AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
MCP verified Apache-2.0 Self-run

DeskVNC

mcp-psmux-deskvnc · by psmux

Native VNC, RDP and SSH client for Windows, macOS and Linux. Pure-Rust protocol cores, Tauri 2. One host library for all three, plus an MCP control plane so an AI agent can drive remote desktops with human takeover.

— No reviews yet
0 installs
7 views
0.0% view→install

Install

$ agentstack add mcp-psmux-deskvnc

✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • ✓ Prompt-injection patterns
  • ✓ Secret / credential exfiltration
  • ✓ Dangerous shell & filesystem operations
  • ✓ Untrusted network calls
  • ✓ Known-malicious package signatures

What it can access

  • ✓ Network access No
  • ✓ Filesystem access No
  • ✓ Shell / process execution No
  • ✓ Environment & secrets No
  • ✓ Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Verified badge

Passed review? Show it. Paste this badge into your README, it links to the public security report.

AgentStack Verified badge Links to your public security report.
[![AgentStack Verified](https://agentstack.voostack.com/badges/verified.svg)](https://agentstack.voostack.com/security/report/mcp-psmux-deskvnc)

Reliability & compatibility

✓ Security review passed
0 installs to date
— no reviews yet
● 12d ago

Declared compatibility

Claude CodeClaude DesktopCursorWindsurf

Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of DeskVNC? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

DeskVNC

One window for every machine you look after, whether it speaks VNC, RDP or SSH. Native, written in Rust on Tauri 2, and it runs on Windows, macOS and Linux.

It also has something no other remote desktop client has yet: an optional control plane that lets an AI agent drive those same machines, with nothing installed on the far end, and a person able to take the wheel back mid task.

[](#license) [](https://github.com/psmux/DeskVNC/releases/latest)

Screenshots are a real build against demo servers on loopback, and are for reference only: the machines in them are invented, and the desktops being viewed are credited in [docs/images/CREDITS.md](docs/images/CREDITS.md).

Why this exists

Anyone who looks after more than a handful of machines ends up with a drawer full of tools. One client for Windows boxes, another for the Linux server in the cupboard, a terminal for everything else, and a text file of addresses nobody trusts. The connection managers that fix this are mostly paid, and several of them run on a .NET runtime that security teams are busy removing.

DeskVNC puts the three protocols in one library. Your hosts carry their own credentials and settings, they connect on a double click, and each tile shows what that machine looked like when you last left it. Passwords go into the operating system keychain rather than a database next to the profiles. There is no account, no telemetry, and no paid tier holding a feature back.

Get started in about a minute

  1. Download the build for your machine from the

latest release. macOS is signed and notarized, so it opens normally. On Windows, SmartScreen will warn because the installer is not signed yet: choose More info, then Run anyway, or check the published checksum first.

  1. Open it and press New Host, or paste an address straight into the bar at

the top and press Connect, which saves nothing.

  1. Double click a tile. That is the whole flow.

Addresses can be written the way you already think of them: 10.0.0.4, 10.0.0.4:5901, rdp://frontdesk, ssh://ops@jump-01. If you do not know the address, press Scan network and DeskVNC will find what is listening nearby.

Full install notes, checksum verification and the permissions the app asks for are in [docs/INSTALL.md](docs/INSTALL.md).

In a session

The toolbar floats over the desktop and stays out of the way until you reach for it. From left to right it carries the measured round trip time, scaling, display and pointer choices, quality, keyboard and clipboard behaviour, file transfer, a terminal for the same host, fullscreen, pane splitting, view only, a screenshot button, and the way out.

Things that matter once you actually use it all day:

  • The picture is decoded in Rust and painted through WebGL2, so whole frames

never cross the process boundary. H.264 decodes with hardware acceleration where the webview offers it.

  • Your scroll wheel and trackpad behave on the remote exactly the way they

behave on your own machine, whichever direction your system is set to.

  • Keyboard layouts, dead keys and CJK input methods reach the remote intact,

and system shortcuts can be passed through when you want them to.

  • Files move both ways over SFTP, and the clipboard follows you.
  • A session that drops comes back on its own and tells you what happened.

Several machines at once

Sessions open as tabs, and any tab splits into panes that can each hold a different machine and a different protocol. A Windows desktop over RDP next to a Linux box over VNC next to a shell is an ordinary arrangement here, not a special mode.

Let an agent drive it

This is the part that does not exist anywhere else. DeskVNC ships dvv, an MCP server that hands an AI agent the same connections you use by hand. The agent opens one of your saved machines, looks at the screen, clicks and types. Nothing is installed on the target, because the connection is the ordinary VNC, RDP or SSH one.

That matters for the machines automation usually cannot reach. The funded tools that let an agent use a Windows desktop all install an agent on that desktop, which is refused on Citrix, on VDI, on jump hosts and on anything a client owns. A protocol those machines already speak gets in anyway.

Switch the plane on in the AI Agents panel, then register it once:

claude mcp add deskvnc -- /Applications/DeskVNCViewer.app/Contents/MacOS/dvv mcp --stdio

There is a button in that panel that does this for Claude Code for you, and dvv doctor prints the exact line for anything else. Claude Code and OpenCode are verified over both stdio and HTTP. Codex, Cursor, Gemini CLI, VS Code and plain Python agents are covered in [the integration notes](docs/AGENTS.md#other-clients).

The loop is four calls. Open a machine, take the wheel, look, act.

dvv_hosts   {}                                    // what there is to open
dvv_open    {"hostId": "", "perceive": true}  // -> limbId, size, state
dvv_control {"limbId": "...", "action": "acquire"}
dvv_screen  {"limbId": "...", "form": "full", "scale": 0.25}
dvv_click   {"limbId": "...", "x": 700, "y": 400, "generation": 1}
dvv_screen  {"limbId": "...", "form": "damage-crop"}  // look again
dvv_type    {"limbId": "...", "text": "notepad", "wpm": 3000}
dvv_key     {"limbId": "...", "keys": "meta+r"}

The rest has the same shape: dvv_files for transfers, dvv_clipboard, dvv_term_read and dvv_term_send for SSH, dvv_run to execute a command, dvv_wait to block until the screen settles, and dvv_group_* to address several machines as one.

It is quick enough to sit inside a loop. Measured against a real 1920x1080 Windows desktop on a LAN:

| call | time | | --- | --- | | dvv_open and attach | 4 ms | | dvv_control acquire | under 1 ms | | dvv_screen at scale: 0.25 (112 KB) | 25 ms | | dvv_screen at full scale (1.5 MB) | 70 ms | | one observe then act cycle | 19 ms, about 52 actions per second | | dvv_type throughput at wpm: 12000 | 447 characters per second |

Every machine is its own limb with its own lease, so ten machines are ten independent loops. One agent holding two desktops and typing a different sum into a calculator on each finished both in 0.95 seconds. The local mouse and keyboard are never involved: input goes over the protocol, the window can be minimised, and you carry on using your own computer.

Four rules the plane enforces, worth reading once rather than debugging later:

  1. Attach before you act. A limb id belongs to the connection that opened it, so

use one long lived peer for a task rather than a new process per call.

  1. Coordinates are fenced. Clicks carry a generation read from dvv_screen,

and a click computed against a stale screen is refused instead of landing somewhere unintended.

  1. Typing is fenced too. dvv_type and dvv_key are refused with

SCREEN_CHANGED if something large has repainted since the agent last looked, because focus moves when a window opens. There is no override.

  1. A person can take the wheel at any moment. Click into the pane and the agent

is fenced out of that session; held keys and buttons are released so a half finished drag cannot strand the desktop.

Anything a remote machine produces is untrusted text. A window title, a directory listing, terminal output: all of it is data to act on, never instructions to follow.

What is under it

Three protocol cores, written here rather than wrapped around somebody else's library.

The VNC core speaks RFB 3.3 through 3.8 with every common encoding, VeNCrypt, RA2 and Apple authentication, and continuous updates. Its rough edges have been filed off against real servers: x11vnc, TigerVNC, QEMU, RealVNC and macOS Screen Sharing. The RDP core covers Windows desktops with NLA, RemoteApp, resolution control and the usual codecs. The SSH core gives you a terminal that survives a drop, SFTP transfers, tunnels, and PuTTY key files.

Around them: mDNS browsing, polite subnet scanning with banner fingerprinting, name resolution over mDNS, LLMNR, NetBIOS and MS-RPC, and Wake on LAN. Secrets live in Keychain Services, Credential Manager or Secret Service, with an encrypted file fallback for headless machines, and a test asserts that saving a host writes nothing sensitive into the profile database.

The protocol feature list, the security model and the crate layout are in [docs/ARCHITECTURE.md](docs/ARCHITECTURE.md).

Status

Pre 1.0 and under active development. The protocol cores are well covered by tests and interoperability work is ongoing. Stored data and the IPC contract may change between minor versions. [CHANGELOG.md](CHANGELOG.md) records every release, and the issue tracker is where several of those releases came from.

Building from source

You need Rust 1.82 or newer, Node 22 or newer, and the Tauri 2 system dependencies for your platform.

npm install --prefix ui
cargo install tauri-cli --version "^2"   # if you do not have it

cargo tauri dev      # development, with hot reload
cargo tauri build    # production bundle

Support and commercial use

DeskVNC is free and open source and stays that way. It is built and maintained by one engineer.

Sponsoring the project funds the roadmap and the signed Windows builds.

If your company depends on DeskVNC, or you want the agent control plane inside your own product (a no install tier for driving legacy or locked down Windows desktops, a hardened dvv, or protocol work on the Rust RDP, VNC and SSH cores), write to godwin@altrosyn.com. Paid priority support and fixed scope contracts are available.

Contributing

Bug reports, interoperability findings and pull requests are all welcome. If you have hit a server this client mishandles, an issue naming the server and its version is useful on its own. Several releases exist because somebody did exactly that. Start with [CONTRIBUTING.md](CONTRIBUTING.md).

For security issues, please do not open a public issue. See [SECURITY.md](SECURITY.md).

License

Licensed under either of

  • Apache License, Version 2.0 ([LICENSE-APACHE](LICENSE-APACHE) or

)

  • MIT License ([LICENSE-MIT](LICENSE-MIT) or )

at your option.

Unless you explicitly state otherwise, any contribution intentionally submitted for inclusion in this work by you, as defined in the Apache-2.0 license, shall be dual licensed as above, without any additional terms or conditions.

The machines in the screenshots are demo servers on loopback, not anybody's network. The desktops being viewed in them, and the licences they carry, are listed in [docs/images/CREDITS.md](docs/images/CREDITS.md).

Source & license

This open-source MCP server is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet, be the first.

Versions

  • v0.1.0 Imported from the upstream source.