Skip to content
mcp/skillhub

Umbriel MCP Server

by obscuritysrlio.github.ObscuritySRL/umbrielv1.14.0

See and drive a whole Windows machine from Bun — apps, input, screen, OCR, registry, OS — via MCP.

2Node.jsstdioofficial registry

context tax

queued

security

queued

cold start

queued

freshness

Maintained55d ago

Install Umbriel MCP server

Install in Claude Code

claude mcp add umbriel -- npx -y umbriel

Configuration

VariableRequiredSecretDescription
UMBRIEL_PROFILE——Capability profile: 'readonly' (inspect/read only), 'safe' (read + input + window — default), or 'full' (also os + fs tools).
UMBRIEL_OS——Set to '1' to allow the 'os' tools (launch_app/run_program/open_path, kill_process, manage_process, control_service, set_env, registry_get/registry_list/registry_set) AND the 'fs' tools (read_file/write_file/list_dir/stat_path/make_dir/copy_file/move_file/delete_file) regardless of profile.
UMBRIEL_ALLOW——Comma-separated tool names or categories to additionally allow on top of the profile.
UMBRIEL_DENY——Comma-separated tool names or categories to deny, overriding the profile and UMBRIEL_ALLOW.
UMBRIEL_CURSOR——Set to 'never' to forbid the real-cursor fallback entirely (strictly cursor-free). By default clicks/drags are cursor-free but fall back to the real hardware cursor when no cursor-free path exists.
UMBRIEL_FS_ROOT——Sandbox root directory that the fs-category file tools (read_file/write_file/list_dir/stat_path/make_dir/copy_file/move_file/delete_file) are confined to when fs tools are enabled; open_path's path argument is honored too.
UMBRIEL_TRACE——File path to journal every mutating tool call as JSON Lines (tool, category, masked args, ok, observation); secret-bearing args and values are redacted. Unset = no trace.
UMBRIEL_FFI_TRACE——File path to a flush-before-call diagnostic journal of every COM vcall (slot, this-pointer, arg count). Each line is written and flushed to the OS BEFORE the native call, so after an uncatchable crash the last line names the faulting call. Has per-call overhead; unset = off. For debugging native faults only.
UMBRIEL_AUDIT——Controls the default-on stderr audit of mutating tool calls. 'off' is the explicit opt-out (reported at startup); 'verbose' also audits reads.
UMBRIEL_REDACT——Credential masking (default on). 'off' opts out; a regex value overrides the built-in secret shapes masked in clipboard/env/registry reads and the trace journal.

Freshness

Maintained — last maintenance signal 55d ago. The newest of the signals below sets the band.

  1. Last commit (default branch)

    2026-08-15 · 55d ago · GitHub

  2. Latest release

    no data · GitHub

  3. Package published

    no data · npm/PyPI

  4. Registry entry updated

    2026-06-27 · 4mo ago · official registry · v1.14.0

FAQ

›How do I install the Umbriel MCP server in Claude Code?

Run: claude mcp add umbriel -- npx -y umbriel. For Cursor, VS Code, Claude Desktop and Windsurf, use the install tabs above.

›Does Umbriel require an API key?

No required environment variables are declared in its published metadata.

›Can I use Umbriel as a remote (hosted) MCP server?

No hosted endpoint is published; it runs locally over stdio.

›Is Umbriel in the official MCP registry?

Yes, as io.github.ObscuritySRL/umbriel.