Atlas / MCP servers / funggier / LConnect

LConnectBLOCK

mcp/funggier/lconnect

MCP-LocalConnect

Verdict
BLOCK
Grade
D
Trust score
69 /100
Exposed tools
152 98r · 42w · 12d
Transport
stdio
License
MIT
Stars
0
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

LConnect คือ MCP server แบบ modular สําหรับให้ ChatGPT เข้าถึงและควบคุมเครื่อง Windows ผ่าน OpenAI Tunnel

เป้าหมายหลักของโปรเจกต์คือให้ AI สามารถทํางานพัฒนาและดูแลเครื่องได้ต่อเนื่องจากจุดเดียว เช่น อ่าน/แก้ไฟล์ รัน PowerShell เปิด process อ่าน stdout/stderr ส่ง stdin ตรวจ process และ port ตลอดจนเพิ่ม module ใหม่ในอนาคต

ค่าเริ่มต้นของ LConnect คือ Full-machine access Filesystem สามารถเข้าถึง path ใดก็ได้ที่ Windows account ซึ่งรัน LConnect มีสิทธิ์เข้าถึง และ shell/process ทํางานด้วยสิทธิ์ของ Windows account เดียวกัน

สถานะปัจจุบัน

  • Source version: 1.3.1
  • MCP catalog on current main: 154 tools
  • Tool-surface policy: docs/TOOL_SURFACE_POLICY.md
  • Release: [v1.3.1 — Operational Hardening & Optional Autostart](https://github.com/funggier/LConnect/releases/tag/v1.3.1)
  • OpenAI tunnel-client minimum: 0.0.14

LConnect Core ผ่าน runtime acceptance บน Windows 10 แล้ว โดย current main แสดง 154 tools ครอบคลุม filesystem, shell, managed process/session, system/network/hardware, Git, GitHub Actions/Release, structured inspection, browser automation แบบ isolated, live browser control ผ่าน Windows UI Automation, runtime/delivery evidence, deployment verification และ turn-risk observation แบบไม่บล็อกการทํางาน

ไฮไลต์ v1.3.1

  • เก็บ Runtime API key + Organization ID แบบเข้ารหัสใน local-secrets\credentials.json.enc
  • ใช้ Windows DPAPI / CurrentUser และจํากัด ACL ให้ Windows user ปัจจุบันกับ SYSTEM
  • Start-LConnect.cmd ใช้ลําดับ parameter > environment > stored DPAPI > interactive prompt
  • first run สามารถบันทึก credential แบบเข้ารหัสได้โดยไม่เก็บ plaintext secret ใน Git
  • เพิ่ม Setup-LConnectCredential.cmd, Status-LConnectCredential.cmd และ Clear-LConnectCredential.cmd
  • Restart-LConnect.cmd ใช้ detached worker เพื่อคืนผลก่อนหยุด tunnel เดิม แล้ว start LConnect ใหม่แบบ non-interactive
  • Runtime API key ไม่ถูกส่งผ่าน restart command line
  • local-secrets/ ถูก preserve ระหว่าง de
Read from source at commit b7048eb6f195OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add lconnect-mcp --env GH_TOKEN=${GH_TOKEN} --env GITHUB_TOKEN=${GITHUB_TOKEN} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "lconnect-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "GH_TOKEN": "${GH_TOKEN}",
        "GITHUB_TOKEN": "${GITHUB_TOKEN}"
      }
    }
  }
}
03

Exposed tools (152)

98 read · 42 write · 12 destructive. Blast radius: 12 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
alpha_fixturereadfixture
batch_inspectwriteRun up to 10 explicit allowlisted read-only LConnect inspections inside one MCP round trip. No shell/process/Git mutation, writes, network requests, autonomous branching, loops, or nested batches.
battery_inforeadReturn battery inventory/status when a battery is exposed; desktops without batteries return available=false.
browser_attachreadAttach to an explicitly automation-enabled browser endpoint. This never discovers or enables automation on a normal live profile.
browser_clickreadClick a DOM target through the browser backend; native mouse fallback is not automatic.
browser_live_attachreadAttach semantically to a currently open Firefox/Chrome window using Windows UI Automation only. No WebDriver/CDP or profile mutation is enabled.
browser_live_clickwriteInvoke/select a live browser accessibility element without enabling browser remote automation.
browser_live_snapshotreadReturn a bounded Windows UI Automation snapshot from an attached live browser window.
browser_live_stopwriteDetach the LConnect live-browser session only. The browser process and profile are never closed or modified.
browser_live_tabsreadList visible browser tab UI items through Windows UI Automation.
browser_live_typewriteSet text through UI Automation ValuePattern on a live browser accessibility element; no WebDriver/CDP is used.
browser_navigatereadNavigate a browser tab using the common adapter-neutral API.
browser_screenshotreadCapture a bounded screenshot. File-backed output is the default to avoid large MCP payloads; inline base64 is opt-in.
browser_snapshotreadReturn a bounded DOM snapshot or accessibility-oriented snapshot through the active backend.
browser_startwriteStart an isolated managed browser session. Normal user profiles are never reused unless the caller explicitly opts into an external profile.
browser_stopwriteStop a managed session or detach an attached session. Attached remote sessions are left running unless close_remote_session=true is explicitly requested.
browser_tabsreadList tabs/contexts through the browser session
browser_typereadType text into a DOM target through the browser backend; native keyboard fallback is not automatic.
clipboard_cleardestructiveClear the Windows clipboard and verify that it is empty.
clipboard_getreadRead text from the Windows clipboard with bounded output and explicit empty/non-text state.
clipboard_setwriteSet Windows clipboard text using a Unicode-safe exact roundtrip.
close_windowreadRequest a native window to close by posting WM_CLOSE; this does not forcibly terminate the owning process.
command_runwriteRun a short executable command with an argument array. Synchronous execution is capped by the LConnect MCP request budget; use start_process for long-running work. On Windows, launch failures are retried through PowerShell.
compare_directoriesreadCompare two bounded directory manifests by relative path, size, and streamed digest. Returns missing/extra/changed evidence; equality is null when either side is incomplete or unstable.
compare_filesreadCompare two files using size plus a streaming cryptographic digest and return evidence for both sides. SHA-256 is the default.
cpu_inforeadReturn structured CPU topology and clock information.
create_directorywriteCreate a directory recursively if needed.
create_scheduled_taskwriteCreate a Windows Scheduled Task for the current LConnect Windows user.
delivery_snapshotreadReturn one compact read-only correlation snapshot combining LConnect handler telemetry with local tunnel delivery/control-plane metrics. Reads only the runtime loopback health endpoint and omits tunnel IDs, credentials, arguments, request bodies and raw metrics.
deployment_verification_snapshotreadReturn one bounded read-only deployment evidence snapshot: Git-tracked source↔installed parity, package/dependency evidence, preserved local paths, and the running runtime catalog identity. Does not copy, install, restart, refresh, fetch, or release.
detect_build_systemreadDetect build/package systems and supported execution contracts.
detect_projectreadDetect project ecosystems from evidence in one project directory.
directory_manifestreadRecursively stream-hash a bounded selected directory tree and return a deterministic relative-path manifest digest plus bounded file evidence. Symlinks/junctions are not followed.
directory_treereadReturn a recursive JSON directory tree with a hard entry bound.
disk_inforeadReturn logical volume and physical disk inventory.
dns_lookupreadResolve a hostname using the operating system resolver.
edit_filewriteReplace exact text sequences in a text file and return a compact diff.
env_getreadRead one environment variable from the LConnect process, user profile, or machine environment.
env_listreadList environment variables. Values are omitted by default to reduce accidental secret exposure.
env_setdestructiveSet or delete an environment variable. Process scope affects only the running LConnect process; user/machine scopes persist for future processes.
file_hashreadStream a file and return deterministic cryptographic digest evidence without loading the whole file into memory. SHA-256 is the default.
find_processreadFind Windows processes using structured filters.
fixture_workreadfixture
focus_windowreadRequest foreground focus for a native window. Windows may reject focus stealing; actual foreground state is reported.
follow_logwriteStart a bounded background log follower and return a follower ID immediately.
get_file_inforeadReturn metadata for a file or directory.
get_scheduled_taskreadRead one Windows Scheduled Task by exact task_path + task_name.
get_servicereadGet one Windows service by exact service Name.
get_windowreadInspect one native window by exact HWND.
git_branchdestructiveList, create, switch or delete local Git branches.
git_commitwriteCreate a Git commit with explicit staging behavior and return exact SHA evidence.
git_diffreadReturn a bounded Git diff or name-only change list.
git_fetchdestructiveFetch from a Git remote without force behavior.
git_is_ancestorwriteResolve two commit-ish values to exact commit SHAs and report whether the first is an ancestor of the second.
git_logwriteReturn structured Git commit history.
git_pullreadPull updates, using fast-forward-only mode by default.
git_pushdestructivePush the current or specified branch to a Git remote. Force push is intentionally not supported.
git_push_refwritePush one exact source commit/full ref to one explicit full branch ref with non-force fast-forward safety and before/after remote SHA evidence.
git_remote_refreadResolve one exact full remote Git ref to its SHA without mutating the repository.
git_statusreadReturn structured repository, HEAD, upstream and working-tree status.
git_sync_statuswriteCompare local HEAD/cached upstream state with one exact remote Git ref without fetching or mutating the repository.
git_worktreedestructiveList, add, remove or prune Git worktrees.
github_commit_run_statuswriteCorrelate one exact 40-hex commit SHA to GitHub Actions runs and return the deterministic latest matching run with jobs/steps.
github_release_downloadreadDownload one exact GitHub Release asset through gh into an allowed existing directory using same-directory temporary staging, size bounds, and local SHA-256 evidence.
github_release_viewreadReturn structured metadata and assets for one exact GitHub Release tag.
github_run_failed_logswriteReturn bounded failed-job/step evidence and failed logs for one GitHub Actions run.
github_run_listwriteList GitHub Actions runs through authenticated gh with structured bounded output.
github_run_viewwriteReturn structured metadata and jobs for one exact GitHub Actions run ID.
github_run_waitwrite
github_workflow_dispatchreadDispatch one exact GitHub workflow with explicit inputs. Input values are never echoed in the result.
gpu_inforeadReturn graphics adapter/driver inventory exposed by Windows.
http_downloadreadDownload an HTTP resource to a file with timeout, size limit and atomic temp-file replacement.
http_headersreadRead HTTP response headers with a bounded HEAD request.
http_probereadProbe an HTTP endpoint with HEAD, optionally falling back to GET for 405/501.
http_requestreadMake a bounded HTTP request and return structured status, headers and body.
install_dependencieswriteStart dependency installation as a managed process session and return immediately.
key_comboreadPress a guarded key combination on a foreground HWND target, releasing keys in reverse order.
key_pressreadPress and release one supported virtual key on a guarded foreground HWND target.
kill_processdestructiveTerminate a Windows process by PID using taskkill.
latency_budget_statusreadRead observation-only LConnect turn-risk telemetry. Compatibility name retained; no handler-sum-derived ceiling or blocking policy is enforced.
latency_round_startwriteStart a fresh observation-only LConnect turn-risk round at zero. Previous-round measurements never carry into the new round.
list_allowed_directoriesreadReturns the current LConnect filesystem access scope.
list_directoryreadList files and directories in one directory with a bounded entry count.
list_directory_with_sizesreadList directory entries with file sizes and a bounded entry count.
list_listening_portsreadList local TCP listening ports and owning process IDs.
list_processesreadList Windows processes with PID, name and executable path when available.
list_scheduled_tasksreadList Windows Scheduled Tasks with bounded structured output.
list_servicesreadList Windows services with structured state/startup information.
list_sessionsreadList process sessions started by this LConnect instance. Supports filtering/pagination and a compact summary mode; buffered stdout/stderr are omitted by default.
list_windowsreadList native top-level Windows windows with HWND/PID/title/class/rectangle evidence.
maximize_windowreadMaximize a native window and return before/after evidence.
memory_inforeadReturn structured physical/virtual memory and RAM-module information.
minimize_windowreadMinimize a native window and return before/after evidence.
mouse_clickreadClick at virtual-desktop screen coordinates with optional exact root-HWND point guard.
mouse_movewriteMove the Windows cursor to virtual-desktop screen coordinates and report cursor/window evidence.
mouse_scrollwriteSend vertical or horizontal wheel input at screen coordinates with optional exact root-HWND point guard.
move_filewriteMove or rename a file or directory.
move_windowwriteMove a native window using virtual-desktop screen coordinates; negative coordinates are valid on multi-monitor layouts.
network_interfacesreadReturn structured local network interface addresses from Node/OS APIs.
path_listreadReturn PATH entries for process, user, or machine scope with existence and duplicate information.
ping_hostwriteSend bounded ICMP echo requests using .NET Ping and return structured replies.
port_ownerreadFind local TCP/UDP endpoints using a port and correlate owning PIDs with process metadata.
port_testreadTest a TCP connection to a host/port with a bounded timeout.
powershell_runwriteRun a short PowerShell command on the local Windows computer. Synchronous execution is capped by the LConnect MCP request budget; use start_process for long-running work.
process_detailsreadReturn structured Windows process details and creation-time identity for one PID.
process_treereadReturn a process subtree plus ancestors using PID/parent PID relationships.
project_inforeadReturn structured project metadata. Node package metadata is expanded when present.
prune_sessionswriteDry-run or release terminal process sessions older than a specified age. Running sessions are never pruned.
read_filereadDeprecated compatibility alias of read_text_file; use read_text_file for new workflows.
read_log_eventsreadRead buffered log follower events after a sequence cursor without waiting.
read_media_filereadRead an image/audio/other file as base64 content with an explicit byte bound.
read_multiple_filesreadRead multiple text files in one call with per-file and total output bounds.
read_process_eventsreadRead incremental process output/lifecycle events after a sequence cursor.
read_process_outputreadCompatibility buffered-output API for a process session. New cursor-based workflows should use read_process_events.
read_text_filereadRead a text file with optional head/tail selection and a bounded text result.
refresh_statereadReconcile transient process/log/watch state and optionally prune safe terminal/stopped handles. Running work is preserved.
release_sessionreadForget one terminal process session and its buffered evidence. Running sessions are refused.
resize_windowreadResize a native window while preserving its current top-left position.
restart_processwriteRestart an explicitly identified process. Requires creation-time identity and an explicit relaunch program.
restart_servicewriteRestart one Windows service selected by exact service Name. A stopped service is started.
run_buildwriteStart a Node build script as a managed process session and return immediately.
run_lintwriteStart a Node lint script as a managed process session and return immediately.
run_testswriteStart a Node test script as a managed process session and return immediately.
runtime_catalogreadReport the catalog loaded by this running LConnect process: tool count, stable name digest, process identity and optional sorted tool names. Useful for distinguishing a restarted runtime from a stale client/plugin catalog.
search_filesreadRecursively search for files/directories using glob-style patterns with hard traversal, depth, time and output bounds.
search_logreadSearch a bounded tail region of a text log using literal or regular-expression matching.
search_textreadSearch UTF-8 text content recursively with literal/regex modes, path/line/column evidence, context, binary/error reporting, and hard files/bytes/matches/output bounds.
session_statusreadRead immediate compact status for one managed process session without waiting. Output is omitted by default; request a bounded tail only when needed.
set_service_startupwriteSet Windows service startup mode by exact service Name.
start_processwriteStart a long-running local process and return a session ID.
start_servicewriteStart one Windows service selected by exact service Name and wait for Running state.
stop_log_followdestructiveStop and remove a log follower session.
stop_servicewriteStop one Windows service selected by exact service Name and wait for Stopped state.
stop_watchdestructiveStop and remove a filesystem watcher session.
storage_healthreadReturn physical storage health when Windows exposes it; otherwise return an explicit fallback/unavailable result.
structured_data_inspectreadParse a bounded UTF-8 JSON, YAML, or TOML file and inspect one node using RFC 6901 JSON Pointer. Returns compact metadata plus a bounded structured value preview without modifying the file.
system_inforeadReturn basic local machine and Node runtime information.
tail_filereadRead the last lines of a text log with a bounded byte scan.
tcp_connectionsreadList structured local TCP connections using lightweight netstat parsing.
terminate_processdestructiveTerminate a process session started by LConnect.
tool_telemetrydestructiveInspect or clear bounded metadata-only telemetry for LConnect tool handlers. Arguments, command text, file contents, environment values, and result contents are never recorded.
type_textreadType Unicode text into a guarded foreground HWND target using KEYEVENTF_UNICODE.
udp_endpointsreadList structured local UDP endpoints using lightweight netstat parsing.
wait_processreadWait a bounded time for a specific process identity to exit. Creation time is required to detect PID reuse.
wait_sessionreadWait briefly (default 1s, maximum 3s) for a managed process session. Prefer session_status for non-blocking checks. Timeout never terminates managed work.
watch_eventsreadRead buffered filesystem events after a sequence cursor without waiting.
watch_pathwriteStart a bounded filesystem watcher session and return a watcher ID after backend readiness.
watch_statusreadReturn status for one filesystem watcher session.
whichreadResolve an executable/file command using the current LConnect process PATH and Windows PATHEXT semantics.
write_filedestructiveCreate or overwrite a text file.
write_process_inputwriteWrite text to stdin of a running process session.
zeta_fixturereadfixture
04

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (3 observation(s))
Network
declared (7 observation(s))
Shell
declared (5 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (17)

HIGHPrompt injection · prompt.credential_read · CWE-94, CWE-1427
<tool:env_get>:1
Read one environment variable from the LConnect process, user profile, or machine environment.
Why it matters. asks the agent to read credentials
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
modules/browser-chrome.mjs:323
const endpoint = `http://127.0.0.1:${port}`;
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
modules/browser-firefox.mjs:332
const endpoint = `http://127.0.0.1:${port}`;
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
lconnect-mcp.mjs:1
import { McpServer } from "@modelcontextprotocol/sdk/server/mcp.js";
MEDIUMHard-coded secrets · secret.github · CWE-798, CWE-321
tests/github-smoke.mjs:13
const tokenLike = "ghp_ABCDEFGHIJKLMNOPQRSTUVWXYZ123456";
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
clipboard_clear, env_set, git_branch, git_fetch, git_push, git_worktree, kill_process, stop_log_follow, stop_watch, terminate_process, tool_telemetry, write_file
Why it matters. 12 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.suspicious_name · CWE-1104
docs/development/reports/LCN-20260928-050-post-retry-auto-round-and-github-wait-payload-containment.md
LCN-20260928-050-post-retry-auto-round-and-github-wait-payload-containment.md
Why it matters. member named after an attack tool
Fix. remove or justify
LOWInventory / provenance · inv.suspicious_name · CWE-1104
docs/development/tasks/LCN-050-post-retry-auto-round-and-github-wait-payload-containment.md
LCN-050-post-retry-auto-round-and-github-wait-payload-containment.md
Why it matters. member named after an attack tool
Fix. remove or justify
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/browser-chrome-smoke.mjs:32
try { await adapter.attach({ endpoint: "http://192.0.2.1:9222" }); } catch (error) { remoteError = error; }
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/browser-firefox-smoke.mjs:61
const endpoint = `http://127.0.0.1:${address.port}`;
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/browser-firefox-smoke.mjs:129
await remoteLayer.attach({ browser: "firefox", endpoint: "http://192.0.2.1:4444", options: { session_id: "x" } });
LOWObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
tests/development-smoke.mjs:1
import fsp from "node:fs/promises";
LOWObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
tests/environment-smoke.mjs:1
import path from "node:path";
LOWObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
tests/execution-smoke.mjs:1
import path from "node:path";
LOWObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
tests/file-watcher-smoke.mjs:1
import fsp from "node:fs/promises";
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, zod
Why it matters. 2 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
docs/development/reports/LCN-20261001-051-v1.2.1-current-reliability-release.md:85
Operational note: the first non-interactive start call omitted explicit script parameters and correctly refused to read credentials through `Read-Host`. The subsequent invocation passed the already-pr
Why it matters. asks the agent to read credentials

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha b7048eb6f195full audit observations/trust-audit/mcp-server/funggier__lconnect.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08b7048eb6f195BLOCKD69first audit
06

Questions

What is the LConnect MCP server?

MCP-LocalConnect

What tools does LConnect expose?

152 in total: 98 read-only, 42 that write, and 12 that can delete or overwrite (clipboard_clear, env_set, git_branch, git_fetch, git_push). Every one is listed on this page with its risk.

Is LConnect safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 12 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does LConnect need?

It reads GH_TOKEN and GITHUB_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does LConnect run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as lconnect-mcp at 1.3.1.

How current is this page?

The grade is for one exact copy of the source (b7048eb6f195), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement