About this project

DeskMCP is a local-first MCP policy gateway for Windows that lets ChatGPT interact with a user's machine under locally enforced permissions. The Gateway and policy checks run on the user's computer, while the remote connection is provided through an OpenAI Tunnel; the local MCP endpoint stays bound to 127.0.0.1:8765. Key characteristics: - Workspace scoping: file tools are limited to a folder the user selects, with lexical and canonical path checks intended to block symlink/junction escapes. - Safe defaults: first run starts in Read-only mode. The Write profile adds guarded create/edit/move operations. Full and Unlock profiles are session-only and are never persisted; restarting returns to the last safe persisted profile. - Sensitive-path exclusions: paths such as .env, .ssh, .gnupg, .aws/credentials and similar are denied by default, and search excludes them before reads. - Stable tool surface: 27 MCP tools covering files, processes, Windows UI automation, task rooms, artifacts, dynamic MCP servers, skills, and browser automation. Schemas remain discoverable across profiles, but each invocation is still checked by local policy. - Computer Use: UI Automation first, with short-lived opaque observation IDs required for actions; screenshots are optional and bounded. - Agent Desktop pool: Windows virtual desktops can be bound as agent slots, with leases preventing concurrent agents from sharing a slot. - Browser automation: DeskMCP owns the browser process, uses a loopback CDP port, redacts password values in snapshots, and requires fresh observation IDs for actions. - Artifacts and tasks: recoverable task state is stored in workspace-bound Task Rooms with opaque capabilities; artifacts are copied into DeskMCP's state root, integrity-checked, and served via signed URLs. - Audit: metadata-only logging with rotation; file contents, terminal I/O, secrets, and screenshot pixels are not recorded. Installation is via a self-contained Windows Setup executable that does not require Node.js, npm, .NET, Git, or a source checkout. The README documents a quick start involving an OpenAI Tunnel ID and Runtime API Key, with the key protected by Windows DPAPI. A macOS ARM64 Developer Preview is mentioned as validated on Apple Silicon CI but ad-hoc signed and not notarized. The project is a personal open-source effort by edmen12, licensed Apache-2.0, with public roadmap issues covering fresh-user validation, optional Authenticode signing, ARM64 packaging, safe updates, and updater UI.