PLwC
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@PLwCWrite a reflection about today's progress."
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
PLwC — Personality Layer with Conscience
PLwC is a local, model-independent governance gateway for AI tool access, persistent context and controlled memory. It is not the agent and it is not the language model. It is the independent control layer between the AI host, the model and local tools.
AI host / model
|
v
PLwC governance gateway
|
v
tools, files, profiles, memory and sandboxPLwC exposes one visible MCP server, routes all capabilities through policy and governance checks, and provides workspace, document, sandbox, profile, reflection and audit-oriented controls. The gateway is designed for MCP-capable hosts in general. Claude Desktop is a packaged and smoke-tested route, but the boundary remains useful when a host, such as ChatGPT Work, Claude or another MCP client, also offers its own file access or agent features.
Status
Current product version: PLwC 1.0.0; distribution remains a pre-release until the external browser Store gates pass.
This repository retains a privacy-filtered public release boundary. Private development history, local evidence, real profiles and workspace data are intentionally not included.
Version
1.0.0contains the complete eight-tool governed Gateway and the PLwC Chat Bridge 1.0 integration for Chrome, Brave and Edge.The explicit unsigned Windows candidate is
PLwC-Setup-1.0.0-installer-r24.exe, SHA-256b00c5298bf6faa76c5910ecbb36497a8aa4764a8a3720f73a450851a3fc3e4d0. It is available from the versioned GitHub pre-release.Internal source, installed-update, Bridge, extension and installer gates pass. On 2026-08-30, the private Chrome submission entered pending review with automatic publication disabled, and the hidden/link-only Edge submission entered review. Store approval, controlled availability and Store-signed live-browser acceptance remain separate gates.
The current Windows Setup and packaged MCPB are not signed.
PLwC is not production-certified. It is local infrastructure under active development.
Related MCP server: win-cli-mcp-server
What PLwC is - and what it is not
PLwC is:
an MCP gateway, not its own agent;
a local governance boundary between model requests and tool execution;
model- and host-independent policy for MCP-capable hosts;
controlled memory, profile and persona management through explicit profile, reflection and Governor flows;
a single public MCP boundary named
plwc-gateway.
PLwC is not:
a standalone AI platform;
a desktop agent;
the language model or a replacement for the user's chosen AI host;
a full proxy for all model traffic;
protection for data that a user or host sends directly to a cloud model outside PLwC;
permission to expose raw PLfC/PBA or Desktop Commander MCP servers beside the gateway.
What PLwC does
Exposes exactly one visible MCP server:
plwc-gateway.Provides exactly eight public facade tools (see below).
Controls workspace operations (read / write / search / move / rename / exact replace / batch read).
Creates and reads
DOCX,XLSX,PPTXandPDFartifacts.Inspects, extracts, merges, splits and rotates PDFs.
Inspects, extracts and creates ZIP archives with bounded safety limits.
Reads workspace raster images and returns them as MCP image content blocks (PNG, JPEG, WEBP, first-frame GIF).
Runs sandboxed Python and Shell snippets through Docker, with no silent fallback to a host shell.
Manages profiles, reflection writes, memory and persona governance, and Governor
plan/applyflows includingreflection_condensationwithplan_idapply.Blocks protected profile and governance paths from direct workspace writes.
Emits structured local audit events for high-risk operations.
Public tools
PLwC 1.0 exposes exactly these eight public facade tools:
Tool | What it does |
| Reports gateway, sandbox, and profile runtime state; generates a ready-to-paste Claude Desktop config snippet. |
| Returns a self-description of all supported tools, operations, plan types, and capability boundaries — the single source of truth for what PLwC can do in the current session. |
| Loads, inspects, and activates profiles; compiles the configured profile into the active session context. |
| Writes governed reflection entries to |
| Two-stage plan / apply flow for promoting insights to |
| Executes Python or Shell snippets in an isolated Docker container with no network access and no silent fallback to a host shell. |
| Reads, writes, lists, searches, copies, moves, and renames files within configured workspace roots; includes binary and base64 paths and an exact-replace mode. Delete is not public. |
| Creates and manipulates DOCX, XLSX, PPTX, and PDF files; inspects, merges, splits, rotates, and extracts text from PDFs; handles ZIP archives; reads workspace images as MCP image content blocks. |
The 19 individual public tool names from earlier scaffolds
(plwc_compile_profile, plwc_write_workspace_file,
plwc_governor_plan, plwc_write_reflection, ...) are no longer
public in v1.0. Their behavior is reachable through the eight facade
tools above via operation / scope / lang dispatch parameters.
Document capabilities
DOCX Creation V2 (layouts, styles, runs, lists, tables, images, page breaks).
XLSX Creation V2 (multi-sheet, formatting, formulas-as-written (not executed), freeze panes, boolean
auto_filter, merges).PPTX Creation V2 (five slide layouts, content elements, tables, images, slide sizes, plain-text speaker notes).
PDF Creation V2 (layout-PDF builder with A4/A5/landscape/custom page sizes, headings, paragraph runs, bullet/numbered lists, tables, images, explicit page breaks).
read_image(governed workspace image reads).ZIP create / inspect / extract.
PDF inspect / extract / merge / split / rotate / extract_pdf_text.
Security model
One visible gateway server. No bypass MCP servers are exposed.
Protected profile and governance files (
PERSONA.md,memory.md,reflection.md,governance/config.yaml, ...) cannot be edited through workspace operations.Workspace operations are scoped to configured roots; parent traversal, absolute host paths, UNC paths and protected segments are rejected.
Docker-backed Python and Shell sandbox; no silent host-shell fallback.
Fail-closed behavior on missing engines, missing Docker image, or policy denial.
No external URL fetching for document assets (PDF V2, PPTX V2 and DOCX V2 image paths must be workspace-relative).
Known limitations
The following are intentionally not implemented in v1.0:
No OCR.
No PDF redaction.
No digital signing.
No form filling or form creation.
No PDF/A claim.
No LibreOffice or Pandoc conversion.
No macro execution (no
.docm/.xlsm/.pptmgeneration).No external URL fetching, no network access at runtime.
No JavaScript in PDFs.
No HTML/CSS rendering pipeline.
Installation
For step-by-step installation, see
docs/QUICKSTART_CLAUDE_DESKTOP.md.
For full installation context, prerequisites and configuration
options, including local GPT and Odysseus stdio setup plus hosted ChatGPT
web/custom-app status, see docs/INSTALLATION.md.
The selectable Windows EXE installer is maintained under
installer/windows. The current r24 candidate
packages the Gateway, Claude MCPB, Codex and Odysseus STDIO preparation, and the
local PLwC Chat Bridge. It detects complete existing installations, preserves
their paths and settings, and uses stable gateway and bridge directory
names for new installs. Its gated build and validation status is documented in
installer/windows/V_MODEL.md. The public r24
artifact is explicitly unsigned and remains a pre-release candidate.
The bilingual end-user flow, including language selection, administrator
approval, download/storage estimates and Chrome/Edge Bridge setup, is described
in docs/WINDOWS_INSTALLER_GUIDE.md.
Documentation
Current 1.0 program and software description:
docs/PROGRAM_AND_SOFTWARE_DESCRIPTION_1_0.mdHistorical rc18 Open Beta program and software description:
docs/PROGRAM_AND_SOFTWARE_DESCRIPTION_OPEN_BETA.mdInstall / quickstart:
docs/INSTALLATION.md,docs/QUICKSTART_CLAUDE_DESKTOP.md,docs/WINDOWS_INSTALLER_GUIDE.mdTool reference:
docs/TOOLS.mdProject scope:
docs/PROJECT_SCOPE.mdSecurity model and protected boundary:
docs/SECURITY_MODEL.md,docs/SAFE_MODE.mdOnboarding / profile setup:
docs/ONBOARDING.md,docs/FIRST_RUN.mdConfiguration and troubleshooting:
docs/CONFIGURATION.md,docs/TROUBLESHOOTING.mdMaintainer client-integration design and scaffold:
docs/LOCAL_CHATGPT_CLIENT_ADAPTER.md,integrations/plwc-chat-bridge/Open beta / external testing - start here:
BETA_TESTING.md. Details:docs/EXTERNAL_TESTER_GUIDE.md,docs/EXTERNAL_TEST_PLAN.md,docs/BUG_REPORT_TEMPLATE.md,docs/GITHUB_BETA_WORKFLOW.mdAudit behavior:
docs/AUDIT_LOG.md
Project Website and Contact
Official website: plwc.de
General inquiries: info@plwc.de
Use GitHub Issues for reproducible bugs and feature requests. For security-sensitive reports, contact info@plwc.de privately. Do not include secrets, real profile content, private paths or other sensitive details in public issues.
Support
If PLwC helps you, you can support development via Ko-fi:
Ko-fi support is voluntary and not required to use PLwC.
License
PLwC is licensed under the Apache License 2.0. See LICENSE.
This server cannot be deployed
Maintenance
Related MCP Connectors
Governed MCP gateway: one endpoint for your tools, with credential custody and audit log.
- gatewayOAuthai.sealgate
MCP gateway with runtime security policy, tool-call-level control, and audit of agent actions.
MCP server unifying ERPs, CRMs, APIs and knowledge base for Claude, ChatGPT and Gemini.
Guarded MCP server for agent-readable business truth, provenance, readiness, and discovery.
Related MCP Servers
- FlicenseNot gradedqualityDmaintenanceA centralized gateway platform for aggregating and managing multiple Model Context Protocol (MCP) servers through a single Electron-based interface. It provides enterprise-grade security features including policy-based access control, human-in-the-loop approval workflows, and comprehensive audit logging.-
- AlicenseAqualityCmaintenanceHardened MCP server providing controlled access to PowerShell, CMD, Git Bash, and SSH from MCP clients like Claude Desktop.41MIT

headlo-mcpofficial
AlicenseCqualityDmaintenanceMCP server that provides Claude Desktop and Claude Code with access to Headlo collections, records, pages, components, and CAP sessions.259 npmElastic 2.0- FlicenseNot gradedqualityCmaintenanceA local MCP server that connects Claude Code to your work environment through auditable tools for file operations, API calls, and command execution, with safety gates and configuration.-