Remote Pc Mcp

io.github.raghibrmv0.5.0更新於 Oct 8, 2026

Drive a PC over MCP: shell, files, processes, system stats, screenshots, mouse and keyboard.

概覽

AI 產生的概覽

讓助理透過 HTTP 遠端在 PC 上執行 shell 指令、管理檔案與行程、讀取系統資訊、截圖,並控制滑鼠與鍵盤。

功能
透過 streamable HTTP 把主機暴露給任何 MCP 用戶端。工具包括 shell_exec 執行任意指令、read_file、write_file、list_directory、system_info、start_process、get_process_output、kill_process、download_file、take_screenshot、click、move_mouse、type_text、press_key 與 scroll。每個請求都是自包含的,因此伺服器重啟不會中斷已連線的用戶端。
適用情境
適合從另一台機器遠端操作家用伺服器、桌上型電腦、建置機、媒體伺服器、工作站或樹莓派,讓代理執行指令、管理檔案、啟動背景工作、截圖並操作桌面介面。
執行需求
以本機 Python 3.10+ 行程執行,支援 Windows 10/11 或含 systemd 的 Linux,也可從 PyPI 安裝。需要 REMOTE_PC_MCP_TOKEN 環境變數,可選 REMOTE_PC_MCP_HOST 與 REMOTE_PC_MCP_PORT。介面工具需要互動式桌面工作階段;Linux 截圖需要 scrot、gnome-screenshot 或 ImageMagick import。用戶端透過 HTTP 攜帶 Bearer 權杖連線。
安裝前請注意
shell_exec 會以啟動伺服器的使用者身分執行任意指令,README 稱該 bearer 權杖等同 root 憑證。write_file、download_file、kill_process 與介面工具會變更主機。不要在沒有 TLS 與反向代理的情況下暴露到公網;在不受信任的網路上綁定 0.0.0.0 有風險。權杖應只放在 .env 中並當作密碼保管。

安裝

在 SourceWeft 中

  1. 開啟 儀表板中的 Remote Pc Mcp,將其新增到工作區。
  2. 為需要使用其工具的對話啟用該服務。

Desktop only,透過 STDIO。 STDIO 服務會啟動本機處理程序,因此需要 SourceWeft 桌面主機。

其他 MCP 客戶端

參照 儲存庫 中的啟動說明。

README

remote-pc-mcp

Expose any PC's capabilities — shell, filesystem, background processes, system stats, screenshots, UI control, and file transfer — to any MCP client (Claude Desktop, Claude Code, Cursor, Cline, Continue, Windsurf, custom agents — anything that speaks the Model Context Protocol) over streamable HTTP.

Drop it on any machine you want to drive remotely: a home server, a desktop, a build/CI box, a media server, a workstation, a Raspberry Pi. From a separate machine, your AI agent of choice can run commands on it, manage files, launch and monitor background jobs, take screenshots, and drive the desktop UI.

[remote-pc-mcp demo: an agent calling system_info, running a background job polled by PID, and taking a screenshot on a remote machine]

The transport is the mcp SDK's streamable HTTP (stateless_http=True), so a server restart does not break already-connected clients. Each request is self-contained — there is no in-memory session to go stale.

⚠️ shell_exec runs arbitrary commands on the host as the user that started the server. The bearer token is a root-equivalent credential. See Security before exposing the server.

Tools

ToolDescription
shell_execRun any shell command — returns stdout, stderr, exit code
read_fileRead a file as text or base64 (binary fallback)
write_fileWrite text or binary content to a file
list_directoryList files and directories, optionally recursive
system_infoOS, CPU, RAM, and GPU stats (NVIDIA GPUs via nvidia-smi; absent on non-GPU hosts)
start_processStart a long-running command in the background — returns a PID
get_process_outputPoll stdout/stderr of a background process by PID
kill_processTerminate a process by PID
download_fileDownload a URL directly to this machine
take_screenshotCapture the primary display — returns base64-encoded PNG
clickClick at screen coordinates (x, y) — left / right / middle, single or multi-click
move_mouseMove cursor to (x, y), optionally animated
type_textType a string into the focused window
press_keyPress a single key or hotkey combo (e.g. enter, f11, ctrl+c, win+d)
scrollScroll the mouse wheel up or down, optionally at a specific point

Requirements

  • Python 3.10+
  • Windows 10/11, or Linux with systemd (for autostart)

Install

On the machine you want to control:

bash
git clone https://github.com/raghibrm/remote-pc-mcpcd remote-pc-mcpcp .env.example .env

Set a strong token in .env:

REMOTE_PC_MCP_TOKEN=your-long-random-token-here

Generate one:

bash
# Windowspython -c "import secrets; print(secrets.token_hex(32))"
# Linux / macOSopenssl rand -hex 32

Then run the installer:

bash
# Windowsinstall.bat
# Linuxchmod +x install.sh./install.sh

That's it — one command. The installer:

  • installs Python dependencies
  • registers the server to launch hidden on every login (Startup-folder shortcut on Windows, systemd user unit on Linux)
  • starts it now
  • supervises it with exponential backoff on crash (5→10→20→40→60 seconds, resets after 5 minutes of uptime)
  • survives reboots — set once, runs forever

Verify it's up

bash
curl http://localhost:8765/health# {"status":"ok","server":"remote-pc-mcp","version":"0.5.0"}

When to rerun the installer

install.bat / install.sh are idempotent and self-healing. Rerun any time after:

  • You move the repo to a different folder
  • You reinstall or upgrade Python to a different path
  • You rebuild the machine and want to restore autostart

For day-to-day operation you never need to think about it.

After a reboot

Autostart fires when you sign in to Windows. A reboot that sits at the lock screen will NOT start the daemon until somebody logs in. This is intentional — enabling Windows auto-logon to make reboots fully hands-off would let anyone with physical access to the machine get a logged-in desktop, which is the wrong trade-off for a remote-control tool.

If you need to bring the daemon back up after a reboot without walking to the PC, sign in remotely via Remote Desktop or Tailscale SSH. Once you're logged in, the Startup shortcut fires and the daemon starts.

Linux is different: install.sh --linger runs sudo loginctl enable-linger $USER so the systemd user unit runs across reboots without any logon. systemd's user services don't share the auto-logon security problem because they don't grant interactive desktop access — they just keep your user-scoped daemons alive.

Uninstall

bash
# Windowsinstall.bat --uninstall
# Linux./install.sh --uninstall

Removes the autostart entry and stops the running server + supervisor.

Foreground run (development)

For a one-off run with visible console output and no autostart:

bash
python server.py

That's it — no special script. Use install.bat / install.sh for the normal supervised setup.

Or install from PyPI

bash
pip install remote-pc-mcpremote-pc-mcp          # run the server in the foregroundremote-pc-mcp-daemon   # supervised: restarts the server on crash

A pip install gives you the server and supervisor commands but does not register autostart. For autostart on sign-in, use the clone and install-script path above. .env, logs, and .state/ live in REMOTE_PC_MCP_HOME (default: the working directory).

Adding to your MCP client

Most MCP clients use the same JSON schema; the file just lives in different places. Example:

json
{  "mcpServers": {    "remote-pc": {      "type": "http",      "url": "http://YOUR_PC_IP_OR_HOSTNAME:8765/mcp",      "headers": {        "Authorization": "Bearer your-long-random-token-here"      }    }  }}

Where to put it:

ClientConfig file
Claude Code.mcp.json in the project root (or ~/.claude.json for user-wide)
Claude Desktopclaude_desktop_config.json (Settings → Developer → Edit Config)
Cursor.cursor/mcp.json
Cline / Continue / Windsurfeach has its own MCP servers panel — paste the JSON there
Custom agentswherever your agent reads MCP server definitions

For Tailscale users, the magic-DNS hostname works in the URL:

json
"url": "http://your-pc.tail12345.ts.net:8765/mcp"

Restart (or reload) your client. The tools appear automatically. The "remote-pc" key is just a label — pick whatever name you want.

Security

shell_exec runs any command on the host as the user that started the server. That is intentional — it is what makes the server useful for remote-driving a PC. It also means:

  • The bearer token is a root-equivalent credential. Generate a 32-byte hex token, store it only in .env (which is git-ignored), and treat it like a password.
  • Never expose the server to the public internet without TLS and a reverse proxy (nginx, Caddy, Cloudflare Tunnel).
  • Use Tailscale (strongly recommended): bind to your Tailscale IP (set REMOTE_PC_MCP_HOST=100.x.x.x in .env) so the listener is only reachable from devices in your tailnet.
  • LAN-only deployments with REMOTE_PC_MCP_HOST=0.0.0.0 are reasonable if you trust every device on the LAN and have a strong token. Don't do this on an untrusted network.

The token is compared with secrets.compare_digest (constant-time). All error messages pass through a sanitiser that strips absolute paths, the home directory, and the token before being returned to clients.

Configuration

All env vars are optional except REMOTE_PC_MCP_TOKEN.

VarDefaultDescription
REMOTE_PC_MCP_TOKEN(required)Bearer token clients must present
REMOTE_PC_MCP_HOST0.0.0.0Bind address. Set to a Tailscale IP to restrict reach
REMOTE_PC_MCP_PORT8765Listen port
REMOTE_PC_MCP_ALLOWED_HOSTS(empty)Comma-separated allowlist for DNS-rebinding protection. Empty disables it (default — wrong threat model on a tailnet)
REMOTE_PC_MCP_MAX_SHELL_TIMEOUT600 (s)Cap on per-call shell_exec timeout
REMOTE_PC_MCP_MAX_READ_BYTES50 MBread_file upper limit
REMOTE_PC_MCP_MAX_WRITE_BYTES50 MBwrite_file upper limit
REMOTE_PC_MCP_MAX_DOWNLOAD_BYTES2 GBdownload_file upper limit

After changing .env, restart the server so the new value takes effect:

bash
# Windows: easiest path is just re-run the installer (idempotent)install.bat --uninstall && install.bat
# Linuxsystemctl --user restart remote-pc-mcp

Logs and troubleshooting

Two log files in the repo root, both rotated automatically:

FileWhat's in itRotation
server.logApp events + uvicorn startup/access logs10 MB × 5
daemon.logSupervisor events (crashes, restarts, backoff)2 MB × 3

Server isn't responding?

bash
# Is the listener up locally?curl http://localhost:8765/health
# What's the supervisor seeing?tail -f daemon.log
# Linux: full journaljournalctl --user -u remote-pc-mcp -f
# Windows: is the autostart registered?explorer shell:startup    # look for remote-pc-mcp.lnk

MCP client says tools are missing after a server restart?

The streamable HTTP transport is designed so a restart does not brick clients, but the client still has to issue a request to notice the new server. First fix: invoke any tool from this server (e.g. ask your agent to run system_info) — the client will retry the connection. If that fails, reconnect the MCP server in your client (Claude Code: /mcp ; Cursor: refresh in MCP panel) or restart the client.

Stuck process / port already in use?

bash
# Windowsinstall.bat --uninstall && install.bat
# Linux./install.sh --uninstall && ./install.sh

UI-driving tools

take_screenshot, click, move_mouse, type_text, press_key, and scroll require an interactive desktop session:

  • Windows: a user must be logged in and the screen unlocked. A service running under Session 0 cannot reach the desktop. The Startup-folder install gives you exactly this — the daemon runs in your user session.
  • Linux: needs an X11 or Wayland session. For screenshots specifically, install scrot, gnome-screenshot, or ImageMagick's import — sudo apt install scrot is the easiest.

Development

Project layout:

FilePurpose
server.pyThe MCP server — tools, auth, transport
daemon.pySupervisor — spawns server, restarts on crash with backoff
_logging.pyShared logging config — one handler for app + uvicorn loggers
install.{bat,sh}Single entry point: default installs, --uninstall removes

Tests

A self-contained test suite under tests/ launches its own isolated server on a high port with an ephemeral token, exercises every tool, and verifies that a mid-run server restart does not lock the client out. It does not touch the production server you have running.

bash
pip install -r requirements-dev.txtpython -m pytest tests/ -v

License

MIT

來源:README.md,提交 9ce65db

工具

0
工具後設資料尚未被收錄。

版本歷史

1
  1. v0.5.0最新Oct 8, 2026