Agent skill

Linux Desktop Control

by agent-sh in agent-sh/computer-use-linux

Lets an agent observe and operate a local Linux desktop through the computer-use-linux MCP server or Pi tools: accessibility trees, screenshots, windows and input.

MITAuto-check passedProductivity & Automation

Install Linux Desktop Control

skills CLI
$ npx skills add agent-sh/computer-use-linux --skill computer-use-linux -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install agent-sh/computer-use-linux computer-use-linux --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/agent-sh/computer-use-linux.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/computer-use-linux .claude/skills/computer-use-linux && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
computer-use-linux
GitHub stars
661
Token cost
~2.7k tokens
SKILL.md length
1,309 words
Files
3 (incl. references)
Skills in repo
1
Repo updated
First seen
Licence
MIT

At a glance

Lets an agent observe and operate a local Linux desktop through the computer-use-linux MCP server or Pi tools: accessibility trees, screenshots, windows and input.

  • Works in 10 steps: In Pi, call computer_use_linux_tools… → Begin every desktop-control turn with… → Use doctor only when you need the full… → …
  • Controlling a Linux GUI application from an agent
  • SKILL.md covers When to Use, Install, Configure Your Agent and Procedure, plus 2 more sections
  • Calls jq, claude and codex

What it does

The skill is for agents that need to inspect or drive a local Linux GUI: reading the accessibility tree, listing and focusing windows, taking screenshots, clicking, scrolling, typing, pressing keys and invoking AT-SPI actions. It is not meant for remote browsers, websites or headless automation where a browser-specific tool exists, and it warns that a working MCP connection does not make desktop actions safe.

Installation comes in three forms: a Claude Code or Codex plugin that registers the MCP server and downloads checksum-verified binaries on first start, Pi native tools added with `pi install`, and a shell CLI through npm or `cargo install`. Commands such as `computer-use-linux doctor`, `setup` and `setup-window-targeting` check and fix input and accessibility support, and ydotool may need its daemon enabled. Native Pi tools need Pi 0.84.4 or newer and Node.js 22.19 or newer, while the standalone CLI and MCP server support Node.js 18 or newer. A niri session needs its `NIRI_SOCKET` exported.

When your agent uses it

  • Controlling a Linux GUI application from an agent
  • Reading desktop state from AT-SPI, screenshots or window metadata
  • Configuring the computer-use-linux MCP server for your agent

Example prompts

  • “Take a screenshot of the focused window and list the buttons in its accessibility tree.”
  • “Open the Settings app, switch to the Network page and tell me what it shows.”
  • “Run computer-use-linux doctor and fix whatever it says is missing.”

Requirements

  • A local Linux desktop session
  • Node.js 18 or newer for the CLI and MCP server, or Rust to install with cargo
  • For Pi native tools: Pi 0.84.4 or newer and Node.js 22.19 or newer
  • Compatibility (from SKILL.md): Native Pi tools require Pi 0.84.4+ and Node.js 22.19+; the standalone CLI/MCP server supports Node.js 18+.

Workflow steps

10 steps, taken from the first numbered list in SKILL.md.

  1. In Pi, call computer_use_linux_tools with the exact tools or capability you need. Enabled tools use the computer_use_linux_ prefix, appear…
  2. Begin every desktop-control turn with get_app_state, scoped to the app you are working in: pass app_name_or_bundle_identifier or a window…
  3. Use doctor only when you need the full diagnostic report.
  4. If can_build_accessibility_tree is false, run setup_accessibility and restart the target app.
  5. If can_query_windows is false on GNOME Wayland, run setup_window_targeting and ask the user to log out and back in if setup says the shell…
  6. Before targeted input, call list_windows or focused_window and verify the intended window by title, app id, pid, or wm class.
  7. Prefer semantic targeting from get_app_state: use element indices or role/name/text/states selectors.
  8. Use coordinates only when the UI surface has no useful accessibility tree.
  9. For text input, prefer type_text with a target selector (window_id, pid, app_id, wm_class, title, tty, terminal_pid, terminal_command, or…
  10. After mutating actions, re-check state with get_app_state, focused_window, or an app-specific readback.

What it can do on your machine

Read from SKILL.md and the folder at commit c4d4162. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • jq
    • claude
    • codex
    • npm
    • cargo

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Native Pi tools require Pi 0.84.4+ and Node.js 22.19+; the standalone CLI/MCP server supports Node.js 18+.

    From compatibility in the SKILL.md frontmatter.

Context cost

Linux Desktop Control loads about 2.7k tokens when it runs, and up to ~4.2k if it reads all its reference files. Until then it costs about 52 tokens; SKILL.md has 1,309 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~52
When it runs · the whole SKILL.md, loaded when a task matches
~2.7k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from agent-sh/computer-use-linux at commit c4d4162, republished under its MIT licence (© agent-sh). 1,309 words, ~2,713 tokens.

Download SKILL.mdSave it as .claude/skills/computer-use-linux/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
computer-use-linux
description
Linux desktop observation and control via native Pi tools or the computer-use-linux MCP server: accessibility trees, screenshots, window targeting, and input synthesis (click, type, scroll).
compatibility
Native Pi tools require Pi 0.84.4+ and Node.js 22.19+; the standalone CLI/MCP server supports Node.js 18+.
author
agent-sh
license
MIT
platforms
linux

computer-use-linux

Use computer-use-linux when an agent needs to observe or operate a local Linux desktop: inspect the accessibility tree, list/focus windows, take screenshots, click, scroll, type, press keys, or invoke AT-SPI actions.

When to Use

Use this skill when:

  • The user wants the agent to control a Linux GUI app.
  • You need desktop state from AT-SPI, screenshots, or compositor window metadata.
  • You are configuring the computer-use-linux MCP server for your agent.
  • A desktop action needs target-aware input instead of blind shell commands.

Do not use this for remote browsers, websites, or headless automation when a browser-specific tool is available. Do not assume desktop actions are safe just because the MCP connection works.

Install

Pick the install that matches how you will run this skill. You can use both.

Claude Code or Codex plugin
bash
claude plugin marketplace add agent-sh/computer-use-linux
claude plugin install computer-use-linux@computer-use-linux
# or, in Codex:
codex plugin marketplace add agent-sh/computer-use-linux
codex plugin add computer-use-linux@computer-use-linux

The plugin registers the MCP server and downloads the pinned, sha256-verified release binaries on first start. It does not put computer-use-linux on PATH; shell commands in this skill need the CLI install below. Set COMPUTER_USE_LINUX_BIN to run a local build instead.

Pi native tools
bash
pi install npm:@agent-sh/computer-use-linux

This enables Pi's computer_use_linux_* tools. It does not put computer-use-linux on PATH. Shell commands in this skill (doctor, setup, setup-window-targeting, guard-accessibility, the MCP command config, and Verification) need the CLI install below.

Shell CLI / MCP server

Use this when you need computer-use-linux on PATH for the commands in this skill.

bash
npm install -g @agent-sh/computer-use-linux
computer-use-linux doctor | jq .readiness

Rust users can install from crates.io:

bash
cargo install computer-use-linux
computer-use-linux doctor | jq .readiness

If doctor reports missing input or accessibility support, run:

bash
computer-use-linux setup
computer-use-linux setup-window-targeting
computer-use-linux doctor | jq .readiness

If doctor selects ydotool as the input backend, also enable its per-user daemon with systemctl --user enable --now ydotoold. Direct uinput, X11 xdotool, and RemoteDesktop portal input do not require ydotoold.

On niri, export the session's NIRI_SOCKET to the server. Window listing and exact focus use niri msg with a direct IPC fallback. Missing positions or unknown/mixed output scaling leave window-relative coordinates unavailable; focus the target and inspect a fresh full-screen screenshot before using desktop coordinates.

On GNOME Wayland, log out and back in after setup-window-targeting if the GNOME Shell extension was newly installed.

For MCP hosts with COMPUTER_USE_LINUX_NOTIFY_ON_COMPLETE=1, call the optional complete_interaction tool once after finishing desktop interaction. A skipped cue is not a task failure. This notification does not guarantee exclusive desktop ownership or that other clients have stopped sending input. This applies only to directly spawned MCP hosts, not the native Pi extension.

setup_accessibility verifies the saved GNOME toolkit-accessibility key separately from runtime AT-SPI. Inspect its warning and readback before assuming new apps can expose trees. Other accessibility tools may change the key later; setup does not hold it enabled continuously.

Optional foreground accessibility guard

Skip unless: the user explicitly wants GNOME's saved toolkit-accessibility setting kept enabled while desktop automation runs.

Run computer-use-linux guard-accessibility in a foreground terminal. It registers a passive AT-SPI window-activation listener and watches/reasserts the saved key with readback. The setting affects all apps for the current user. mcp, setup, and get_app_state never start this guard automatically. Stop with Ctrl-C or SIGTERM before intentionally disabling accessibility. Stopping ends writes and removes its listener without disabling other clients or restoring a previous saved value. Apps launched during a reset/reassertion race may still need restarting; do not claim a complete GNOME toggle fix.

Configure Your Agent

The computer-use-linux binary is an MCP server. Configure it as a stdio MCP server in your agent of choice:

json
{
  "command": "computer-use-linux",
  "args": ["mcp"]
}

If the binary is not on PATH, use the absolute path (typically ~/.local/bin/computer-use-linux or the npm global bin directory). Pi native tools skip this MCP command config; see Pi setup.

Host-specific guides

Procedure

  1. In Pi, call computer_use_linux_tools with the exact tools or capability you need. Enabled tools use the computer_use_linux_<name> prefix, appear starting on the next model turn, and remain active for the session.
  2. Begin every desktop-control turn with get_app_state, scoped to the app you are working in: pass app_name_or_bundle_identifier or a window target (window_id, pid, app_id, wm_class, title). Without a target the result is the whole desktop AT-SPI tree, tree_scoped is false, and message warns; that can flood context. Use include_screenshot: false when the accessibility tree is sufficient. If accessibility_tree_truncated is true, the tree is incomplete: scope to a narrower target and raise max_nodes or max_depth (hard caps 2000 and 64) rather than lowering them. The compact readiness block identifies missing setup.
  3. Use doctor only when you need the full diagnostic report.
  4. If can_build_accessibility_tree is false, run setup_accessibility and restart the target app.
  5. If can_query_windows is false on GNOME Wayland, run setup_window_targeting and ask the user to log out and back in if setup says the shell extension needs a reload.
  6. Before targeted input, call list_windows or focused_window and verify the intended window by title, app id, pid, or wm class.
  7. Prefer semantic targeting from get_app_state: use element indices or role/name/text/states selectors.
  8. Use coordinates only when the UI surface has no useful accessibility tree.
  9. For text input, prefer type_text with a target selector (window_id, pid, app_id, wm_class, title, tty, terminal_pid, terminal_command, or terminal_cwd) rather than relying on current focus.
  10. After mutating actions, re-check state with get_app_state, focused_window, or an app-specific readback.

Plain left element/index/selector click prefers native AT-SPI click, press, or toggle over toolkit bounds, avoiding coordinate conversion when available. This preference does not replace a coordinate click with an arbitrary action name. Explicit x/y, right clicks, and double/multiple clicks retain pointer semantics. Use perform_action explicitly for entry activate or slider jump; click never substitutes those actions, including when bounds are unavailable.

Show full SKILL.md (399 more words)Show less
Screenshot-relative coordinates

Skip unless: a coordinate click or scroll uses relative: true.

Select a target window and use its clipped screenshot crop origin. Divide preview x/y by screenshot scale first. Widget-local and raw GDK surface coordinates are not interchangeable with that origin; missing window targets are rejected. For calibration, use the repository's examples/coordinate_probe.py: select the green square from the screenshot and require a delivered-event hit: true. Do not pass widget-local (85, 85) directly to a window-relative click.

Pitfalls

  • Already-running GTK, Qt, and Electron apps may need a restart after AT-SPI is enabled.
  • GNOME may show a portal prompt on the first screenshot or get_app_state call with screenshots enabled.
  • On GNOME Wayland, the remote-control portal asks on each new computer-use-linux process. COMPUTER_USE_LINUX_PERSIST_REMOTE_DESKTOP=1 in the server environment asks the portal to remember the grant (GNOME starts with the remember box checked). Later processes reuse a single-use restore token stored mode 0600 in the user state directory. Unset is the default and prompts every time. The flag does nothing when ydotool, not the portal, is the input backend.
  • Desktop input is stateful. Avoid concurrent tool calls against this MCP server.
  • Pi serializes the native Computer Use tools and keeps one process for the session. If that process exits, do not replay an ambiguous mutating call; obtain a fresh get_app_state before another element-based action.
  • click, drag, press_key, type_text, perform_action, and set_value can change real application state.
  • When ydotool is selected, ydotoold should run as a per-user service with its socket under /run/user/$UID, not as a system-wide service.
  • The optional ydotool backend requires version 1.0.3 or newer; doctor rejects older or semantically incompatible CLIs even when ydotoold is running.
  • On COSMIC, the standard npm, Cargo, and install-script paths install the computer-use-linux-cosmic helper automatically. Manual binary installs must copy both binaries.

Verification

Pi-only installs: enable and call computer_use_linux_doctor as in Pi setup. Shell computer-use-linux doctor needs the CLI on PATH.

Run:

bash
computer-use-linux doctor | jq .readiness

Ready output should have:

  • can_register_mcp_tools: true
  • can_build_accessibility_tree: true
  • can_query_windows: true
  • can_send_development_input: true
  • screenshot_capture_status: "unverified"
  • can_capture_screenshots: false
  • blockers: []

Doctor detects screenshot routes without capturing or requesting consent. Treat unverified capture as a warning. Call get_app_state with include_screenshot: true to verify it: a successful raw capture reports screenshot_capture_status: "verified" and can_capture_screenshots: true; a failure reports failed and keeps the boolean false. Inspect screenshot_error for the full backend cause.

Then test with your agent by calling the doctor tool or asking the agent to list desktop windows.

© agent-sh, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (references) in skills/computer-use-linux of agent-sh/computer-use-linux.

  • SKILL.md
  • references/hermes-setup.md
  • references/pi-setup.md

Open the folder on GitHubat commit c4d4162

Compare with similar skills

Linux Desktop Control next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Linux Desktop Control compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Linux Desktop Control this skillagent-sh/computer-use-linux661—~2.7kAutomated safety check: PassMIT
Browser MCP Agentantibrow/anti-detect-browser-skills9141 repos~4.2kAutomated safety check: WarnMIT
Isolated Linux Agent Workspaceagent-sh/agent-workspace-linux185—~2.1kAutomated safety check: PassMIT
Code Reviewoaslananka/kicad-mcp-pro119—~3.9kAutomated safety check: PassMIT
Open Computer UseiFurySt/open-codex-computer-use2.3k—~1.5kAutomated safety check: PassMIT
Waku Computer Useegoist/waku1.6k—~3.6kAutomated safety check: PassGPL-3.0

Similar skills

  • Browser MCP Agent

    antibrow/anti-detect-browser-skills

    Give an AI agent its own real browser over MCP tool calls - launch, navigate, click, fill, screenshot, extract text, run JS - with a kernel-level real-device fingerprint and a persistent profile, so…

    914 GitHub starsUsed in 1 repo~4.2k tokens
    Productivity & AutomationAuto-check: warnings
  • Isolated Linux Agent Workspace

    agent-sh/agent-workspace-linux

    Drives a hidden, agent-owned Linux desktop and browser over MCP for GUI testing and web automation without touching the user's real desktop.

    185 GitHub stars~2.1k tokensUpdated 3 days ago
    Productivity & AutomationAuto-check passed
  • Code Review

    oaslananka/kicad-mcp-pro

    A skill your agent uses for GitHub Copilot pull request and code reviews in oaslananka/kicad-mcp-pro.

    119 GitHub stars~3.9k tokensUpdated today
    DevelopmentAuto-check passed
  • Open Computer Use

    iFurySt/open-codex-computer-use

    Platform-neutral guidance for using Open Computer Use, the open-source Computer Use MCP server and CLI for macOS, Linux, and Windows.

    2.3k GitHub stars~1.5k tokensUpdated today
    Productivity & AutomationAuto-check passed
  • Control local macOS, Windows, and Linux apps through Waku Computer Use.

    1.6k GitHub stars~3.6k tokensUpdated 5 days ago
    Productivity & AutomationAuto-check passed
  • Altic Studio

    altic-dev/altic-mcp

    macOS automation skill for AppleScript actions and Chrome browser control via MCP CDP tools.

    172 GitHub stars~3.3k tokensUpdated 2 mo ago
    Productivity & AutomationAuto-check passed

Questions about Linux Desktop Control

What does Linux Desktop Control do?

Lets an agent observe and operate a local Linux desktop through the computer-use-linux MCP server or Pi tools: accessibility trees, screenshots, windows and input. The skill is for agents that need to inspect or drive a local Linux GUI: reading the accessibility tree, listing and focusing windows, taking screenshots, clicking, scrolling, typing, pressing keys and invoking AT-SPI actions. It is not meant for remote browsers, websites or headless automation where a browser-specific tool exists, and it warns that a working MCP connection does not make desktop actions safe.

When should I use Linux Desktop Control?

Linux Desktop Control fits situations like: controlling a Linux GUI application from an agent; reading desktop state from AT-SPI, screenshots or window metadata; configuring the computer-use-linux MCP server for your agent.

How do I install Linux Desktop Control in Claude Code?

Run `npx skills add agent-sh/computer-use-linux --skill computer-use-linux -a claude-code`. Or copy the skill folder (skills/computer-use-linux in agent-sh/computer-use-linux) into .claude/skills/computer-use-linux in your project. Claude Code loads it when a task matches its description.

How do I install Linux Desktop Control in Codex?

Run `npx skills add agent-sh/computer-use-linux --skill computer-use-linux -a codex`. Or copy the skill folder (skills/computer-use-linux in agent-sh/computer-use-linux) into .agents/skills/computer-use-linux in your project. Codex loads it when a task matches its description.

Can I use Linux Desktop Control in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add agent-sh/computer-use-linux --skill computer-use-linux -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/computer-use-linux, .gemini/skills/computer-use-linux, .github/skills/computer-use-linux and .opencode/skills/computer-use-linux in your project.

What does Linux Desktop Control need to run?

Going by SKILL.md and its folder, Linux Desktop Control needs the command-line tools its instructions call (jq, claude, codex, npm and cargo). Our summary lists: A local Linux desktop session; Node.js 18 or newer for the CLI and MCP server, or Rust to install with cargo; For Pi native tools: Pi 0.84.4 or newer and Node.js 22.19 or newer. Compatibility (from SKILL.md): Native Pi tools require Pi 0.84.4+ and Node.js 22.19+; the standalone CLI/MCP server supports Node.js 18+..

Does Linux Desktop Control access the network?

SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Linux Desktop Control safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Linux Desktop Control use?

Linux Desktop Control is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Linux Desktop Control use?

About 2.7k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.5k tokens, read only when the agent opens those files.

What are the alternatives to Linux Desktop Control?

Skills that share tags, products or a category with Linux Desktop Control: Browser MCP Agent (antibrow/anti-detect-browser-skills, 914 stars), Isolated Linux Agent Workspace (agent-sh/agent-workspace-linux, 185 stars), Code Review (oaslananka/kicad-mcp-pro, 119 stars) and Open Computer Use (iFurySt/open-codex-computer-use, 2.3k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Linux Desktop Control?

agent-sh (a GitHub organization) maintains it in agent-sh/computer-use-linux, which has 661 GitHub stars. The repository was last updated on October 4, 2026.

Source: agent-sh/computer-use-linux on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.