Skip to main content
Glama
AxelHu
by AxelHu

chatgpt-web-agent

Capa de pegamento MCP local que permite que la interfaz web de ChatGPT utilice herramientas locales a través del Túnel MCP Seguro de OpenAI.

Esta es una implementación de referencia ejecutable, no un producto listo para instalar con un solo clic; su propósito principal es compartir una vía de integración validada en la práctica, que los usuarios puedan adaptar rápidamente a su propio entorno local con la ayuda de un agente.

La interfaz MCP del proyecto se mantiene estable, y las herramientas reales son proporcionadas por un LocalToolBackend reemplazable. El primer backend reutiliza directamente el SDK del Plugin OpenClaw, sin modificar el código fuente de OpenClaw ni reimplementar las herramientas de archivos, shell, parches y procesos en segundo plano.

Estado actual

P0 proporciona cuatro herramientas de OpenClaw:

  • read

  • exec

  • process

  • apply_patch

Opcionalmente, se pueden habilitar herramientas de intercambio de archivos de Google Drive:

  • drive_list

  • drive_search

  • drive_stat

  • drive_upload

  • drive_download

  • drive_export

  • drive_mkdir

Por defecto, están habilitadas dos herramientas de solo lectura de OpenClaw Skills:

  • skills_list(query?, limit?)

  • skill_read(name)

skills_list() devuelve un directorio compacto de nombres de Skills elegibles y visibles para el modelo; con una query en lenguaje natural, puede devolver un pequeño conjunto de nombres y descripciones candidatos a través de una colección QMD independiente. skill_read solo acepta el nombre/clave de la Skill; la ruta canónica SKILL.md siempre se resuelve mediante skills.status de OpenClaw en tiempo real, sin aceptar rutas de archivo proporcionadas por el cliente. Las instrucciones de inicialización de MCP también indicarán al cliente: solo descubrir Skills activamente cuando la tarea claramente pueda depender de herramientas, servicios, flujos de trabajo o normas operativas locales y el contexto actual sea insuficiente; las tareas autónomas comunes no consultan Skills.

Por defecto, solo se permite que las herramientas de archivos y parches accedan al workspace configurado; exec.workdir también debe estar dentro del workspace. Los parámetros internos de host/security/ask/node/elevated de OpenClaw no se exponen al cliente MCP.

Para conectores independientes autorizados solo para un workspace de ChatGPT de confianza, se puede establecer CHATGPT_WEB_AGENT_WORKSPACE_ONLY=false; en este modo, el workspace es solo el punto de referencia para rutas relativas y el cwd predeterminado, y read/apply_patch/exec.workdir puede acceder a rutas absolutas externas. Este modo no es un sandbox de seguridad.

El límite de exec.workdir no es un sandbox de comandos. Un cliente con permiso exec aún puede acceder a otras partes del sistema en el texto del comando; solo se debe autorizar el Túnel a un workspace de ChatGPT de confianza y utilizar las políticas de allowlist/approval de OpenClaw según sea necesario.

Related MCP server: agent-mcp-gateway

Desarrollo

Requiere Node.js 22.22.3 o una versión compatible de OpenClaw Node, y pnpm.

pnpm install
pnpm check
pnpm smoke

Ejecución

export CHATGPT_WEB_AGENT_WORKSPACE=/path/to/workspace
# 可信独立 Connector 如需把 workspace 仅作为默认工作目录:
# export CHATGPT_WEB_AGENT_WORKSPACE_ONLY=false
pnpm build
node dist/cli.js

El servicio utiliza MCP stdio; la salida estándar solo transporta el protocolo MCP.

Configuración

Copia .env.example para ver las variables de entorno disponibles. La lista blanca de herramientas predeterminada es:

read,exec,process,apply_patch

exec usa por defecto allowlist + on-miss. Se puede sobrescribir explícitamente:

export CHATGPT_WEB_AGENT_EXEC_SECURITY=allowlist
export CHATGPT_WEB_AGENT_EXEC_ASK=on-miss

Para una primera prueba de humo local de confianza, se puede usar temporalmente:

export CHATGPT_WEB_AGENT_EXEC_SECURITY=full
export CHATGPT_WEB_AGENT_EXEC_ASK=off

Arquitectura

ChatGPT Web
  → OpenAI Secure MCP Tunnel
  → chatgpt-web-agent MCP Server
  → LocalToolBackend
      → OpenClawBackend
      → SkillsBackend → OpenClaw Gateway (live status)
                      → QMD MCP (optional semantic discovery)
      → NativeBackend / other backend(后续按需)

El backend de Skills solo realiza descubrimiento/lectura de capacidades; QMD es solo un acelerador de búsqueda de candidatos; el inventario en tiempo real de OpenClaw es siempre la fuente de verdad para elegibilidad, visibilidad del modelo y rutas canónicas de Skills.

Descubrimiento semántico de Skills

Se recomienda colocar el catálogo semántico en un índice QMD nombrado independiente, en lugar de compartir el índice de memoria. El ANN vectorial de QMD 2.5.3 primero toma candidatos de todo el índice y luego aplica el filtro de colección; mezclar unas decenas de Skills entre decenas de miles de documentos de memoria haría que la colección pequeña se viera inundada por candidatos de toda la base.

El despliegue actual utiliza:

local catalog: <workspace>/skills-catalog/
M4 mirror:     ~/qmd-data/skills-chatgpt-web-agent/
QMD index:     skills-chatgpt-web-agent
collection:    skills-chatgpt-web-agent
MCP endpoint:  http://192.168.0.96:8182/mcp

La recuperación usa Qwen3-Embedding-0.6B, solo vectorial, rerank=false, sin query expansion / HyDE. Los aciertos de QMD son solo candidatos; antes de devolverlos, se cruzan con skills.status en vivo. El esquema/inventario del catálogo se invalida por generación mediante catalogHash; cuando QMD no está disponible o el catálogo está obsoleto, se retrocede automáticamente al catálogo de solo nombres en vivo.

Google Drive

Drive es un canal de datos opcional; no realiza sincronización en segundo plano, montaje de disco ni duplicación completa del disco. La implementación utiliza directamente la API v3 de Google Drive; MCP solo expone primitivas pequeñas y estables para operaciones con archivos.

De forma predeterminada, las rutas locales de carga/descarga/exportación de Drive solo pueden estar en:

<CHATGPT_WEB_AGENT_WORKSPACE>/exchange

Esta restricción es independiente de CHATGPT_WEB_AGENT_WORKSPACE_ONLY y sirve para reducir el riesgo de que las herramientas de Drive se utilicen indebidamente como canal de transferencia arbitraria de datos locales. Si es necesario, el implementador puede ajustarlo mediante CHATGPT_WEB_AGENT_DRIVE_LOCAL_ROOT y CHATGPT_WEB_AGENT_DRIVE_LOCAL_ROOT_ONLY.

Configuración OAuth única

  1. Habilita la API de Drive en Google Cloud y crea un cliente OAuth de escritorio.

  2. Guarda el JSON de OAuth descargado como:

    <workspace>/.credentials/google-drive/credentials.json

    o establece CHATGPT_WEB_AGENT_DRIVE_CREDENTIALS para que apunte a otra ruta local privada.

  3. Ejecuta:

    CHATGPT_WEB_AGENT_WORKSPACE=/path/to/workspace pnpm drive:auth

    Después de la autorización en el navegador, se generará un token de usuario autorizado con permisos 0600. El secreto del cliente OAuth y el token de actualización no deben enviarse a Git ni devolverse a través de MCP.

  4. Al iniciar el servicio, establece:

    export CHATGPT_WEB_AGENT_DRIVE_ENABLED=true

En las herramientas de Drive, folderId / fileId utilizan directamente los IDs de la API de Drive. Los archivos binarios comunes usan drive_download; los documentos de Google Docs/Sheets/Slides usan drive_export para exportar al tipo MIME especificado.

Available Tools

6 tools
apply_patchapply_patchC

Apply a patch to one or more files using the apply_patch format. The input should include *** Begin Patch and *** End Patch markers.

ParametersJSON Schema
NameRequiredDescriptionDefault
inputYesPatch content using the *** Begin Patch/End Patch format.

TDQS

C2.9/5.0
Behavior2/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

No annotations are provided, so the description must fully disclose behavior. It states the tool applies patches and uses markers, but it does not mention side effects like file modification, potential for partially applied patches, rollback capability, or whether it creates files that don't exist. Key behavioral traits are missing.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is brief and front-loaded with the core purpose. It uses two sentences effectively, but the repeated mention of 'apply_patch format' is slightly redundant.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness2/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given the tool modifies files, it lacks details on safety, rollback, or how partial patches are handled. With no output schema and no annotations, the description should cover failure modes and post-conditions, which it omits.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100%, and the description adds minor context about the format markers beyond the schema's generic 'Patch content' description. However, it does not explain the patch syntax (e.g., unified diff), allowed operations, or error handling if format is invalid.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states the tool applies a patch to files and specifies the patch format with markers. However, it does not distinguish itself from siblings like 'exec' or 'process', which might also apply changes.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines2/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

No guidance on when to use this tool vs alternatives like 'read' or 'exec'. The description lacks context on prerequisites, such as whether files must exist or be writable, and does not mention that 'apply_patch' is specifically for applying patch diffs versus directly editing files.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

execexecA

Execute shell commands with background continuation for work that starts now. Use yieldMs/background to continue later via process tool. For long-running work started now, rely on automatic completion wake when it is enabled and the command emits output or fails; otherwise use process to confirm completion. Use process whenever you need logs, status, input, or intervention. Use pty=true for TTY-required commands (terminal UIs, coding agents).

ParametersJSON Schema
NameRequiredDescriptionDefault
envNo
ptyNoRun in a pseudo-terminal (PTY) when available (TTY-required CLIs, coding agents)
commandYesShell command to execute
timeoutNoTimeout in seconds (optional, kills process on expiry)
workdirNoWorking directory. Blank/whitespace values are invalid; omit to use the default cwd.
yieldMsNoMilliseconds to wait before backgrounding (default 10000)
backgroundNoRun in background immediately

TDQS

A4.4/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations provided, the description carries the full burden of behavioral disclosure. It explains backgrounding behavior, automatic completion wake, and the necessity of using 'process' for interaction. However, it does not detail security restrictions, output handling, or timeout effects beyond what is in the schema.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is four sentences, front-loaded with the core purpose, followed by concise usage rules. Every sentence contributes unique information with no redundancy or filler.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

The tool has no output schema, so the description should clarify return values. It does not mention what the initial call returns (e.g., immediate output or a handle). However, it covers the backgrounding workflow, including the role of 'process' for logs and status, making the overall completeness high despite the ambiguity about immediate response.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is high (86%), so baseline is 3. The description adds usage context for 'yieldMs', 'background', and 'pty', but does not significantly elaborate on parameter meaning beyond what the schema already provides. It ties parameters to scenarios but does not introduce new semantic information.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states 'Execute shell commands' and elaborates on background continuation, distinguishing itself from sibling tools like 'process' which handles logs/status. It provides a specific verb-resource combination and explicitly differentiates usage.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description gives explicit guidance on when to use alternative tool 'process' (for logs, status, input, intervention) and when to enable 'pty=true' (TTY-required commands). It also explains the 'yieldMs/background' mechanism for continuing work later, leaving no ambiguity about context.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

processprocessA

Manage running exec sessions for commands already started: list, poll, log, write, send-keys, submit, paste, kill. Use poll/log when you need status, logs, quiet-success confirmation, or completion confirmation when automatic completion wake is unavailable. Use poll/log also for input-wait hints. Use write/send-keys/submit/paste/kill for input or intervention.

ParametersJSON Schema
NameRequiredDescriptionDefault
eofNoClose stdin after write
hexNoHex bytes to send for send-keys
dataNoData to write for write
keysNoKey tokens to send for send-keys
textNoText to paste for paste
limitNoLog length
actionYesProcess action (list|poll|log|write|send-keys|submit|paste|kill|clear|remove)
offsetNoLog offset
literalNoLiteral string for send-keys
timeoutNoFor poll: wait up to this many milliseconds before returning; max 30000 ms, higher values are clamped to 30000
bracketedNoWrap paste in bracketed mode
sessionIdNoSession id for actions other than list

TDQS

A4.4/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations, the description carries full burden. It discloses that the tool manages running sessions and that poll can wait up to 30000 ms (clamped). However, it doesn't mention that actions modify session state (e.g., writing data, killing), which is reasonably inferred. It also doesn't state that list returns session IDs needed for other actions, though the schema makes that somewhat clear. Very good but not exhaustive.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is a tight 4-sentence paragraph. The first sentence front-loads all actions and the tool's purpose. The next two sentences give precise when-to-use guidance. The last sentence covers the remaining actions. Every sentence earns its place; no filler.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given 12 parameters, 100% schema coverage, and no output schema, the description fills the behavioral gap well. It explains when to use each action type. The only missing element is a brief note that some actions (e.g., kill) are destructive or irreversible, which would have pushed completeness to 5. Still strong and sufficient for an agent.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100%, so baseline is 3. The description does not add meaning beyond schema property descriptions – it simply names the action groups. The schema already describes each property's purpose (e.g., 'Hex bytes to send for send-keys'). The description adds no new parameter details or usage patterns, so it stays at baseline.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description lists all eight supported actions (list, poll, log, write, send-keys, submit, paste, kill) and clearly states the tool manages running exec sessions. It even details specific use cases like confirming completion or getting input-wait hints. This fully distinguishes it from siblings like exec (which starts sessions) and read/apple_patch (which operate on files).

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

It explicitly tells the agent when to use poll/log for status, logs, or input-wait hints, and when to use write/send-keys/submit/paste/kill for input/intervention. It also mentions the fallback when automatic completion wake is unavailable, giving actionable guidance to select among the tool's own actions. No sibling-level exclusions are needed because the tool manages already-started sessions – distinct from siblings.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

readreadA

Read the contents of a file. Supports text files and images (jpg, png, gif, webp, bmp). Images are sent as attachments. For text files, output is truncated to 2000 lines or 50KB (whichever is hit first). Use offset/limit for large files. When you need the full file, continue with offset until complete.

ParametersJSON Schema
NameRequiredDescriptionDefault
pathYesPath to the file to read (relative or absolute)
limitNoMaximum number of lines to read
offsetNoLine number to start reading from (1-indexed)

TDQS

A4.6/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations provided, the description fully discloses behavioral traits: truncation to 2000 lines or 50KB, offset/limit pagination, and image handling as attachments. This goes well beyond the input schema's parameter descriptions, providing critical operational details.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is three sentences long, front-loaded with the purpose, and every sentence provides essential information. No unnecessary words or repetition, making it highly efficient for an AI agent to parse.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given the tool's simplicity (3 parameters, no output schema), the description covers purpose, supported file types, truncation limits, and pagination strategy. It does not explicitly describe the return format for text files, but the information provided is sufficient for most use cases. A minor gap for completeness.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%, so the baseline is 3. The description adds value by explaining the intended use of offset/limit for pagination ('Use offset/limit for large files') and clarifying that offset is 1-indexed, which is implicit in the schema but reinforced here.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states the specific verb 'read' and resource 'file', and lists supported file types (text and images). It distinguishes from sibling tools like 'exec' (command execution) and 'skill_read' (reading skills) by focusing on general file reading.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description provides clear guidance on when to use the tool (for reading text and image files) and how to handle large files via offset/limit pagination ('use offset/limit for large files'). It lacks explicit exclusions (e.g., binary files other than images) but the context is sufficient for correct usage.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

skill_readA

Read one currently eligible/model-visible OpenClaw Skill by its name or skillKey. Use after skills_list identifies a likely match. This tool does not accept filesystem paths.

ParametersJSON Schema
NameRequiredDescriptionDefault
nameYes

TDQS

A4.4/5.0
Behavior3/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations, the description carries full burden. It mentions 'currently eligible/model-visible' but does not specify behavior on missing skills, read-only guarantee, or potential errors. The description is minimal regarding side effects or failure conditions.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Two concise sentences, no redundant wording. Every clause adds value—purpose, usage timing, and a key constraint.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness3/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given no output schema, the description could clarify what is returned (e.g., skill content, metadata). It does not mention output details, but the tool's purpose is clear enough for selection. Slightly incomplete in describing the full interaction.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters5/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

The only parameter 'name' is clarified to accept either the skill name or skillKey, and explicitly excludes filesystem paths. This adds significant meaning beyond the bare string type, compensating for the lack of schema-level description.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states the tool reads a skill by name or skillKey, distinguishing it from sibling tools like skills_list (which lists) and read/apply_patch/exec/process (which operate on files or processes). It is specific and unambiguous.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Explicitly instructs to use after skills_list identifies a likely match, and provides a clear constraint (does not accept filesystem paths). This fully guides when and how to use the tool.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

skills_listA

Discover local OpenClaw Skills available to ChatGPT Web. Pass a natural-language task description in query to get a small semantic top-k with descriptions. Without query, returns the compact names-only live catalog. Only currently eligible and model-visible Skills are surfaced.

ParametersJSON Schema
NameRequiredDescriptionDefault
limitNoMaximum semantic candidates; defaults to 8.
queryNoNatural-language task or capability to discover.

TDQS

A3.9/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

No annotations present, so description carries full burden. It explains the tool surfaces only 'currently eligible and model-visible Skills' and describes two distinct outputs. This is adequate for a read-operation.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Two sentences pack purpose, dual behavior, and constraints with zero waste. Every sentence contributes meaning.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given the tool's simplicity (2 optional params, no output schema, no annotations), the description covers core functionality, parameter options, and eligibility. It could mention the return format, but is largely complete.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100%, so baseline is 3. Description adds value by explaining that 'query' triggers semantic top-k search with descriptions, while omitting it yields a names-only catalog. This clarifies the parameter's effect beyond the schema.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states that the tool discovers local OpenClaw Skills for ChatGPT Web. It distinguishes between query and no-query modes, but doesn't explicitly differentiate from sibling tool 'skill_read'.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Provides clear context on when to pass a query vs. not, but does not mention alternatives or when to avoid using this tool.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Tool Schema Changelog

Recent tool additions, removals, and schema changes observed during successful MCP inspections.

  1. 6 tool updatesv0.1.0
    • First observedapply_patch
    • First observedexec
    • First observedprocess
    • First observedread
    • First observedskill_read
    • First observedskills_list

TDQS

A4/5.0

Scored across 6 tools

Disambiguation5/5

Each tool has a distinct purpose: file reading, patch application, command execution, process management, and skills listing/reading. Descriptions clearly differentiate them.

Naming Consistency4/5

Most tools use verb-like names with a mix of underscore and no-underscore styles (e.g., 'read' vs 'skills_list'). The convention is not fully uniform but remains understandable.

Tool Count5/5

Six tools is appropriate for a coding-agent server, covering core operations without being excessive or sparse.

Completeness5/5

The suite covers file access, modifications, command execution, background process management, and skill discovery, leaving no obvious gaps for common agent workflows.

Maintenance

ActivityActive
ResponsivenessResponsive

Related MCP Connectors

Related MCP Servers

  • F
    license
    Not graded
    quality
    B
    maintenance
    Enables ChatGPT Web to securely access local files and run commands via MCP, with optional OpenCode agent mode for autonomous tasks.
    -
  • A
    license
    Not graded
    quality
    C
    maintenance
    Turns ChatGPT web into a local coding agent, enabling file edits, shell commands, Git operations, patches, and process management through 40+ MCP tools.
    MIT