local-mcp-server
# local-mcp-server
A stdio MCP server that exposes local file I/O, a small shell whitelist, and SQLite helpers. Built for wiring Cursor/Claude Desktop to stuff on your machine without giving the model full shell access.
## Setup
```bash
npm install
npm run build
cp config.example.json config.json
# edit allowedRoots to match your machine
```
Add to your MCP client config (Cursor example):
```json
{
"mcpServers": {
"local": {
"command": "node",
"args": ["D:/path/to/local-mcp-server/dist/index.js"],
"env": {
"LOCAL_MCP_CONFIG": "D:/path/to/local-mcp-server/config.json"
}
}
}
}
```
## Tools
| Tool | What it does |
|------|--------------|
| `read_file` / `list_dir` / `write_file` | Scoped to `allowedRoots` in config |
| `system_info` | Host stats, no secrets |
| `run_command` | Whitelist only: `echo`, `date`, `pwd`, `whoami`, `uname` |
| `db_query` / `db_exec` | SQLite via named aliases in config |
## Limitations
- File access is path-jail'd but still powerful — don't point `allowedRoots` at `$HOME`.
- Shell tool is intentionally useless for real admin work.
- `db_exec` blocks `DROP`/`ALTER`; everything else is on you.
- Windows: `uname` won't work unless you have it installed.
## Dev
```bash
npm run dev # tsx, stdio — hard to debug interactively
npm test
```
MIT licensed. PRs welcome for additional read-only system probes.
TDQS
Scored across 7 tools
Each tool has a clear, distinct purpose: database operations separate read and write, file operations are split into listing, reading, and writing, and shell commands are distinct from system info. No overlapping responsibilities.
All tool names follow a consistent verb_noun pattern (e.g., db_query, list_dir, run_command), making the set predictable and easy to navigate.
With 7 tools, the server covers a broad range of basic local operations (database, file system, shell) without being bloated or insufficient. The scope is well-matched to a general-purpose utility server.
The tool surface covers essential CRUD-like operations for databases and files, plus command execution and system info. Minor gaps exist, like no explicit file deletion or directory creation, but write_file creates parent directories and the set is functional for common tasks.