Safe cross-OS desktop control for any AI agent - the fallback execution layer.
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β or use 1-click editor setup below.
One-click editor setup isnβt available for this listing yet β we donβt have a confirmed install command, and weβd rather show nothing than point your editor at the wrong package or host. Follow the projectβs own setup instructions, linked above.
Safe desktop control for any AI agent. Compiles the screen into a UI map and acts on elements by stable id (screenshot/vision only as a last resort),
verifies its own actions, and gates everything through one safety checkpoint. Local Β· cross-OS Β· any model.
Quickstart Β· Why it's different Β· The engine Β· How it works Β· Tools Β· Platforms Β· Changelog
Clawd Cursor is a local MCP server that gives any tool-calling agent β Claude Code, Cursor, Windsurf, OpenClaw, the Claude Agent SDK, or your own loop β safe control of the real desktop. It clicks, types, reads the screen, opens apps, and drives any GUI the way a human would: native apps, the browser, even a canvas.
Most "let an agent use the computer" tools take a screenshot and feed it to a vision model β slow, expensive, and brittle. Clawd Cursor compiles the screen into one UI map: it fuses the accessibility tree and OCR into a confidence-scored set of elements, each tagged with a stable el_NN id, and acts on elements by id β not pixel coordinates. Coordinates appear only in the last-resort screenshot/vision tier (live pixels off the current frame), for canvas-only apps or tasks that genuinely need spatial reasoning. The result is cheaper, faster, private, and β uniquely β it checks that each action actually did what it claimed.
If a human can do it on a screen, your agent can too. No API, no integration, no problem β only the right sequence of reads, clicks, keys, and waits. Use it as the last-mile fallback: native API exists? Use it. CLI? Use it. Clawd Cursor is for the click, the legacy app, the GUI with no public surface.
The desktop-agent space is crowded. The closest install-and-go peers are Windows-MCP and Terminator (desktop MCP servers); browser-only tools (browser-use, Playwright MCP) are adjacent; and OmniParser / UI-TARS are vision-centric parsing approaches you'd build an agent around, not products you install. Here's the honest comparison across those approaches β what Clawd Cursor does that the popular options don't:
| Clawd Cursor | browser-use | Playwright MCP | OmniParser / UI-TARS | computer-use | |
|---|---|---|---|---|---|
| Any desktop app, not just the web | β | web only | web only | β | β |
| Cross-OS (Windows + macOS + Linux) | β | β | β | varies | sandbox |
| Perception without a vision model | β compiled a11y + OCR map | DOM | a11y tree | β vision-centric | β vision |
| Verifies its own actions (deviation) | β | β | β | β | β |
| Single safety chokepoint (allow/confirm/block) | β | β | β | β | β |
| Any model / vendor | β | β | not an agent | model-specific | Claude only |
| MCP-native (one config, any host) | β | library | test framework | β | tool-use API |
| Local-only, no cloud required | β | β | β | needs a model | screens β cloud |
Three things here are genuinely rare:
expect on a consequential action and Clawd Cursor re-checks the live screen (with a short settle window for async UIs) and reports a DEVIATION instead of a hollow "success." A completed task can't be marked done on evidence that was already true before it acted.safety.evaluate() chokepoint (allow / confirm / block) before it touches the desktop. The agent cannot bypass it.Plus: an on-screen "desktop control in progress" banner with a blinking red dot whenever an agent is driving β double-click it to stop. A human at the machine always knows, and always has a kill switch.
clawdcursor is an MCP server published to npm β install it into any MCP-capable agent (Claude Code, Claude Desktop, Cursor, Windsurf, Zed, OpenAI Codex, or your own loop) the same way you install any other MCP server.
Zero-install also works β swap
clawdcursorfornpx -y clawdcursorin any snippet below and npx fetches it on demand. A global install is recommended anyway: it's pinnable and inspectable on disk (safer for a tool with full desktop control than auto-fetchinglatestevery run), and it's the path on which the macOS native helper builds at install time. Requires Node.js 20+.
Per-OS prerequisites. Windows installs clean β
sharpand@nut-tree-fork/nut-jsship prebuilt binaries, so no C++/Python build tools are needed. macOS needs Xcode Command Line Tools (xcode-select --install) for screenshots / vision; core accessibility-driven control still works without them. Linux needs a few system packages npm can't install:tesseract-ocr(OCR),python3-gi+gir1.2-atspi-2.0(accessibility tree), and β on Wayland βydotool(synthetic input).
One click, if your host supports it:
These hand the host the npx config below, so they work with or without a global
install. Everything that follows is the same thing done by hand, per host.
Claude Code
OpenAI Codex β add to ~/.codex/config.toml:
Cursor / Windsurf / Claude Desktop β add to the host's MCP config:
Zed β Zed uses context_servers (not mcpServers) in settings.json:
No reviews yet β be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/clawdcursor)<a href="https://allmcps.com/mcp/clawdcursor"><img src="https://allmcps.com/api/badge/clawdcursor?style=directory" alt="Clawdcursor on AllMCPs" /></a>