home directory, and the token before being returned to clients.
Configuration
All env vars are optional except REMOTE_PC_MCP_TOKEN.
After changing .env, restart the server so the new value takes effect:
Logs and troubleshooting
Two log files in the repo root, both rotated automatically:
Server isn't responding?
MCP client says tools are missing after a server restart?
The streamable HTTP transport is designed so a restart does not brick clients, but the client still has to issue a request to notice the new server. First fix: invoke any tool from this server (e.g. ask your agent to run system_info) — the client will retry the connection. If that fails, reconnect the MCP server in your client (Claude Code: /mcp ; Cursor: refresh in MCP panel) or restart the client.
Stuck process / port already in use?
UI-driving tools
take_screenshot, click, move_mouse, type_text, press_key, and scroll require an interactive desktop session:
- Windows: a user must be logged in and the screen unlocked. A service running under Session 0 cannot reach the desktop. The Startup-folder install gives you exactly this — the daemon runs in your user session.
- Linux: needs an X11 or Wayland session. For screenshots specifically, install
scrot,gnome-screenshot, or ImageMagick'simport—sudo apt install scrotis the easiest.
Development
Project layout:
Tests
A self-contained test suite under tests/ launches its own isolated server on a high port with an ephemeral token, exercises every tool, and verifies that a mid-run server restart does not lock the client out. It does not touch the production server you have running.
License
MIT
來源:README.md,提交 9ce65db
工具
0版本歷史
1- v0.5.0最新Oct 8, 2026


