Skip to main content
Glama

osmcp — OS Capabilities for AI Agents

A typed, policy-controlled OS capability layer for AI agents via the Model Context Protocol (MCP).

osmcp exposes a curated set of safe filesystem, git, and text-processing tools to AI agents — all governed by a strict Policy Engine that enforces path boundaries, tool allowlists, output limits, mutation controls, and an immutable audit trail.

📖 Read the comprehensive Architecture & Design Document for a deep dive into the philosophy, safety boundaries, and design decisions behind osmcp.

LiteLLM Compatible Smithery Verified

Features

Category

Tools

Phase

🔍 Search

grep, find

1

📁 File Inspection

ls, cat, stat, wc, head, tail

1

🌳 Filesystem

tree, du

1

🔀 Git Intelligence

git_status, git_diff, git_log

1

🔧 Transform

jq, sed, diff

1

✍️ File Mutation

write_file, append_file, mkdir, rm, mv, cp, patch

2

🚀 Git Mutation

git_add, git_commit, git_checkout, git_branch, git_pull, git_push

2

Related MCP server: core-agent-mcp

Architecture

AI Agent (Claude, GPT, etc.)
    │  MCP JSON-RPC (stdio)
    ▼
osmcp binary
    ├── Policy Engine      ← enforces allowed_root, allowed_tools, limits
    ├── Audit Logger       ← append-only NDJSON log of every invocation
    ├── Tool Registry      ← self-registering tools via RegisterMCP()
    └── Envelope Builder   ← typed {ok, data, error, meta} responses

Demo

osmcp Demo Action A demonstration of Claude Desktop securely editing code via osmcp, safely bounded by a TOML policy engine.

Quick Start

1. Install via Homebrew

brew tap KrushnaVardhanReddy/tap
brew install osmcp

Alternatively, build from source:

make build
# Binary: bin/osmcp

2. Configure a Policy

# policy.toml
[policy]
allowed_root   = "/home/user/myproject"
allowed_tools  = ["grep", "ls", "cat", "git_status", "git_log"]
allow_mutation = false

[limits]
timeout_ms       = 5000
max_output_bytes = 1048576
max_matches      = 100

[audit]
destination = "stderr"   # or "file"
path        = "/var/log/osmcp-audit.ndjson"

3. Run

bin/osmcp --policy policy.toml

The binary communicates over stdio using MCP JSON-RPC. Connect any MCP-compatible client.

Client Integrations

Claude Desktop

Add the following to your claude_desktop_config.json:

{
  "mcpServers": {
    "osmcp": {
      "command": "osmcp",
      "args": ["--policy", "/absolute/path/to/policy.toml"]
    }
  }
}

Smithery (npx)

To install osmcp for Claude Desktop automatically via Smithery:

npx @smithery/cli install osmcp

LiteLLM

Integrate osmcp into your enterprise LLM proxy using the LiteLLM MCP Gateway.

5. Test

make test     # unit tests
make e2e      # end-to-end tests against real binary
make lint     # golangci-lint

Policy Security Model

  • allowed_root — All filesystem paths are validated to be inside this root. Traversal outside is blocked with POLICY_DENIED.

  • allowed_tools — Only tools in this list are visible to the MCP client. Unlisted tools do not appear in tools/list.

  • allow_mutation — When false, mutating tools (write, delete, git commit) are globally blocked.

  • Limits — Per-invocation timeout, output byte cap, and match count cap prevent runaway operations.

Envelope Response Format

All tool responses follow a consistent typed envelope:

{
  "ok": true,
  "tool": "grep",
  "data": { ... },
  "error": null,
  "meta": {
    "execution_time_ms": 12,
    "truncated": false
  }
}

License

MIT

Acknowledgements

osmcp would not be possible without the incredible open-source libraries it is built upon:

  • mcp-go for the core Model Context Protocol SDK.

  • go-git for pure Go git manipulation.

  • gojq for pure Go JSON processing.

  • go-gitdiff for parsing and applying patches.

  • grep-go for regular expression searching.

  • toml for configuration parsing.

Tool Schema Changelog

Recent tool additions, removals, and schema changes observed during successful MCP inspections. Dates show when Glama detected each change.

No tool schema history has been recorded yet.

Maintenance

ActivityMaintained
ResponsivenessNo issues

Resources

Unclaimed servers have limited discoverability.

Looking for Admin?

If you are the server author, to access and configure the admin panel.

Related MCP Connectors

Related MCP Servers

  • A
    license
    Not graded
    quality
    C
    maintenance
    Remote execution layer for agentic systems exposing 64 production tools via MCP for file, network, system, text, git, crypto, and monitoring operations.
    MIT
  • F
    license
    Not graded
    quality
    C
    maintenance
    Secure local development platform that exposes controlled developer capabilities (FS, Git, search, command execution) to AI assistants via MCP with deny-by-default security and audit logging.
    -
  • A
    license
    Not graded
    quality
    B
    maintenance
    A local-first MCP server that lets AI agents use gated APIs without holding keys, enforcing declarative policies, injecting secrets server-side, and auditing access without content.
    2
    Apache 2.0

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/KrushnaVardhanReddy/osmcp'

If you have feedback or need assistance with the MCP directory API, please join our Discord server