mcplocal
Local Files MCP server that lets MCP-compatible clients read, search, and modify files inside a sandboxed directory. Provides file management and coding workflow tools with security controls like path boundary enforcement and disabled deletion by default.
README
mcplocal
Local Files MCP server that lets an MCP-capable client (including ChatGPT Web custom MCP apps where available) read, search and modify files inside one explicitly configured directory.
Features
- Legacy HTTP+SSE:
GET /sse+POST /messages - Modern MCP HTTP endpoint:
/mcp - Health check:
/health - Sandbox: every file path is resolved under
MCP_ROOT - Optional Bearer authentication
- Read/search tools for project discovery
- Write/edit tools for coding workflows
- Delete is disabled by default
- No shell/CLI execution tool
- No dependency on an external database
- Node.js 20+
The MCP TypeScript SDK currently recommends Streamable HTTP for remote servers and treats HTTP+SSE as a backwards-compatibility transport. This project intentionally exposes both so older SSE clients can still connect while newer clients can use /mcp.
1. Run
cp .env.example .env
# edit MCP_ROOT if needed
npm start
Example:
MCP_ROOT=~/Projects
MCP_HOST=127.0.0.1
MCP_PORT=8008
MCP_AUTH_TOKEN=change-me
Then:
SSE: http://127.0.0.1:8008/sse
Streamable: http://127.0.0.1:8008/mcp
Health: http://127.0.0.1:8008/health
2. What ChatGPT Web can connect to
ChatGPT Web cannot directly reach localhost from the hosted service. A local MCP server must be made reachable through the supported Secure MCP Tunnel/private-network mechanism. After you have a remote MCP endpoint, add it as a custom MCP app in ChatGPT Developer Mode, scan its tools, and enable it.
For a tunnel that maps the local service, the local origin is:
http://127.0.0.1:8008/sse
or, for modern clients:
http://127.0.0.1:8008/mcp
Do not expose this server to the public internet without authentication and an explicit network policy.
3. Tools exposed to ChatGPT
list_files(path, recursive)read_file(path, startLine, endLine)write_file(path, content, createDirs)edit_file(path, oldText, newText, replaceAll)search_files(query, path, regex, caseSensitive, maxResults)create_directory(path)file_info(path)delete_file(path)only whenMCP_ENABLE_DELETE=true
Typical coding workflow:
list_filesto understand the project.search_filesto locate symbols.read_fileto inspect the relevant code.edit_filefor a surgical change, orwrite_filefor a new file.read_fileagain to verify the result.
4. Security model
MCP_ROOT is the hard boundary. ../ traversal and absolute paths outside it are rejected. Binary/unreadable files are skipped by search. File size is capped by MCP_MAX_FILE_BYTES.
The server intentionally does not expose arbitrary shell execution. That means ChatGPT can edit code but cannot automatically run rm, curl, package managers, git commands, or arbitrary programs through this MCP.
For a development machine, keep MCP_HOST=127.0.0.1 and use the supported Secure MCP Tunnel rather than binding the server to all interfaces.
5. Build
npm run build
node dist/server.js
The build is dependency-free and copies the runtime into dist/.
6. Docker
docker build -t mcplocal .
docker run --rm -p 8008:8008 -v "$PWD:/workspace" mcplocal
7. Example prompts in ChatGPT
Inspect this local project and tell me where the authentication flow is implemented. Do not modify anything.
Open src/server.js and refactor the error handling. Before changing it, read the relevant code. Then edit only the necessary section and show me what changed.
Search the project for TODO comments and create a report at reports/todos.md.
License
MIT
Recommended Servers
playwright-mcp
A Model Context Protocol server that enables LLMs to interact with web pages through structured accessibility snapshots without requiring vision models or screenshots.
Magic Component Platform (MCP)
An AI-powered tool that generates modern UI components from natural language descriptions, integrating with popular IDEs to streamline UI development workflow.
Audiense Insights MCP Server
Enables interaction with Audiense Insights accounts via the Model Context Protocol, facilitating the extraction and analysis of marketing insights and audience data including demographics, behavior, and influencer engagement.
VeyraX MCP
Single MCP tool to connect all your favorite tools: Gmail, Calendar and 40 more.
graphlit-mcp-server
The Model Context Protocol (MCP) Server enables integration between MCP clients and the Graphlit service. Ingest anything from Slack to Gmail to podcast feeds, in addition to web crawling, into a Graphlit project - and then retrieve relevant contents from the MCP client.
Kagi MCP Server
An MCP server that integrates Kagi search capabilities with Claude AI, enabling Claude to perform real-time web searches when answering questions that require up-to-date information.
E2B
Using MCP to run code via e2b.
Neon Database
MCP server for interacting with Neon Management API and databases
Exa Search
A Model Context Protocol (MCP) server lets AI assistants like Claude use the Exa AI Search API for web searches. This setup allows AI models to get real-time web information in a safe and controlled way.
Qdrant Server
This repository is an example of how to create a MCP server for Qdrant, a vector search engine.