Back to Discover

osmcp

connector

KrushnaVardhanReddy

A typed, policy-controlled OS capability layer for AI agents.

View on GitHub
0 starsSynced Aug 16, 2026

Install to Claude Code

/plugin marketplace add KrushnaVardhanReddy/osmcp

README

osmcp — OS Capabilities for AI Agents

A typed, policy-controlled OS capability layer for AI agents via the Model Context Protocol (MCP).

osmcp exposes a curated set of safe filesystem, git, and text-processing tools to AI agents — all governed by a strict Policy Engine that enforces path boundaries, tool allowlists, output limits, mutation controls, and an immutable audit trail.

šŸ“– Read the comprehensive Architecture & Design Document for a deep dive into the philosophy, safety boundaries, and design decisions behind osmcp.

LiteLLM Compatible Smithery Verified

Features

CategoryToolsPhase
šŸ” Searchgrep, find1
šŸ“ File Inspectionls, cat, stat, wc, head, tail1
🌳 Filesystemtree, du1
šŸ”€ Git Intelligencegit_status, git_diff, git_log1
šŸ”§ Transformjq, sed, diff1
āœļø File Mutationwrite_file, append_file, mkdir, rm, mv, cp, patch2
šŸš€ Git Mutationgit_add, git_commit, git_checkout, git_branch, git_pull, git_push2

Architecture

AI Agent (Claude, GPT, etc.)
    │  MCP JSON-RPC (stdio)
    ā–¼
osmcp binary
    ā”œā”€ā”€ Policy Engine      ← enforces allowed_root, allowed_tools, limits
    ā”œā”€ā”€ Audit Logger       ← append-only NDJSON log of every invocation
    ā”œā”€ā”€ Tool Registry      ← self-registering tools via RegisterMCP()
    └── Envelope Builder   ← typed {ok, data, error, meta} responses

Demo

osmcp Demo Action A demonstration of Claude Desktop securely editing code via osmcp, safely bounded by a TOML policy engine.

Quick Start

1. Install via Homebrew

brew tap KrushnaVardhanReddy/tap
brew install osmcp

Alternatively, build from source:

make build
# Binary: bin/osmcp

2. Configure a Policy

# policy.toml
[policy]
allowed_root   = "/home/user/myproject"
allowed_tools  = ["grep", "ls", "cat", "git_status", "git_log"]
allow_mutation = false

[limits]
timeout_ms       = 5000
max_output_bytes = 1048576
max_matches      = 100

[audit]
destination = "stderr"   # or "file"
path        = "/var/log/osmcp-audit.ndjson"

3. Run

bin/osmcp --policy policy.toml

The binary communicates over stdio using MCP JSON-RPC. Connect any MCP-compatible client.

Client Integrations

Claude Desktop

Add the following to your claude_desktop_config.json:

{
  "mcpServers": {
    "osmcp": {
      "command": "osmcp",
      "args": ["--policy", "/absolute/path/to/policy.toml"]
    }
  }
}

Smithery (npx)

To install osmcp for Claude Desktop automatically via Smithery:

npx @smithery/cli install osmcp

LiteLLM

Integrate osmcp into your enterprise LLM proxy using the LiteLLM MCP Gateway.

5. Test

make test     # unit tests
make e2e      # end-to-end tests against real binary
make lint     # golangci-lint

Policy Security Model

  • allowed_root — All filesystem paths are validated to be inside this root. Traversal outside is blocked with POLICY_DENIED.
  • allowed_tools — Only tools in this list are visible to the MCP client. Unlisted tools do not appear in tools/list.
  • allow_mutation — When false, mutating tools (write, delete, git commit) are globally blocked.
  • Limits — Per-invocation timeout, output byte cap, and match count cap prevent runaway operations.

Envelope Response Format

All tool responses follow a consistent typed envelope:

{
  "ok": true,
  "tool": "grep",
  "data": { ... },
  "error": null,
  "meta": {
    "execution_time_ms": 12,
    "truncated": false
  }
}

License

MIT

Acknowledgements

osmcp would not be possible without the incredible open-source libraries it is built upon:

  • mcp-go for the core Model Context Protocol SDK.
  • go-git for pure Go git manipulation.
  • gojq for pure Go JSON processing.
  • go-gitdiff for parsing and applying patches.
  • grep-go for regular expression searching.
  • toml for configuration parsing.

Rendered live from KrushnaVardhanReddy/osmcp's GitHub README — not stored, always reflects the source repo.

1 Install Method

NameDescriptionCategorySource
oci packageInstall via oci (stdio transport)mcp-serverghcr.io/krushnavardhanreddy/osmcp:latest

0 Comments

Login required
Log in to post a comment or update on this repo.

No comments yet — be the first to share an update.