# input.type_text

Type a Unicode string into the currently focused control via native input. Does not click first — focus the field (input.click_target / input.send_actions) before calling. Side effect: keystrokes on the remote desktop. For form fills (click → type → tab/enter), prefer input.send_actions in one call.

Agent View of the PolicyLayer registry record for `input.type_text`. HTML page: https://policylayer.com/tools/com-glasswarp-mcp-server/input.type-text

## Facts

- Tool: `input.type_text`
- Server: Glasswarp (`https://mcp.glasswarp.com/mcp`) — https://policylayer.com/tools/com-glasswarp-mcp-server.md
- Homepage: https://github.com/glasswarp/mcp-server
- Risk category: Execute (High risk)
- Registry record: grade F, identity unverified
- Server auth posture: open
- Server rate-limited: no
- Parameters: 2 (2 required)
- Recommended policy verdict: Rate-limited

## Parameters

| Parameter | Type | Required | Description |
| --- | --- | --- | --- |
| `text` | string | yes | Literal text to type (not a key combo) |
| `session_id` | string | yes | Active session id |

Parameters from the server's own tool schema.

## Example call (MCP tools/call, JSON-RPC 2.0)

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "input.type_text",
    "arguments": {
      "text": "<text>",
      "session_id": "<session_id>"
    }
  }
}
```

## Why input.type_text is rated High

This tool executes actions (typing) on a remote system whose effects depend on the argument (the string to type) and the current state of the remote desktop. While typing alone appears benign, in combination with other tools it enables credential entry, command injection into text fields, or manipulation of any application.

From the tool's own definition: "The tool performs keystrokes on a remote Windows PC ('Side effect: keystrokes on the remote desktop'). It takes a Unicode string argument and inputs it into a focused control, which represents direct manipulation of a remote system's input handling."

## Use case

AI agents invoke input.type_text to trigger actions in Glasswarp. What it does depends on the arguments the agent supplies, and its effects often reach beyond the immediate call: builds kicked off, notifications sent, workflows started.

## Recommended policy (PolicyLayer)

Verdict: **Rate-limited**. Enforced by the PolicyLayer MCP gateway (https://policylayer.com/mcp-gateway) before a call reaches Glasswarp:

```json
{
  "version": "1",
  "default": "deny",
  "tools": {
    "input.type_text": {
      "limits": [
        {
          "counter": "input.type_text_rate",
          "window": "minute",
          "max": 10,
          "scope": "grant"
        }
      ]
    }
  }
}
```

## Other tools on Glasswarp (15)

- `app.launch` — Execute — https://policylayer.com/tools/com-glasswarp-mcp-server/app.launch.md
- `input.click_target` — Execute — https://policylayer.com/tools/com-glasswarp-mcp-server/input.click-target.md
- `input.click_xy` — Execute — https://policylayer.com/tools/com-glasswarp-mcp-server/input.click-xy.md
- `input.drag` — Execute — https://policylayer.com/tools/com-glasswarp-mcp-server/input.drag.md
- `input.scroll` — Execute — https://policylayer.com/tools/com-glasswarp-mcp-server/input.scroll.md
- `input.send_actions` — Execute — https://policylayer.com/tools/com-glasswarp-mcp-server/input.send-actions.md
- `input.send_keys` — Execute — https://policylayer.com/tools/com-glasswarp-mcp-server/input.send-keys.md
- `session.end` — Execute — https://policylayer.com/tools/com-glasswarp-mcp-server/session.end.md
- `session.start` — Execute — https://policylayer.com/tools/com-glasswarp-mcp-server/session.start.md
- `demos.get` — Read — https://policylayer.com/tools/com-glasswarp-mcp-server/demos.get.md
- `demos.list` — Read — https://policylayer.com/tools/com-glasswarp-mcp-server/demos.list.md
- `rigs.list` — Read — https://policylayer.com/tools/com-glasswarp-mcp-server/rigs.list.md
- `screen.observe` — Read — https://policylayer.com/tools/com-glasswarp-mcp-server/screen.observe.md
- `session.live_view` — Read — https://policylayer.com/tools/com-glasswarp-mcp-server/session.live-view.md
- `session.status` — Read — https://policylayer.com/tools/com-glasswarp-mcp-server/session.status.md

## For agents

This record is a snapshot. Live verdicts and the full registry:

- Check every server in your MCP config at once: `npx -y policylayer stack`
- Vet a server before you add it: install the mcp-precheck skill — `npx skills add https://policylayer.com` (skill text: https://policylayer.com/skill.md)
- Query the registry over MCP: endpoint `https://api.policylayer.com/mcp` — tools `check_mcp_server`, `check_mcp_stack`, `check_tool`, `search_registry`, `get_change_events`

---

Source: the PolicyLayer MCP registry — one continuously verified record per MCP server. Full record: https://policylayer.com/registry?q=com-glasswarp-mcp-server · API: https://policylayer.com/registry/api · Policy library: https://policylayer.com/policies/com-glasswarp-mcp-server
