wyrd-mcp
Wyrd is a read-only MCP server that exposes exactly one granted folder of files to an AI client and refuses access outside that folder.
Read any file inside the granted folder, including hidden files and directories such as
.git,.env, and.ssh.Serve files to MCP clients like Claude Code, Codex, Cursor, ChatGPT, and Claude Desktop over local stdio.
Request byte-bounded slices with
path,offset, andlimit; continue long reads usingnext_offsetandtruncatedflags.Use paths relative to the granted folder; absolute paths, drive-relative paths, and
..traversal are refused.Receive clear refusals that name the rule fired, distinguishing outside-grant paths from nonexistent files.
Read only valid UTF-8 content; non-UTF-8 bytes are refused with
NOT_TEXTrather than silently altered.Detect Mage vault structure (
Arc/andMage/layers) when present, but treat ordinary folders identically.Keep data local: no network connections, no telemetry, nothing leaves the machine via wyrd itself.
Nothing limits total bytes read, and no extension or ignore-file filtering applies within the granted folder.
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@wyrd-mcpfind my notes about the 2025 budget and summarize them"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
wyrd
An MCP server that exposes one folder of Markdown to an AI client, read-only.
Point Claude Code, Codex, Cursor, ChatGPT or Claude Desktop at a folder of notes and let it read them. Wyrd serves exactly the folder you grant and refuses everything else, and it tells you plainly what that means before you grant anything.
If the folder happens to be a Mage vault — one organised into Arc/ and Mage/ layers — wyrd
notices and says which layers it found. If it is an ordinary folder of notes, it works the same
way; vault structure is a detected bonus, never a requirement.
Install
npm install -g wyrd-mcpNode 20 or newer.
Related MCP server: Obsidian MCP Tools
Use
Wyrd refuses to start until you grant it a folder. Grant one on the command line or in the environment:
wyrd-mcp --grant /absolute/path/to/notes
WYRD_GRANT=/absolute/path/to/notes wyrd-mcpClaude Code — save as wyrd.mcp.json and pass --mcp-config wyrd.mcp.json:
{
"mcpServers": {
"wyrd": {
"command": "wyrd-mcp",
"args": ["--grant", "/absolute/path/to/notes"]
}
}
}Codex — MCP servers arrive as config overrides:
codex exec -c 'mcp_servers.wyrd.command="wyrd-mcp"' \
-c 'mcp_servers.wyrd.args=["--grant","/absolute/path/to/notes"]' "..."Other clients take a command and args in their own MCP configuration; the shape is the same.
What it can reach — read this before granting
Wyrd serves the folder you name, read-only. It does not serve anything above it.
⚠ EVERY file inside that folder can be read, of any type, including hidden files and directories
such as .git, .env and .ssh. There is no extension filter and no ignore-file support. Grant a
subfolder containing only what you mean to share.
A path that resolves outside the granted folder is refused, and the refusal names the rule that fired rather than pretending the file is absent.
Known limits, stated before you grant rather than after
A containment claim without its limits would be false, so:
A hard link created inside the granted folder can reach a file outside it.
A path component swapped between validation and opening may be read instead of the one checked. Both of these need write access to the granted folder.
Some filesystem reparse points are invisible to this runtime and are not detected at all — not partially. ⚠ This one needs no attacker: an ordinary cloud-synced or WSL-mounted folder can contain one in normal use.
A refusal distinguishes "outside the grant" from "does not exist", which tells a caller one bit about whether a file outside the folder exists.
This list is what is known, not a proof that nothing else exists. The limits were measured on Windows; behaviour on macOS and Linux is reasoned but unmeasured, and the package declares no OS restriction.
What leaves your machine
Nothing, by wyrd. It is a local stdio server: it reads files and hands them to the client that launched it. It opens no network connection and phones nothing home.
⚠ What your AI client does with the content is between you and that client. Wyrd cannot see or control that, and no server on this side of the protocol can.
Tests
npm test # the full battery
npm run test:portable # the arms that need no symlink privilege⚠ npm test needs the Windows symlink privilege (Developer Mode, or an elevated shell) because
most fence arms build link fixtures. Without it the suite refuses to run rather than skipping, so
a green never means "the arms that could run, ran."
npm run test:portable runs the arms that need no privilege and states its own denominator — how
many ran, how many were held back, and which. A green there is not a green fence; it is a partial run
that says so.
Licence
MIT. See LICENSE.
wyrd — Old English, "that which has become": the accumulated weight of what has already happened, constraining what can happen next.
Available Tools
1 toolreadRead a file from the granted folderA
Read a byte-bounded slice of one file from the single folder this server was granted.
Paths are relative to the granted folder, for example Mage/projects/legend.md. Absolute
paths, Windows drive-relative paths such as C:notes, and any path that climbs out with
.. are refused.
Reads are byte-oriented, never character-oriented. offset and limit are byte counts
into the file's UTF-8 encoding. A returned slice may be up to 3 bytes shorter than limit
so that it ends on a whole codepoint.
If the file is longer than the slice, the response says truncated: true and gives
next_offset. Call again with that offset to continue; following next_offset to
exhaustion reconstructs the UTF-8 text byte for byte. This server never returns a silently
shortened file — if content is missing, the response says so.
Every path is validated against the granted folder before anything is opened, and a refusal names the rule that fired rather than pretending the file is absent.
WHAT IS IN SCOPE, since the boundary is a folder and not a file type: EVERY file inside the
granted folder can be requested, including hidden files and directories such as .git,
.env and .ssh. There is no extension filter, no ignore-file support, and no cap on how
much may be read in total. The granted folder is the whole of the restriction.
What comes BACK is text. A requested slice that is not valid UTF-8 is refused with
NOT_TEXT rather than returned with substituted characters — a file that comes back altered
but looks complete is worse than one that is refused. Note this is a property of the BYTES,
not the file extension: a .bin whose contents happen to be valid UTF-8 is returned, and a
.md saved in Latin-1 is refused. Nothing here is a filter on what may be reached.
KNOWN LIMITS of that restriction, stated because a containment claim without them would be false: a hard link created inside the folder can reach a file outside it; a folder or path component swapped after validation may be read instead of the one checked; and some filesystem reparse points are invisible to this runtime and are not detected at all — that last one needs no attacker and can occur in an ordinary cloud-synced folder. This list is what is known, not a proof that nothing else exists.
| Name | Required | Description | Default |
|---|---|---|---|
| path | Yes | Path to the file, relative to the granted folder. Forward or back slashes both work. | |
| limit | No | Maximum bytes to return. Defaults to 32768, capped at 262144. | |
| offset | No | Byte offset to start at. Defaults to 0. Use the `next_offset` from a truncated response. |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description carries the full behavioral burden and does so thoroughly. It discloses byte-oriented reads, possible truncation with `next_offset`, refusal rules, the `NOT_TEXT` error for invalid UTF-8, and even known security limitations like hard links and reparse points. This is exemplary transparency beyond what the schema or annotations provide.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is long, but every paragraph earns its place by adding operationally relevant detail. It is front-loaded with the core purpose, followed by path rules, byte semantics, scope, encoding behavior, and known limits, with clear section headers that make it easy for an agent to scan.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Despite having no output schema, the description explains what the response will contain (`truncated: true`, `next_offset`, `NOT_TEXT` refusals) and covers all caller-relevant behavior. An agent has everything needed to use the tool correctly: path constraints, offset/limit semantics, continuation mechanism, edge cases, and security caveats.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Although the schema covers all three parameters, the description adds meaning beyond the schema by explaining that `offset` and `limit` are byte counts into UTF-8 encoding, that a slice may end up to 3 bytes shorter to preserve codepoints, and that callers should use `next_offset` from a truncated response. It also clarifies path semantics with concrete examples and refusal cases.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The first sentence states a specific action and resource: 'Read a byte-bounded slice of one file from the single folder this server was granted.' It precisely defines scope and behavior, making it easy for an agent to know exactly what the tool does even without siblings to distinguish it from.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description gives explicit when-to-use and when-not-to-use guidance: every file inside the granted folder is in scope, absolute paths and `..` traversal are refused, and non-UTF-8 content is refused. The 'WHAT IS IN SCOPE' and 'KNOWN LIMITS' sections provide clear boundary conditions, which fully compensates for the absence of sibling tools.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
TDQS
Only a single tool exists, so there is no possibility of confusing it with another. The tool's purpose is singular and precisely described.
The lone tool name 'read' is a clear, conventional verb that directly matches its action. There are no conflicting naming styles to evaluate.
One tool is at the thin end of the range, but it serves a narrow, well-defined purpose (bounded reads from a single folder). The server is not bloated, yet it feels minimal.
The read operation itself is thoroughly implemented with offset pagination and encoding safeguards, but there is no way to list or stat files in the folder, forcing agents to know exact paths in advance.
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Connectors
Search and reason over your Obsidian-style Markdown vault, right from ChatGPT.
Markdown workspace for AI agents: read, write, organize, and share markdown documents.
Secure AI access to OpenOak tasks, notes, and Kanban boards.
Portable AI memory shared across models and harnesses - plain markdown you own.
Related MCP Servers
- FlicenseNot gradedqualityNot gradedmaintenanceEnables reading and managing markdown note files from a specified directory through natural language interactions.
- AlicenseNot gradedqualityDmaintenanceA read-only toolkit for searching and analyzing Markdown note directories and Obsidian vaults through AI clients. It enables metadata extraction, full-text search, and natural language querying of note content, tags, and backlinks.234AGPL 3.0
- AlicenseNot gradedqualityAmaintenanceEnables AI assistants to search, read, create, update, and remove personal markdown notes stored locally, providing persistent memory across sessions.952MIT
- AlicenseAqualityCmaintenanceEnables AI assistants to interact with a local folder of Markdown notes, supporting listing, reading, searching, creating, and appending to notes with strict security boundaries.5MIT
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/MortalPastry/wyrd-mcp'
If you have feedback or need assistance with the MCP directory API, please join our Discord server