osmcp
Provides tools for inspecting and manipulating Git repositories, including status, diff, log, add, commit, checkout, branch, pull, and push operations.
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@osmcpsearch for 'AWS_SECRET' in the repo and show the file paths"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
osmcp — OS Capabilities for AI Agents
A typed, policy-controlled OS capability layer for AI agents via the Model Context Protocol (MCP).
osmcp exposes a curated set of safe filesystem, git, and text-processing tools to AI agents — all governed by a strict Policy Engine that enforces path boundaries, tool allowlists, output limits, mutation controls, and an immutable audit trail.
📖 Read the comprehensive Architecture & Design Document for a deep dive into the philosophy, safety boundaries, and design decisions behind osmcp.
Features
Category | Tools | Phase |
🔍 Search |
| 1 |
📁 File Inspection |
| 1 |
🌳 Filesystem |
| 1 |
🔀 Git Intelligence |
| 1 |
🔧 Transform |
| 1 |
✍️ File Mutation |
| 2 |
🚀 Git Mutation |
| 2 |
Related MCP server: Coding Tools MCP
Architecture
AI Agent (Claude, GPT, etc.)
│ MCP JSON-RPC (stdio)
▼
osmcp binary
├── Policy Engine ← enforces allowed_root, allowed_tools, limits
├── Audit Logger ← append-only NDJSON log of every invocation
├── Tool Registry ← self-registering tools via RegisterMCP()
└── Envelope Builder ← typed {ok, data, error, meta} responsesDemo
A demonstration of Claude Desktop securely editing code via osmcp, safely bounded by a TOML policy engine.
Quick Start
1. Install via Homebrew
brew tap KrushnaVardhanReddy/tap
brew install osmcpAlternatively, build from source:
make build
# Binary: bin/osmcp2. Configure a Policy
# policy.toml
[policy]
allowed_root = "/home/user/myproject"
allowed_tools = ["grep", "ls", "cat", "git_status", "git_log"]
allow_mutation = false
[limits]
timeout_ms = 5000
max_output_bytes = 1048576
max_matches = 100
[audit]
destination = "stderr" # or "file"
path = "/var/log/osmcp-audit.ndjson"3. Run
bin/osmcp --policy policy.tomlThe binary communicates over stdio using MCP JSON-RPC. Connect any MCP-compatible client.
Client Integrations
Claude Desktop
Add the following to your claude_desktop_config.json:
{
"mcpServers": {
"osmcp": {
"command": "osmcp",
"args": ["--policy", "/absolute/path/to/policy.toml"]
}
}
}Smithery (npx)
To install osmcp for Claude Desktop automatically via Smithery:
npx @smithery/cli install osmcpLiteLLM
Integrate osmcp into your enterprise LLM proxy using the LiteLLM MCP Gateway.
5. Test
make test # unit tests
make e2e # end-to-end tests against real binary
make lint # golangci-lintPolicy Security Model
allowed_root— All filesystem paths are validated to be inside this root. Traversal outside is blocked withPOLICY_DENIED.allowed_tools— Only tools in this list are visible to the MCP client. Unlisted tools do not appear intools/list.allow_mutation— Whenfalse, mutating tools (write, delete, git commit) are globally blocked.Limits — Per-invocation timeout, output byte cap, and match count cap prevent runaway operations.
Envelope Response Format
All tool responses follow a consistent typed envelope:
{
"ok": true,
"tool": "grep",
"data": { ... },
"error": null,
"meta": {
"execution_time_ms": 12,
"truncated": false
}
}License
MIT
Acknowledgements
osmcp would not be possible without the incredible open-source libraries it is built upon:
This server cannot be deployed
Maintenance
Related MCP Connectors
- gatewayOAuthai.sealgate
MCP gateway with runtime security policy, tool-call-level control, and audit of agent actions.
Zero-secret MCP gateway for AI agents: risk-scored, audited calls with human-in-the-loop approval.
OCR, transcription, file extraction, and image generation for AI agents via MCP.
AgentGuard — 20-tool AI safety MCP: policy preflight, risk scoring, audit logging, rate limits.
Related MCP Servers
- AlicenseNot gradedqualityDmaintenanceRemote execution layer for agentic systems exposing 64 production tools via MCP for file, network, system, text, git, crypto, and monitoring operations.MIT
- AlicenseNot gradedqualityBmaintenanceGives any MCP-compatible AI chat or agent a safe, model-neutral coding runtime with file read/search, structured multi-file patches, command execution, interactive sessions, and git operations, all confined to a single workspace and gated by permission modes.Apache 2.0
- AlicenseNot gradedqualityAmaintenanceEnables AI clients to securely control and interact with a local Windows machine through 218 configurable tools for files, Git, processes, Windows UI, browser automation, WSL, Office, recovery, skills, and child MCP servers.5 npmMIT
- AlicenseNot gradedqualityBmaintenanceEnables coding agents to perform file, search, patch, git, process, test, package, network, and system operations through 60 typed MCP tools with structured inputs/outputs, structured errors, and a full event journal, replacing terminal use with a typed machine API.MIT