MCP_Chatgpt
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@MCP_Chatgptrun npm test in D:\Projects\my-app and show me the output"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
MCP_Chatgpt
Local MCP server for a Windows PC so a supported ChatGPT/OpenAI MCP client can read/edit project files, run PowerShell/CLI commands, manage long-running processes, and inspect or mutate Git repositories.
Status: MVP v0.1.0. The HTTP server binds to
127.0.0.1only. It now supports both MCP clients and an experimental read-only browser bridge for normalchatgpt.comconversations.
What this MVP exposes
Filesystem
fs_list_directoryfs_read_filefs_file_infofs_write_filefs_replace_textfs_search_textfs_create_directoryfs_copy_filefs_move_pathfs_delete_path
Filesystem operations are constrained to allowedRoots and perform a real-path ancestor check to reduce symlink/junction escapes.
Shell / processes
shell_execprocess_startprocess_statusprocess_listprocess_stop
The default example uses Windows PowerShell. Set shell.executable to pwsh.exe if you prefer PowerShell 7.
Important security boundary: allowedRoots is a filesystem-tool boundary, not a complete OS sandbox for arbitrary shell commands. A shell command runs with the Windows permissions of the account that starts this server. Run the MCP under a dedicated low-privilege Windows account/AppContainer if you need a hard shell boundary.
Git
git_statusgit_diffgit_loggit_showgit_commit— disabled by defaultgit_push— disabled by default
git_commit and git_push require explicit policy opt-in.
Related MCP server: bridge-mcp
Requirements
Windows 10/11 recommended for this project
Node.js 20+
Git in
PATHPowerShell (
powershell.exe) or PowerShell 7 (pwsh.exe)
Install
git clone https://github.com/hoafff/MCP_Chatgpt.git
cd MCP_Chatgpt
npm install
Copy-Item .\config\policy.example.json .\config\policy.jsonEdit config/policy.json and replace the example roots with only the folders you want MCP tools to access.
Then:
npm run check
npm run build
npm startExpected local endpoints:
http://127.0.0.1:8787/mcp
http://127.0.0.1:8787/healthYou can change the port:
$env:MCP_PORT = "8788"
npm startOr use a different policy file:
$env:MCP_POLICY_PATH = "D:\\MCP\\my-policy.json"
npm startChatGPT Web Local Bridge (experimental)
For ChatGPT Plus users who want to keep using a normal conversation on chatgpt.com without the OpenAI API or a separate chat UI, this repository includes an unpacked Chrome/Edge extension under extension/.
The extension is not native ChatGPT MCP. Version 0.2.0 uses Safe Manual-Send Mode:
you type @local + a Windows path
↓
extension blocks that first Send
↓
read-only localhost bridge
↓
existing allowedRoots / protectedPaths / audit policy
↓
local material is inserted into the ChatGPT composer
↓
extension stops
↓
you review/edit the material
↓
you manually press SendIn this mode the extension does not inspect ChatGPT replies, does not parse assistant output, does not auto-loop, and does not press Send for you.
Browser access remains read-only. It can inspect a path, read a text file, or list a directory through the existing filesystem security policy. It does not expose shell, process, write, delete, Git commit, or Git push actions.
Safe Mode activates only when the prompt explicitly contains @local.
Example:
@local đọc file E:\MCP_ChatGpt\README.md và tóm tắt project nàyFor paths containing spaces, quote the full path:
@local đọc "E:\My Project\notes.txt" và tóm tắtThe first Enter/click prepares the local material but does not send it. Review the composer and manually press Send only if you approve the content.
Once you manually press Send, the inserted local content is uploaded to ChatGPT just as if you pasted it yourself. Do not send secrets, tokens, passwords, private keys, cookies, credentials, recovery codes, or confidential material that you do not want in the conversation.
See extension/README.md for setup and detailed safety notes.
Automated self-test
With the MCP server already running in another terminal, run:
npm.cmd run self-testThe self-test exercises the health endpoint, MCP initialize, tools/list, filesystem read/write, the allowedRoots rejection path, shell execution, background process lifecycle, Git status, and the Git commit policy gate. It creates a temporary file under logs/ and deletes it at the end.
The test expects the current working directory to be one of allowedRoots and expects git.allowCommit=false. Override the endpoint/root when needed:
$env:MCP_SELF_TEST_URL = "http://127.0.0.1:8787/mcp"
$env:MCP_SELF_TEST_ROOT = "E:\\MCP_ChatGpt"
npm.cmd run self-testStdio mode
For an MCP host that launches the local server as a child process:
npm run build
npm run start:stdioDo not write debug output to stdout in stdio mode; stdout is the MCP JSON-RPC channel. This project logs startup messages to stderr.
Policy example
The checked-in config/policy.example.json is intentionally conservative around Git mutations while keeping shell enabled for local development.
Create config/policy.json; it is ignored by Git so machine-specific paths do not leak into the repository.
Key settings:
{
"allowedRoots": ["D:\\Projects"],
"shell": {
"enabled": true,
"executable": "powershell.exe"
},
"git": {
"allowCommit": false,
"allowPush": false
}
}Audit log
Tool activity is appended as JSONL under logs/ by default. File contents and command outputs are not written to the audit log. Command strings are logged by default; set audit.logCommands=false if commands may contain secrets.
Never pass passwords, API keys, access tokens, private keys, or MFA codes directly inside a model-visible command when an interactive/secret-safe alternative exists.
Security model
This MVP has several layers:
HTTP binds only to
127.0.0.1.Host and Origin validation are enabled in front of MCP HTTP handling.
File tools enforce
allowedRootsandprotectedPaths.Shell commands must start in an allowed directory and are checked against a small emergency blocklist.
Git commit/push are separately policy-gated.
Tool actions are audited locally.
The shell blocklist is a guardrail, not a sandbox. Do not run the MCP process as Administrator. A later hardening phase can add a dedicated Windows account, ACLs, Job Objects/AppContainer, signed policy, and explicit approval gates.
Connecting to ChatGPT / OpenAI
For a private server on your own PC, prefer OpenAI Secure MCP Tunnel rather than opening an inbound firewall port or publishing the local MCP endpoint. The tunnel client runs inside your machine/network and forwards MCP traffic to the local endpoint through an outbound HTTPS connection.
Keep this local server bound to loopback (127.0.0.1).
Reference design choices
This project is built against the current MCP TypeScript SDK v2 API (@modelcontextprotocol/server, @modelcontextprotocol/node) and the 2026-era MCP protocol rather than copying older SSE-only templates.
Useful upstream references:
modelcontextprotocol/typescript-sdkmodelcontextprotocol/serversyotsuda/PowerShell.MCP(PowerShell architecture/security ideas; this repo is not a fork)
Roadmap
MCP v2 HTTP + stdio transport
Allowed-root filesystem tools
PowerShell execution + long-running managed processes
Git read tools and policy-gated commit/push
JSONL audit log
Windows hard sandbox / dedicated low-privilege execution identity
Human approval policy for high-risk mutations
Better patch/diff application tool
Process output cursors/streaming
Installer / Windows service or scheduled startup
Secure MCP Tunnel setup helper
Read-only ChatGPT Web browser bridge
Browser bridge write/approval layer
GUI automation layer (optional)
License
MIT
This server cannot be deployed
Maintenance
Related MCP Connectors
Nifty's MCP server — exposes tasks, projects, messages, and files as tools for AI agents.
Personal assistant MCP server with search, execute, packages, jobs, secrets, and integrations.
Remote MCP server for supportsheep: run AI interviews and manage support content for your blog.
MCP server for mandates, delegation, policy-gated execution, credential grants, and audit.
Related MCP Servers
- AlicenseNot gradedqualityCmaintenanceLocal MCP server bridging ChatGPT Web to local tools for file, shell, git, test, and process management with secure policy controls.MIT
- FlicenseBqualityBmaintenanceA local MCP server that bridges ChatGPT to a Windows PC, offering filesystem, shell, Git, and diagnostic tools via a secure tunnel.171-
- AlicenseAqualityAmaintenanceMCP server that lets a private ChatGPT app remotely control a paired Windows PC, including files, PowerShell, programs, screenshots, mouse/keyboard, clipboard, and Chrome.214MIT
- AlicenseNot gradedqualityBmaintenanceOpen-source Windows MCP policy gateway that gives ChatGPT controlled access to local files and terminal sessions with workspace-scoped permissions, guarded writes, session-owned processes, and audit logging.2Apache 2.0