---
bezeichner: "io.github.IlyasKhallouki/hypruse"
art: "mcp_server"
slug: "io-github-ilyaskhallouki-hypruse"
paketkoordinate: "pypi:hypruse"
status: "aktiv"
homepage: "https://github.com/IlyasKhallouki/hypruse#readme"
erhebungsstand: "2026-10-11T01:17:01.851Z"
namensraum: "io.github.IlyasKhallouki"
registerseite: "https://tracevero.com/mcp/io-github-ilyaskhallouki-hypruse"
abgerufen_am: "2026-10-11"
zugangsdaten_erforderlich: false
ausfuehrungsort: "lokal"
dateisystem_pfadargument: false
quelloffen_einsehbar: true
roh_beschreibung: "Computer use for Hyprland: semantic desktop state over IPC, plus vision and native input"
version: "0.12.0"
roh_umgebungsvariablen: "HYPRUSE_SCREENSHOT_MODE, HYPRUSE_READONLY, HYPRUSE_CONFINE, HYPRUSE_AUTH_GUARD, HYPRUSE_STRICT, HYPRUSE_MARK, HYPRUSE_CLIPBOARD, HYPRUSE_JOURNAL, HYPRUSE_JOURNAL_MAX_BYTES, HYPRUSE_JOURNAL_TEXT, HYPRUSE_DRYRUN"
roh_geheime_pflichtvariablen: ""
roh_transportarten: "stdio"
roh_pfadargumente: ""
roh_repository_url: "https://github.com/IlyasKhallouki/hypruse"
roh_paketquellen: "pypi"
roh_geheime_pflichtkopfzeilen: ""
roh_pfad_umgebungsvariablen: ""
roh_remote_adressen: ""
roh_remote_hosts: ""
roh_statusmeldung: ""
roh_veroeffentlicht_am: "2026-10-08"
roh_aktualisiert_am: "2026-10-08"
roh_schemafassung: "https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json"
roh_bereitstellungsform: "paket"
roh_repository_quelle: "github"
roh_repository_unterordner: ""
roh_paketbezeichner: "hypruse"
roh_paketversionen: "0.12.0"
roh_laufzeithinweise: "uvx"
roh_umgebungsformate: ""
roh_umgebungsbeschreibungen: "HYPRUSE_AUTH_GUARD=Refuse to click or type into system authentication dialogs (polkit, keyring prompts). On by default; 'strict' also refuses password fields in ordinary windows; 0 disables it. · HYPRUSE_CLIPBOARD=Set to 1 to register the opt-in clipboard tool (never in read-only mode). Off by default because clipboards hold passwords. · HYPRUSE_CONFINE=Restrict input to a scope of windows and refuse everything outside it: 'launched' (only windows hypruse opened this session), 'class:firefox,kitty', or 'workspace:3,special:notes'. Unset means no confinement. · HYPRUSE_DRYRUN=Set to 1 for a rehearsal: every acting tool validates its arguments and runs every trust guard, then reports what it would have done and delivers no input. · HYPRUSE_JOURNAL=Record every tool call, refusals included, as one NDJSON line: 1 writes to XDG_STATE_HOME/hypruse/journal.ndjson, or give a path. Read it back with 'hypruse journal'. Off by default. · HYPRUSE_JOURNAL_MAX_BYTES=Rotate the journal once it reaches this size, keeping one previous generation alongside it. Set 0 to never rotate. · HYPRUSE_JOURNAL_TEXT=Set to 1 to record typed and copied text in the journal verbatim instead of as a length plus digest. Off by default because keystrokes are passwords; needed only to replay typing. · HYPRUSE_MARK=Set to 1 to make the agent's presence legible: tag every window it opens 'hypruse-owned' and flash an on-screen notice when it opens a window or captures the screen. · HYPRUSE_READONLY=Set to 1 to expose only the observation tools (desktop, screenshot, zoom, ui, marks, binds, wait_for). The agent can see and narrate but cannot click, type, or launch. · HYPRUSE_SCREENSHOT_MODE=How captures are returned: 'file' writes to XDG_RUNTIME_DIR and returns the path, 'image' returns the image inline. Use 'image' for clients that render MCP images but cannot read files, such as Claude Desktop. · HYPRUSE_STRICT=Set to 1 to refuse to act when the cursor or focused window moved since hypruse's last action, so the agent must re-read the desktop before retrying."
roh_symbolformate: ""
roh_verbindungswege: "{\"packages\":[{\"registryType\":\"pypi\",\"identifier\":\"hypruse\",\"version\":\"0.12.0\",\"runtimeHint\":\"uvx\",\"transport\":\"stdio\",\"environment\":[{\"name\":\"HYPRUSE_SCREENSHOT_MODE\",\"description\":\"How captures are returned: 'file' writes to XDG_RUNTIME_DIR and returns the path, 'image' returns the image inline. Use 'image' for clients that render MCP images but cannot read files, such as Claude Desktop.\",\"required\":false,\"secret\":false},{\"name\":\"HYPRUSE_READONLY\",\"description\":\"Set to 1 to expose only the observation tools (desktop, screenshot, zoom, ui, marks, binds, wait_for). The agent can see and narrate but cannot click, type, or launch.\",\"required\":false,\"secret\":false},{\"name\":\"HYPRUSE_CONFINE\",\"description\":\"Restrict input to a scope of windows and refuse everything outside it: 'launched' (only windows hypruse opened this session), 'class:firefox,kitty', or 'workspace:3,special:notes'. Unset means no confinement.\",\"required\":false,\"secret\":false},{\"name\":\"HYPRUSE_AUTH_GUARD\",\"description\":\"Refuse to click or type into system authentication dialogs (polkit, keyring prompts). On by default; 'strict' also refuses password fields in ordinary windows; 0 disables it.\",\"required\":false,\"secret\":false},{\"name\":\"HYPRUSE_STRICT\",\"description\":\"Set to 1 to refuse to act when the cursor or focused window moved since hypruse's last action, so the agent must re-read the desktop before retrying.\",\"required\":false,\"secret\":false},{\"name\":\"HYPRUSE_MARK\",\"description\":\"Set to 1 to make the agent's presence legible: tag every window it opens 'hypruse-owned' and flash an on-screen notice when it opens a window or captures the screen.\",\"required\":false,\"secret\":false},{\"name\":\"HYPRUSE_CLIPBOARD\",\"description\":\"Set to 1 to register the opt-in clipboard tool (never in read-only mode). Off by default because clipboards hold passwords.\",\"required\":false,\"secret\":false},{\"name\":\"HYPRUSE_JOURNAL\",\"description\":\"Record every tool call, refusals included, as one NDJSON line: 1 writes to XDG_STATE_HOME/hypruse/journal.ndjson, or give a path. Read it back with 'hypruse journal'. Off by default.\",\"required\":false,\"secret\":false},{\"name\":\"HYPRUSE_JOURNAL_MAX_BYTES\",\"description\":\"Rotate the journal once it reaches this size, keeping one previous generation alongside it. Set 0 to never rotate.\",\"required\":false,\"secret\":false},{\"name\":\"HYPRUSE_JOURNAL_TEXT\",\"description\":\"Set to 1 to record typed and copied text in the journal verbatim instead of as a length plus digest. Off by default because keystrokes are passwords; needed only to replay typing.\",\"required\":false,\"secret\":false},{\"name\":\"HYPRUSE_DRYRUN\",\"description\":\"Set to 1 for a rehearsal: every acting tool validates its arguments and runs every trust guard, then reports what it would have done and delivers no input.\",\"required\":false,\"secret\":false}],\"additional_arguments_declared\":false}],\"remotes\":[]}"
---

# hypruse

## Measured values

| Property | Value | Source | Collected on | Level of trust | Raw declaration |
| --- | --- | --- | --- | --- | --- |
| Required secrets declared | false | MCP-Register | 2026-08-06T13:57:41.838Z | abgeleitet | roh_geheime_pflichtvariablen: ; roh_geheime_pflichtkopfzeilen: |
| Execution location | lokal | MCP-Register | 2026-08-06T13:57:41.838Z | abgeleitet | roh_transportarten: stdio |
| Path argument present | false | MCP-Register | 2026-08-06T13:57:41.838Z | abgeleitet | roh_pfadargumente: ; roh_pfad_umgebungsvariablen: |
| Repository URL listed | true | MCP-Register | 2026-08-06T13:57:41.838Z | abgeleitet | roh_repository_url: https://github.com/IlyasKhallouki/hypruse |
| Description (raw) | Computer use for Hyprland: semantic desktop state over IPC, plus vision and native input | MCP-Register | 2026-08-26T16:45:01.514Z | selbstauskunft |  |
| Declared version | 0.12.0 | MCP-Register | 2026-10-09T01:17:01.645Z | selbstauskunft |  |
| Environment variables (raw) | HYPRUSE_SCREENSHOT_MODE, HYPRUSE_READONLY, HYPRUSE_CONFINE, HYPRUSE_AUTH_GUARD, HYPRUSE_STRICT, HYPRUSE_MARK, HYPRUSE_CLIPBOARD, HYPRUSE_JOURNAL, HYPRUSE_JOURNAL_MAX_BYTES, HYPRUSE_JOURNAL_TEXT, HYPRUSE_DRYRUN | MCP-Register | 2026-09-01T01:17:01.342Z | selbstauskunft |  |
| Required secret variables (raw) |  | MCP-Register | 2026-08-06T13:57:41.838Z | selbstauskunft |  |
| Transports (raw) | stdio | MCP-Register | 2026-08-06T13:57:41.838Z | selbstauskunft |  |
| Path arguments (raw) |  | MCP-Register | 2026-08-06T13:57:41.838Z | selbstauskunft |  |
| Repository (raw) | https://github.com/IlyasKhallouki/hypruse | MCP-Register | 2026-08-06T13:57:41.838Z | selbstauskunft |  |
| Package registries (raw) | pypi | MCP-Register | 2026-08-06T13:57:41.838Z | selbstauskunft |  |
| Required secret headers (raw) |  | MCP-Register | 2026-08-16T01:17:01.420Z | selbstauskunft |  |
| Path environment variables (raw) |  | MCP-Register | 2026-08-16T01:17:01.420Z | selbstauskunft |  |
| Remote URLs (raw) |  | MCP-Register | 2026-08-16T01:17:01.420Z | selbstauskunft |  |
| Remote hosts (raw) |  | MCP-Register | 2026-08-16T01:17:01.420Z | selbstauskunft |  |
| Registry status message (raw) |  | MCP-Register | 2026-08-16T01:17:01.420Z | selbstauskunft |  |
| First listed in the registry (raw) | 2026-10-08 | MCP-Register | 2026-10-09T01:17:01.645Z | selbstauskunft |  |
| Last changed in the registry (raw) | 2026-10-08 | MCP-Register | 2026-10-09T01:17:01.645Z | selbstauskunft |  |
| Schema version of the raw record (raw) | https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json | MCP-Register | 2026-08-16T01:17:01.420Z | selbstauskunft |  |
| Delivery form (raw) | paket | MCP-Register | 2026-08-16T01:17:01.420Z | selbstauskunft |  |
| Repository platform (raw) | github | MCP-Register | 2026-08-16T01:17:01.420Z | selbstauskunft |  |
| Repository subfolder (raw) |  | MCP-Register | 2026-08-16T01:17:01.420Z | selbstauskunft |  |
| Package identifiers (raw) | hypruse | MCP-Register | 2026-08-16T01:17:01.420Z | selbstauskunft |  |
| Package versions (raw) | 0.12.0 | MCP-Register | 2026-10-09T01:17:01.645Z | selbstauskunft |  |
| Runtime hints (raw) | uvx | MCP-Register | 2026-08-16T01:17:01.420Z | selbstauskunft |  |
| Environment variable formats (raw) |  | MCP-Register | 2026-08-16T01:17:01.420Z | selbstauskunft |  |
| Environment variable descriptions (raw) | HYPRUSE_AUTH_GUARD=Refuse to click or type into system authentication dialogs (polkit, keyring prompts). On by default; 'strict' also refuses password fields in ordinary windows; 0 disables it. · HYPRUSE_CLIPBOARD=Set to 1 to register the opt-in clipboard tool (never in read-only mode). Off by default because clipboards hold passwords. · HYPRUSE_CONFINE=Restrict input to a scope of windows and refuse everything outside it: 'launched' (only windows hypruse opened this session), 'class:firefox,kitty', or 'workspace:3,special:notes'. Unset means no confinement. · HYPRUSE_DRYRUN=Set to 1 for a rehearsal: every acting tool validates its arguments and runs every trust guard, then reports what it would have done and delivers no input. · HYPRUSE_JOURNAL=Record every tool call, refusals included, as one NDJSON line: 1 writes to XDG_STATE_HOME/hypruse/journal.ndjson, or give a path. Read it back with 'hypruse journal'. Off by default. · HYPRUSE_JOURNAL_MAX_BYTES=Rotate the journal once it reaches this size, keeping one previous generation alongside it. Set 0 to never rotate. · HYPRUSE_JOURNAL_TEXT=Set to 1 to record typed and copied text in the journal verbatim instead of as a length plus digest. Off by default because keystrokes are passwords; needed only to replay typing. · HYPRUSE_MARK=Set to 1 to make the agent's presence legible: tag every window it opens 'hypruse-owned' and flash an on-screen notice when it opens a window or captures the screen. · HYPRUSE_READONLY=Set to 1 to expose only the observation tools (desktop, screenshot, zoom, ui, marks, binds, wait_for). The agent can see and narrate but cannot click, type, or launch. · HYPRUSE_SCREENSHOT_MODE=How captures are returned: 'file' writes to XDG_RUNTIME_DIR and returns the path, 'image' returns the image inline. Use 'image' for clients that render MCP images but cannot read files, such as Claude Desktop. · HYPRUSE_STRICT=Set to 1 to refuse to act when the cursor or focused window moved since hypruse's last action, so the agent must re-read the desktop before retrying. | MCP-Register | 2026-09-01T01:17:01.342Z | selbstauskunft |  |
| Icon formats (raw) |  | MCP-Register | 2026-08-16T01:17:01.420Z | selbstauskunft |  |
| Connection paths (source structure) | {"packages":[{"registryType":"pypi","identifier":"hypruse","version":"0.12.0","runtimeHint":"uvx","transport":"stdio","environment":[{"name":"HYPRUSE_SCREENSHOT_MODE","description":"How captures are returned: 'file' writes to XDG_RUNTIME_DIR and returns the path, 'image' returns the image inline. Use 'image' for clients that render MCP images but cannot read files, such as Claude Desktop.","required":false,"secret":false},{"name":"HYPRUSE_READONLY","description":"Set to 1 to expose only the observation tools (desktop, screenshot, zoom, ui, marks, binds, wait_for). The agent can see and narrate but cannot click, type, or launch.","required":false,"secret":false},{"name":"HYPRUSE_CONFINE","description":"Restrict input to a scope of windows and refuse everything outside it: 'launched' (only windows hypruse opened this session), 'class:firefox,kitty', or 'workspace:3,special:notes'. Unset means no confinement.","required":false,"secret":false},{"name":"HYPRUSE_AUTH_GUARD","description":"Refuse to click or type into system authentication dialogs (polkit, keyring prompts). On by default; 'strict' also refuses password fields in ordinary windows; 0 disables it.","required":false,"secret":false},{"name":"HYPRUSE_STRICT","description":"Set to 1 to refuse to act when the cursor or focused window moved since hypruse's last action, so the agent must re-read the desktop before retrying.","required":false,"secret":false},{"name":"HYPRUSE_MARK","description":"Set to 1 to make the agent's presence legible: tag every window it opens 'hypruse-owned' and flash an on-screen notice when it opens a window or captures the screen.","required":false,"secret":false},{"name":"HYPRUSE_CLIPBOARD","description":"Set to 1 to register the opt-in clipboard tool (never in read-only mode). Off by default because clipboards hold passwords.","required":false,"secret":false},{"name":"HYPRUSE_JOURNAL","description":"Record every tool call, refusals included, as one NDJSON line: 1 writes to XDG_STATE_HOME/hypruse/journal.ndjson, or give a path. Read it back with 'hypruse journal'. Off by default.","required":false,"secret":false},{"name":"HYPRUSE_JOURNAL_MAX_BYTES","description":"Rotate the journal once it reaches this size, keeping one previous generation alongside it. Set 0 to never rotate.","required":false,"secret":false},{"name":"HYPRUSE_JOURNAL_TEXT","description":"Set to 1 to record typed and copied text in the journal verbatim instead of as a length plus digest. Off by default because keystrokes are passwords; needed only to replay typing.","required":false,"secret":false},{"name":"HYPRUSE_DRYRUN","description":"Set to 1 for a rehearsal: every acting tool validates its arguments and runs every trust guard, then reports what it would have done and delivers no input.","required":false,"secret":false}],"additional_arguments_declared":false}],"remotes":[]} | MCP-Register | 2026-10-09T01:17:01.645Z | selbstauskunft |  |

## Links

- Namespace: [[namensraum/io-github-ilyaskhallouki|io.github.IlyasKhallouki]]

---

- Registry page: <https://tracevero.com/mcp/io-github-ilyaskhallouki-hypruse>
- Retrieved on: 2026-10-11
