kasm-use

io.github.rchurrov0.3.1更新於 Oct 2, 2026

Computer-use for Kasm Workspaces: lets AI agents see and drive your Kasm desktops over KasmVNC.

概覽

AI 產生的概覽

讓 AI 助理啟動 Kasm Workspaces 桌面工作階段,並透過檢視截圖以及點擊、輸入、按鍵與捲動來操作它。

功能
kasm-use 為代理提供對 Kasm Workspaces 桌面的電腦操作能力。工具可以列出可啟動的工作區與執行中的工作階段、啟動工作區、取得即時截圖、依座標點擊、輸入文字、送出按鍵或快速鍵、捲動,以及銷毀工作階段(R22-R31)。它透過 Kasm API 與工作階段自身的 KasmVNC 連線驅動桌面,因此原版工作區映像即可使用,不需在映像內安裝任何東西(R5)。工作階段以你的 Kasm 使用者身分建立並顯示在儀表板中,你可以觀看或接手(R6、R7)。
適用情境
當你希望代理真正操作 Kasm 代管的桌面時使用,例如在一次性容器中驅動 Chrome、終端機或遊戲,而不只是管理工作階段(R3、R4、R14)。適合你自行掌控 Kasm 執行個體、並希望工作階段在 Kasm 儀表板中可見且可隨時接手的場景(R6、R8)。它仍是早期軟體,僅在 Kasm 1.19.0 上測試過,需要針對你的版本與安裝方式做驗證(R17-R19)。
執行需求
需要本機 Python 執行環境與 uv/uvx(Hermes 外掛用 pip),以及 Kasm Workspaces 1.19 或更新版本。必要的環境變數:KASM_API_URL、KASM_API_KEY、KASM_API_KEY_SECRET、KASM_USER_ID;選用 KASM_VERIFY_TLS,HTTP 模式下另有 KASM_USE_TOKEN。Kasm API 金鑰需要 Images View、User、Users Auth Session、Sessions View 與 Sessions Delete 權限(R33、R35-R38、R47-R51)。
安裝前請注意
KASM_API_KEY 與 KASM_API_KEY_SECRET 是伺服器層級的管理憑證:持有者可以觸及所有 Kasm 使用者,因此只能在可信任的機器上執行(R74、R83)。代理會操作真實桌面,請使用一次性工作區,避免使用已登入真實帳號的工作階段,並留意所造訪網頁的提示注入(R66、R67)。工具描述要求模型不要輸入密碼、MFA 驗證碼或付款資訊,但這只是提示,並非強制(R71、R97)。HTTP 模式下,任何持有 KASM_USE_TOKEN 的人都能操控你的桌面,應僅限私有網路(R61、R62)。

安裝

在 SourceWeft 中

  1. 開啟 儀表板中的 kasm-use,將其新增到工作區。
  2. 為需要使用其工具的對話啟用該服務。

Desktop only,透過 STDIO。 STDIO 服務會啟動本機處理程序,因此需要 SourceWeft 桌面主機。

其他 MCP 客戶端

參照 儲存庫 中的啟動說明。

README

kasm-use

Let an AI agent use a Kasm Workspaces desktop: start a session, look at the screen, click, type, press keys, scroll, and stop it — in plain language, from any MCP client (Claude Code, Claude Desktop, OpenCode, Cursor, …) or as a native Hermes Agent plugin.

Other Kasm MCP servers manage sessions (start, list, stop). kasm-use actually uses them: the agent sees the desktop and operates it, like computer-use or browser-use, inside your Kasm.

  • Works with stock Kasm images. Nothing is baked into the workspace; it drives the desktop through Kasm's API and the session's own KasmVNC connection.
  • You can watch and take over. Sessions are created as your Kasm user, so they show up in your Kasm dashboard. Open one to watch the agent work, or to handle a login or CAPTCHA yourself.
  • Your Kasm, your key. You run the server next to your own Kasm. Nothing goes through a third party.

What's Kasm?

Kasm Workspaces streams disposable desktops and apps to your web browser, each running in its own container on a server you control. Click "Chrome" and you get a fresh Chrome in a browser tab; close it and it's wiped. kasm-use lets an AI agent sit down at those desktops and use them the way a person would.

[Demo: Hermes Agent runs three Kasm sessions in parallel with kasm-use (Chrome, Terminal, Minetest) while the dashboard shows them live]

Demo (3x speed): Hermes Agent runs a three-session demo with kasm-use. Chrome, Terminal and Minetest are started and driven in parallel while the Kasm dashboard shows each one live.

How the pieces connect:

mermaid
flowchart LR    agent["AI agent<br/>(any MCP client or Hermes)"] -->|"tool calls:<br/>look, click, type"| ku["kasm-use"]    ku -->|"start / list / stop<br/>(API key)"| api["Kasm API"]    api -->|"starts container"| desk    ku -->|"screenshots + input<br/>(VNC over websocket)"| proxy["Kasm proxy"]    you["You, in the<br/>Kasm dashboard"] -->|"watch or take over"| proxy    proxy --> desk["Session desktop<br/>(KasmVNC in a container)"]

Status: early — testers wanted

kasm-use works well on the setup it was built on (Kasm 1.19.0 in linuxserver's Docker image; Chrome, Terminal and Minetest workspaces; Claude Code and Hermes Agent as clients). It talks to parts of Kasm that aren't documented, so other versions and install types are the big unknown. If you try it, please open an issue, whether it worked or not: your Kasm version, how Kasm is installed, the workspace image and your MCP client are the most useful details.

Tools

ToolWhat it does
kasm_listWorkspaces you can start, and your running sessions
kasm_startStart a workspace (e.g. Chrome); returns once the session is running
kasm_lookLive screenshot of the session, returned as an image (~1 s)
kasm_clickClick at x,y in the latest screenshot's coordinates
kasm_typeType text into the focused field
kasm_keyKeys/shortcuts, e.g. ctrl+l, Return, Tab
kasm_scrollScroll, optionally at a point
kasm_stopDestroy the session

Requirements

  • Kasm Workspaces 1.19 or newer (tested on 1.19.0).

  • A Kasm API key: Admin → Settings → Developers → API Keys → Add, then edit its permissions. kasm-use 0.3 needs exactly these five (tested end to end with a key that has only these):

    • Images View, User, Users Auth Session — starting sessions (without them kasm_start fails with Unauthorized).
    • Sessions View — session status and kasm_list.
    • Sessions Delete — kasm_stop.

    It no longer calls Kasm's exec API (Sessions Modify) or screenshot API (Session Recordings View), so you can remove those if you granted them for 0.2 or earlier. A missing permission shows up as Unauthorized from the tool that needs it. Read Security model first: these permissions are server-wide.

  • Your Kasm user ID, so sessions belong to you: Admin → Access Management → Users → open your user; the ID is in the page URL.

  • Any workspace image. Nothing is installed in the session for sessions kasm-use starts.

Configuration

VariableRequiredMeaning
KASM_API_URLyese.g. https://kasm.example.com
KASM_API_KEY / KASM_API_KEY_SECRETyesthe API key pair
KASM_USER_IDyesthe Kasm user sessions are created for
KASM_VERIFY_TLSnofalse to accept a self-signed Kasm certificate (default true)
KASM_USE_TOKENHTTP onlybearer token clients must send

Run it

Locally (stdio) — the usual way

Your MCP client starts the server itself. With uv installed:

json
{  "mcpServers": {    "kasm": {      "command": "uvx",      "args": ["kasm-use"],      "env": {        "KASM_API_URL": "https://kasm.example.com",        "KASM_API_KEY": "…",        "KASM_API_KEY_SECRET": "…",        "KASM_USER_ID": "…"      }    }  }}

Claude Code:

bash
claude mcp add kasm -e KASM_API_URL=https://kasm.example.com -e KASM_API_KEY=… -e KASM_API_KEY_SECRET=… -e KASM_USER_ID=… -- uvx kasm-use

As a service (streamable HTTP)

bash
docker run -d -p 8000:8000 \  -e KASM_API_URL=https://kasm.example.com -e KASM_API_KEY=… -e KASM_API_KEY_SECRET=… \  -e KASM_USER_ID=… -e KASM_USE_TOKEN="$(openssl rand -hex 32)" \  ghcr.io/rchurro/kasm-use:latest

Clients connect to http://host:8000/mcp with the header Authorization: Bearer <KASM_USE_TOKEN>. Health check: GET /healthz. Run one replica per Kasm user: the server remembers each session's last screenshot size in memory to map click coordinates.

Keep it on a private network (LAN, VPN, Tailscale). Anyone with the token can drive your desktops.

Hermes Agent

bash
pip install kasm-use                      # into Hermes's Python environmentcp -r hermes-plugin/kasm ~/.hermes/plugins/kasm

Enable kasm under plugins.enabled, set the environment variables above, and start a new Hermes session (/new) so the tools load.

Safety

An agent with these tools drives a real desktop on your network, so treat it like handing someone your mouse and keyboard.

  • Use throwaway workspaces. Don't let the agent work in a session that's logged into your real accounts, and don't save passwords in workspace images it uses.
  • Web pages can talk to the agent. Text on a page it visits can try to steer it (prompt injection). Keep a human watching for anything that matters.
  • Traffic comes from your network. Whatever the agent browses comes from your Kasm host's IP address. Kasm's per-workspace VPN/egress settings can route it elsewhere.
  • The tool descriptions tell the agent never to type passwords, MFA codes or payment details and to hand CAPTCHAs to you, but that is guidance to the model, not enforcement.

Security model

Two Kasm facts shape what kasm-use can and can't promise:

  • A Kasm API key is server-wide, not per user. Kasm has no way to limit a key to one user. With the permissions above it can see and stop any user's sessions, and Users Auth Session ("login on behalf of another user") lets it get a login for any user.
  • The token request_kasm returns is a login for KASM_USER_ID, not for one session. It opens every session that user has (verified on Kasm 1.19.0: a token from one session opened another session of the same user over VNC).

So the boundary is kasm-use itself:

  • Every tool only acts on sessions this kasm-use process started. Any other session_id (yours, another user's, one from before a restart) is refused, including for kasm_look and kasm_stop. kasm_list only shows kasm-use's own sessions.
  • The model never sees the API key or any token, only the eight tools.
  • No exec, no screenshot API. kasm-use doesn't use Kasm's exec API (which can run commands in a session as root) or its screenshot API, so it doesn't need those permissions.

What that means for you:

  • Treat the API key like an admin credential, and run kasm-use only on a machine you trust. Anyone who gets the key gets your Kasm, whatever kasm-use's code does.
  • Give the agent its own Kasm user and set KASM_USER_ID to it. That keeps the agent's sessions and tokens away from your own sessions if something goes wrong in kasm-use. (It is a seatbelt, not a wall: the key itself can still reach every user.)
  • Kasm's disposability helps, but only so much. Sessions are thrown away when they end (unless you enable persistent profiles), so nothing an agent does survives the session. The exposure is in sessions that are still running: one that's logged into an account, or that you're working in.
  • There's no per-action policy yet (rate limits, blocked keys, "ask the human first"). Input goes straight to VNC once the scope check passes. VNC only sees pixels and keystrokes, so rules like "never type into this window" can't be enforced at this layer.

Limitations

  • Only sessions kasm-use started, and only until it restarts. The session tokens live in memory. After a restart, earlier sessions keep running in Kasm but kasm-use won't touch them; stop them from the Kasm dashboard.
  • Input reports "sent", not "succeeded". The next screenshot is the confirmation.
  • CAPTCHAs, passwords, MFA and payments are handed to you. The tool descriptions tell the agent never to type them; open the session in Kasm and take over.
  • It's slow compared to a local browser tool: every step is a screenshot round trip.

How it works

kasm-use talks to each session's KasmVNC server directly, through Kasm's own proxy (wss://<kasm>/desktop/<id>/vnc/websockify), with the login token request_kasm returns. The VNC client is built in and uses only the Python standard library.

  • Eyes: a full framebuffer read over VNC (ZRLE, decoded with zlib), returned as PNG. Kasm's screenshot API isn't used for these sessions: it only refreshes while a viewer is connected, so with nobody watching it returns stale frames.
  • Hands: VNC pointer and key events. KasmVNC's pointer message is 11 bytes (16-bit button mask plus scroll deltas), not standard RFB's 6.
  • Clicks are given in screenshot pixels and scaled to the desktop's current size, which VNC reports on connect — it changes when someone opens the session and Kasm resizes it to their window.
  • Each tool call opens a short VNC connection and does a round trip before closing, so no input is lost on disconnect. The owner can stay connected at the same time.

What this relies on. None of this is an official Kasm API; it's how Kasm's own web viewer connects, observed on Kasm 1.19.0:

  • Kasm's proxy accepts the username + session_token cookies that request_kasm returns, and requires an Origin header matching the Kasm host.
  • Behind the proxy, KasmVNC offers VNC authentication and accepts an empty password (the proxy has already authenticated you).
  • KasmVNC's pointer message is 11 bytes (visible in its open-source web client).

A Kasm update or a different install type could change any of these. If kasm-use stops connecting, that's the likely cause, and an issue with your Kasm version and install type helps.

License

MIT

來源:README.md,提交 97c017d

工具

0
工具後設資料尚未被收錄。

版本歷史

1
  1. v0.3.1最新Oct 2, 2026