Skip to main content
Glama

osmcp — OS Capabilities for AI Agents

A typed, policy-controlled OS capability layer for AI agents via the Model Context Protocol (MCP).

osmcp exposes a curated set of safe filesystem, git, and text-processing tools to AI agents — all governed by a strict Policy Engine that enforces path boundaries, tool allowlists, output limits, mutation controls, and an immutable audit trail.

📖 Read the comprehensive Architecture & Design Document for a deep dive into the philosophy, safety boundaries, and design decisions behind osmcp.

LiteLLM Compatible Smithery Verified

Features

Category

Tools

Phase

🔍 Search

grep, find

1

📁 File Inspection

ls, cat, stat, wc, head, tail

1

🌳 Filesystem

tree, du

1

🔀 Git Intelligence

git_status, git_diff, git_log

1

🔧 Transform

jq, sed, diff

1

✍️ File Mutation

write_file, append_file, mkdir, rm, mv, cp, patch

2

🚀 Git Mutation

git_add, git_commit, git_checkout, git_branch, git_pull, git_push

2

Related MCP server: Coding Tools MCP

Architecture

AI Agent (Claude, GPT, etc.)
    │  MCP JSON-RPC (stdio)
    ▼
osmcp binary
    ├── Policy Engine      ← enforces allowed_root, allowed_tools, limits
    ├── Audit Logger       ← append-only NDJSON log of every invocation
    ├── Tool Registry      ← self-registering tools via RegisterMCP()
    └── Envelope Builder   ← typed {ok, data, error, meta} responses

Demo

osmcp Demo Action A demonstration of Claude Desktop securely editing code via osmcp, safely bounded by a TOML policy engine.

Quick Start

1. Install via Homebrew

brew tap KrushnaVardhanReddy/tap
brew install osmcp

Alternatively, build from source:

make build
# Binary: bin/osmcp

2. Configure a Policy

# policy.toml
[policy]
allowed_root   = "/home/user/myproject"
allowed_tools  = ["grep", "ls", "cat", "git_status", "git_log"]
allow_mutation = false

[limits]
timeout_ms       = 5000
max_output_bytes = 1048576
max_matches      = 100

[audit]
destination = "stderr"   # or "file"
path        = "/var/log/osmcp-audit.ndjson"

3. Run

bin/osmcp --policy policy.toml

The binary communicates over stdio using MCP JSON-RPC. Connect any MCP-compatible client.

Client Integrations

Claude Desktop

Add the following to your claude_desktop_config.json:

{
  "mcpServers": {
    "osmcp": {
      "command": "osmcp",
      "args": ["--policy", "/absolute/path/to/policy.toml"]
    }
  }
}

Smithery (npx)

To install osmcp for Claude Desktop automatically via Smithery:

npx @smithery/cli install osmcp

LiteLLM

Integrate osmcp into your enterprise LLM proxy using the LiteLLM MCP Gateway.

5. Test

make test     # unit tests
make e2e      # end-to-end tests against real binary
make lint     # golangci-lint

Policy Security Model

  • allowed_root — All filesystem paths are validated to be inside this root. Traversal outside is blocked with POLICY_DENIED.

  • allowed_tools — Only tools in this list are visible to the MCP client. Unlisted tools do not appear in tools/list.

  • allow_mutation — When false, mutating tools (write, delete, git commit) are globally blocked.

  • Limits — Per-invocation timeout, output byte cap, and match count cap prevent runaway operations.

Envelope Response Format

All tool responses follow a consistent typed envelope:

{
  "ok": true,
  "tool": "grep",
  "data": { ... },
  "error": null,
  "meta": {
    "execution_time_ms": 12,
    "truncated": false
  }
}

License

MIT

Acknowledgements

osmcp would not be possible without the incredible open-source libraries it is built upon:

  • mcp-go for the core Model Context Protocol SDK.

  • go-git for pure Go git manipulation.

  • gojq for pure Go JSON processing.

  • go-gitdiff for parsing and applying patches.

  • grep-go for regular expression searching.

  • toml for configuration parsing.

Related MCP Connectors

Related MCP Servers

  • A
    license
    Not graded
    quality
    D
    maintenance
    Remote execution layer for agentic systems exposing 64 production tools via MCP for file, network, system, text, git, crypto, and monitoring operations.
    MIT
  • A
    license
    Not graded
    quality
    B
    maintenance
    Gives any MCP-compatible AI chat or agent a safe, model-neutral coding runtime with file read/search, structured multi-file patches, command execution, interactive sessions, and git operations, all confined to a single workspace and gated by permission modes.
    Apache 2.0
  • A
    license
    Not graded
    quality
    A
    maintenance
    Enables AI clients to securely control and interact with a local Windows machine through 218 configurable tools for files, Git, processes, Windows UI, browser automation, WSL, Office, recovery, skills, and child MCP servers.
    5 npm
    MIT
  • A
    license
    Not graded
    quality
    B
    maintenance
    Enables coding agents to perform file, search, patch, git, process, test, package, network, and system operations through 60 typed MCP tools with structured inputs/outputs, structured errors, and a full event journal, replacing terminal use with a typed machine API.
    MIT