ScopeRail
Provides Git publishing capabilities with read operations separate from parameter-bound publish grants.
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@ScopeRailopen a shell session and show git status in my workspace"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
ScopeRail
ScopeRail is a scoped local execution runtime for MCP clients that need to work on a real Mac without receiving unrestricted host access by default. Files, processes, browser sessions and native desktop UI are exposed through one workspace capability model with explicit grants and auditable actions.
It is not just a shell MCP. Shell access is one surface inside a broader permission model: a caller starts from a registered workspace, receives only the profiles and grants the operator enabled, and uses retry-safe primitives that return provenance and observable results.
Install and run
Python 3.12+ and pipx on macOS:
brew install pipx # skip if pipx is already installed
pipx install "https://github.com/HanpuLi/scoperail/releases/download/v0.2.2/scoperail-0.2.2-py3-none-any.whl"
SCOPERAIL_WORKSPACE_ROOT="$PWD" scoperail stdioThe tagged GitHub wheel is the current working install path and is tested with pipx. PyPI Trusted Publishing is prepared but the first PyPI upload still requires the maintainer's one-time PyPI login; after that, pipx install scoperail is equivalent.
Or register once, then start stdio:
scoperail init "$PWD"
scoperail stdioFor the full OAuth HTTP service, launchd installation and optional reverse-proxy/Tailscale deployment, see docs/install.md.
Security:
sandboxedexecution is the default.trusted-host, desktop control, Git publishing and similar capabilities are explicit operator choices. Read SECURITY.md and docs/security-model.md before enabling them.
Related MCP server: wisp
What is different
Surface | Boundary |
Files | Workspace-confined paths, symlink-aware resolution, conflict-checked writes |
Commands / PTY | macOS Seatbelt sandbox by default; explicit |
Persistent shells | Named zsh sessions built on the same job/process boundary |
Browser | Managed Playwright profile plus explicit attachment to loopback Chromium CDP sessions |
Native UI | macOS Accessibility semantic tree and fingerprinted refs, with coordinate fallback |
Git publish | Read operations are separate from parameter-bound publish grants |
Audit/state | Request IDs, provenance, audit records, persistent workspace state |
ScopeRail does not embed a model. The connected client decides what to do; ScopeRail enforces and records the execution boundary.
MCP client
|
+-- local stdio --------------------------------+
| |
+-- OAuth 2.1 / remote HTTPS -- public plane ---+
v
workspace + grant policy
| | |
+----------+ | +----------+
v v v
files/git jobs/shells browser/native UI
| | |
+-------- audit + provenance --------+Platform and client status
ScopeRail is macOS-first. Native Accessibility control and the Seatbelt sandbox are macOS features. Pure policy/file/package tests may run on Linux CI, but Linux and Windows are not currently advertised as complete runtime platforms.
Generic MCP clients: local stdio transport is supported.
ChatGPT: remote OAuth/streamable-HTTP is the primary deployed integration and is exercised by the project.
Claude / Codex / other MCP clients: the stdio server uses the standard MCP SDK transport; client-specific setup is documented as integration work rather than claimed as continuously tested compatibility.
Native semantic UI
The native desktop path prefers Accessibility over coordinate-only clicking. Observation returns semantic elements and bounds; element actions use fingerprinted ax: refs and fail closed when the target becomes stale, ambiguous or materially moves. Secure values are redacted and secure fields reject semantic value-setting.
Screenshot, mouse and keyboard primitives remain available for apps with incomplete Accessibility trees.
Browser sessions
The managed browser uses a ScopeRail-owned profile. A trusted-host workspace may also attach to an already-running Chromium-family browser only through an operator-configured loopback DevTools endpoint. Existing tabs are treated as external resources: detaching the bridge does not close them.
Remote service
A source checkout can run the full HTTP service with OAuth 2.1, PKCE, dynamic client registration, token rotation/revocation and DNS-rebinding protections. The admin plane listens separately on loopback and is not exposed through the public MCP route.
See docs/quickstart.md, docs/permissions.md, docs/workspaces.md, docs/files.md, and docs/audit.md.
Development
python3 -m venv .venv
. .venv/bin/activate
pip install -e '.[dev]'
python -m unittest discover -s tests -p 'test_*.py' -v
ruff check --select E9,F63,F7,F82 bridge tests scripts
python -m build
twine check dist/*The maintainer's operational repository may contain machine-specific acceptance evidence. Release candidates are produced as an allowlisted fresh-history tree before they reach this public repository. scripts/verify_public_tree.py, CI secret scanning and package checks enforce the public-tree invariants; the private operational Git history is never imported here.
Contributing
Start with CONTRIBUTING.md, the architecture and the security model. Issues intended for contributors describe the problem and acceptance criteria; the project does not create trivial work to inflate contributor counts.
License
Apache-2.0. See LICENSE and THIRD_PARTY_NOTICES.md.
This server cannot be deployed
Maintenance
Related MCP Connectors
- gatewayOAuthai.sealgate
MCP gateway with runtime security policy, tool-call-level control, and audit of agent actions.
MCP server for mandates, delegation, policy-gated execution, credential grants, and audit.
Remote MCP for Copilot CLI switch gate MCP, structured receipts, audit logs, and reviewer-ready evid
Remote MCP for A2A caller identity, scope policy, verdict receipts, and audit history.
Related MCP Servers
- AlicenseAqualityBmaintenanceA macOS computer-use MCP server that grants AI agents mouse, keyboard, and screen control with a robust security model including permission profiles, app deny-lists, and audit logging.22MIT
- AlicenseNot gradedqualityBmaintenanceProvides bounded, observable access to graphical apps, browsers, terminals, Android devices, virtual machines, and SSH hosts through MCP tools, enabling safe automation and app QA.109 npmApache 2.0
- AlicenseNot gradedqualityCmaintenanceEnables bounded agent authority over a macOS workstation via 63 MCP tools with policy, approval, and audit.2 npmApache 2.0
- AlicenseNot gradedqualityCmaintenanceEnables an MCP client to safely access selected local files and trusted executables with policy control, audit, and rollback via a Windows control center.Apache 2.0