LConnectBLOCK
MCP-LocalConnect
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
LConnect คือ MCP server แบบ modular สําหรับให้ ChatGPT เข้าถึงและควบคุมเครื่อง Windows ผ่าน OpenAI Tunnel
เป้าหมายหลักของโปรเจกต์คือให้ AI สามารถทํางานพัฒนาและดูแลเครื่องได้ต่อเนื่องจากจุดเดียว เช่น อ่าน/แก้ไฟล์ รัน PowerShell เปิด process อ่าน stdout/stderr ส่ง stdin ตรวจ process และ port ตลอดจนเพิ่ม module ใหม่ในอนาคต
ค่าเริ่มต้นของ LConnect คือ Full-machine access Filesystem สามารถเข้าถึง path ใดก็ได้ที่ Windows account ซึ่งรัน LConnect มีสิทธิ์เข้าถึง และ shell/process ทํางานด้วยสิทธิ์ของ Windows account เดียวกัน
สถานะปัจจุบัน
- Source version: 1.3.1
- MCP catalog on current
main: 154 tools - Tool-surface policy:
docs/TOOL_SURFACE_POLICY.md - Release: [v1.3.1 — Operational Hardening & Optional Autostart](https://github.com/funggier/LConnect/releases/tag/v1.3.1)
- OpenAI tunnel-client minimum: 0.0.14
LConnect Core ผ่าน runtime acceptance บน Windows 10 แล้ว โดย current main แสดง 154 tools ครอบคลุม filesystem, shell, managed process/session, system/network/hardware, Git, GitHub Actions/Release, structured inspection, browser automation แบบ isolated, live browser control ผ่าน Windows UI Automation, runtime/delivery evidence, deployment verification และ turn-risk observation แบบไม่บล็อกการทํางาน
ไฮไลต์ v1.3.1
- เก็บ Runtime API key + Organization ID แบบเข้ารหัสใน
local-secrets\credentials.json.enc - ใช้ Windows DPAPI / CurrentUser และจํากัด ACL ให้ Windows user ปัจจุบันกับ SYSTEM
Start-LConnect.cmdใช้ลําดับ parameter > environment > stored DPAPI > interactive prompt- first run สามารถบันทึก credential แบบเข้ารหัสได้โดยไม่เก็บ plaintext secret ใน Git
- เพิ่ม
Setup-LConnectCredential.cmd,Status-LConnectCredential.cmdและClear-LConnectCredential.cmd Restart-LConnect.cmdใช้ detached worker เพื่อคืนผลก่อนหยุด tunnel เดิม แล้ว start LConnect ใหม่แบบ non-interactive- Runtime API key ไม่ถูกส่งผ่าน restart command line
local-secrets/ถูก preserve ระหว่าง de
b7048eb6f195OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add lconnect-mcp --env GH_TOKEN=${GH_TOKEN} --env GITHUB_TOKEN=${GITHUB_TOKEN} -- npx -y [email protected]{
"mcpServers": {
"lconnect-mcp": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"GH_TOKEN": "${GH_TOKEN}",
"GITHUB_TOKEN": "${GITHUB_TOKEN}"
}
}
}
}Exposed tools (152)
98 read · 42 write · 12 destructive. Blast radius: 12 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
alpha_fixture | read | fixture |
batch_inspect | write | Run up to 10 explicit allowlisted read-only LConnect inspections inside one MCP round trip. No shell/process/Git mutation, writes, network requests, autonomous branching, loops, or nested batches. |
battery_info | read | Return battery inventory/status when a battery is exposed; desktops without batteries return available=false. |
browser_attach | read | Attach to an explicitly automation-enabled browser endpoint. This never discovers or enables automation on a normal live profile. |
browser_click | read | Click a DOM target through the browser backend; native mouse fallback is not automatic. |
browser_live_attach | read | Attach semantically to a currently open Firefox/Chrome window using Windows UI Automation only. No WebDriver/CDP or profile mutation is enabled. |
browser_live_click | write | Invoke/select a live browser accessibility element without enabling browser remote automation. |
browser_live_snapshot | read | Return a bounded Windows UI Automation snapshot from an attached live browser window. |
browser_live_stop | write | Detach the LConnect live-browser session only. The browser process and profile are never closed or modified. |
browser_live_tabs | read | List visible browser tab UI items through Windows UI Automation. |
browser_live_type | write | Set text through UI Automation ValuePattern on a live browser accessibility element; no WebDriver/CDP is used. |
browser_navigate | read | Navigate a browser tab using the common adapter-neutral API. |
browser_screenshot | read | Capture a bounded screenshot. File-backed output is the default to avoid large MCP payloads; inline base64 is opt-in. |
browser_snapshot | read | Return a bounded DOM snapshot or accessibility-oriented snapshot through the active backend. |
browser_start | write | Start an isolated managed browser session. Normal user profiles are never reused unless the caller explicitly opts into an external profile. |
browser_stop | write | Stop a managed session or detach an attached session. Attached remote sessions are left running unless close_remote_session=true is explicitly requested. |
browser_tabs | read | List tabs/contexts through the browser session |
browser_type | read | Type text into a DOM target through the browser backend; native keyboard fallback is not automatic. |
clipboard_clear | destructive | Clear the Windows clipboard and verify that it is empty. |
clipboard_get | read | Read text from the Windows clipboard with bounded output and explicit empty/non-text state. |
clipboard_set | write | Set Windows clipboard text using a Unicode-safe exact roundtrip. |
close_window | read | Request a native window to close by posting WM_CLOSE; this does not forcibly terminate the owning process. |
command_run | write | Run a short executable command with an argument array. Synchronous execution is capped by the LConnect MCP request budget; use start_process for long-running work. On Windows, launch failures are retried through PowerShell. |
compare_directories | read | Compare two bounded directory manifests by relative path, size, and streamed digest. Returns missing/extra/changed evidence; equality is null when either side is incomplete or unstable. |
compare_files | read | Compare two files using size plus a streaming cryptographic digest and return evidence for both sides. SHA-256 is the default. |
cpu_info | read | Return structured CPU topology and clock information. |
create_directory | write | Create a directory recursively if needed. |
create_scheduled_task | write | Create a Windows Scheduled Task for the current LConnect Windows user. |
delivery_snapshot | read | Return one compact read-only correlation snapshot combining LConnect handler telemetry with local tunnel delivery/control-plane metrics. Reads only the runtime loopback health endpoint and omits tunnel IDs, credentials, arguments, request bodies and raw metrics. |
deployment_verification_snapshot | read | Return one bounded read-only deployment evidence snapshot: Git-tracked source↔installed parity, package/dependency evidence, preserved local paths, and the running runtime catalog identity. Does not copy, install, restart, refresh, fetch, or release. |
detect_build_system | read | Detect build/package systems and supported execution contracts. |
detect_project | read | Detect project ecosystems from evidence in one project directory. |
directory_manifest | read | Recursively stream-hash a bounded selected directory tree and return a deterministic relative-path manifest digest plus bounded file evidence. Symlinks/junctions are not followed. |
directory_tree | read | Return a recursive JSON directory tree with a hard entry bound. |
disk_info | read | Return logical volume and physical disk inventory. |
dns_lookup | read | Resolve a hostname using the operating system resolver. |
edit_file | write | Replace exact text sequences in a text file and return a compact diff. |
env_get | read | Read one environment variable from the LConnect process, user profile, or machine environment. |
env_list | read | List environment variables. Values are omitted by default to reduce accidental secret exposure. |
env_set | destructive | Set or delete an environment variable. Process scope affects only the running LConnect process; user/machine scopes persist for future processes. |
file_hash | read | Stream a file and return deterministic cryptographic digest evidence without loading the whole file into memory. SHA-256 is the default. |
find_process | read | Find Windows processes using structured filters. |
fixture_work | read | fixture |
focus_window | read | Request foreground focus for a native window. Windows may reject focus stealing; actual foreground state is reported. |
follow_log | write | Start a bounded background log follower and return a follower ID immediately. |
get_file_info | read | Return metadata for a file or directory. |
get_scheduled_task | read | Read one Windows Scheduled Task by exact task_path + task_name. |
get_service | read | Get one Windows service by exact service Name. |
get_window | read | Inspect one native window by exact HWND. |
git_branch | destructive | List, create, switch or delete local Git branches. |
git_commit | write | Create a Git commit with explicit staging behavior and return exact SHA evidence. |
git_diff | read | Return a bounded Git diff or name-only change list. |
git_fetch | destructive | Fetch from a Git remote without force behavior. |
git_is_ancestor | write | Resolve two commit-ish values to exact commit SHAs and report whether the first is an ancestor of the second. |
git_log | write | Return structured Git commit history. |
git_pull | read | Pull updates, using fast-forward-only mode by default. |
git_push | destructive | Push the current or specified branch to a Git remote. Force push is intentionally not supported. |
git_push_ref | write | Push one exact source commit/full ref to one explicit full branch ref with non-force fast-forward safety and before/after remote SHA evidence. |
git_remote_ref | read | Resolve one exact full remote Git ref to its SHA without mutating the repository. |
git_status | read | Return structured repository, HEAD, upstream and working-tree status. |
git_sync_status | write | Compare local HEAD/cached upstream state with one exact remote Git ref without fetching or mutating the repository. |
git_worktree | destructive | List, add, remove or prune Git worktrees. |
github_commit_run_status | write | Correlate one exact 40-hex commit SHA to GitHub Actions runs and return the deterministic latest matching run with jobs/steps. |
github_release_download | read | Download one exact GitHub Release asset through gh into an allowed existing directory using same-directory temporary staging, size bounds, and local SHA-256 evidence. |
github_release_view | read | Return structured metadata and assets for one exact GitHub Release tag. |
github_run_failed_logs | write | Return bounded failed-job/step evidence and failed logs for one GitHub Actions run. |
github_run_list | write | List GitHub Actions runs through authenticated gh with structured bounded output. |
github_run_view | write | Return structured metadata and jobs for one exact GitHub Actions run ID. |
github_run_wait | write | |
github_workflow_dispatch | read | Dispatch one exact GitHub workflow with explicit inputs. Input values are never echoed in the result. |
gpu_info | read | Return graphics adapter/driver inventory exposed by Windows. |
http_download | read | Download an HTTP resource to a file with timeout, size limit and atomic temp-file replacement. |
http_headers | read | Read HTTP response headers with a bounded HEAD request. |
http_probe | read | Probe an HTTP endpoint with HEAD, optionally falling back to GET for 405/501. |
http_request | read | Make a bounded HTTP request and return structured status, headers and body. |
install_dependencies | write | Start dependency installation as a managed process session and return immediately. |
key_combo | read | Press a guarded key combination on a foreground HWND target, releasing keys in reverse order. |
key_press | read | Press and release one supported virtual key on a guarded foreground HWND target. |
kill_process | destructive | Terminate a Windows process by PID using taskkill. |
latency_budget_status | read | Read observation-only LConnect turn-risk telemetry. Compatibility name retained; no handler-sum-derived ceiling or blocking policy is enforced. |
latency_round_start | write | Start a fresh observation-only LConnect turn-risk round at zero. Previous-round measurements never carry into the new round. |
list_allowed_directories | read | Returns the current LConnect filesystem access scope. |
list_directory | read | List files and directories in one directory with a bounded entry count. |
list_directory_with_sizes | read | List directory entries with file sizes and a bounded entry count. |
list_listening_ports | read | List local TCP listening ports and owning process IDs. |
list_processes | read | List Windows processes with PID, name and executable path when available. |
list_scheduled_tasks | read | List Windows Scheduled Tasks with bounded structured output. |
list_services | read | List Windows services with structured state/startup information. |
list_sessions | read | List process sessions started by this LConnect instance. Supports filtering/pagination and a compact summary mode; buffered stdout/stderr are omitted by default. |
list_windows | read | List native top-level Windows windows with HWND/PID/title/class/rectangle evidence. |
maximize_window | read | Maximize a native window and return before/after evidence. |
memory_info | read | Return structured physical/virtual memory and RAM-module information. |
minimize_window | read | Minimize a native window and return before/after evidence. |
mouse_click | read | Click at virtual-desktop screen coordinates with optional exact root-HWND point guard. |
mouse_move | write | Move the Windows cursor to virtual-desktop screen coordinates and report cursor/window evidence. |
mouse_scroll | write | Send vertical or horizontal wheel input at screen coordinates with optional exact root-HWND point guard. |
move_file | write | Move or rename a file or directory. |
move_window | write | Move a native window using virtual-desktop screen coordinates; negative coordinates are valid on multi-monitor layouts. |
network_interfaces | read | Return structured local network interface addresses from Node/OS APIs. |
path_list | read | Return PATH entries for process, user, or machine scope with existence and duplicate information. |
ping_host | write | Send bounded ICMP echo requests using .NET Ping and return structured replies. |
port_owner | read | Find local TCP/UDP endpoints using a port and correlate owning PIDs with process metadata. |
port_test | read | Test a TCP connection to a host/port with a bounded timeout. |
powershell_run | write | Run a short PowerShell command on the local Windows computer. Synchronous execution is capped by the LConnect MCP request budget; use start_process for long-running work. |
process_details | read | Return structured Windows process details and creation-time identity for one PID. |
process_tree | read | Return a process subtree plus ancestors using PID/parent PID relationships. |
project_info | read | Return structured project metadata. Node package metadata is expanded when present. |
prune_sessions | write | Dry-run or release terminal process sessions older than a specified age. Running sessions are never pruned. |
read_file | read | Deprecated compatibility alias of read_text_file; use read_text_file for new workflows. |
read_log_events | read | Read buffered log follower events after a sequence cursor without waiting. |
read_media_file | read | Read an image/audio/other file as base64 content with an explicit byte bound. |
read_multiple_files | read | Read multiple text files in one call with per-file and total output bounds. |
read_process_events | read | Read incremental process output/lifecycle events after a sequence cursor. |
read_process_output | read | Compatibility buffered-output API for a process session. New cursor-based workflows should use read_process_events. |
read_text_file | read | Read a text file with optional head/tail selection and a bounded text result. |
refresh_state | read | Reconcile transient process/log/watch state and optionally prune safe terminal/stopped handles. Running work is preserved. |
release_session | read | Forget one terminal process session and its buffered evidence. Running sessions are refused. |
resize_window | read | Resize a native window while preserving its current top-left position. |
restart_process | write | Restart an explicitly identified process. Requires creation-time identity and an explicit relaunch program. |
restart_service | write | Restart one Windows service selected by exact service Name. A stopped service is started. |
run_build | write | Start a Node build script as a managed process session and return immediately. |
run_lint | write | Start a Node lint script as a managed process session and return immediately. |
run_tests | write | Start a Node test script as a managed process session and return immediately. |
runtime_catalog | read | Report the catalog loaded by this running LConnect process: tool count, stable name digest, process identity and optional sorted tool names. Useful for distinguishing a restarted runtime from a stale client/plugin catalog. |
search_files | read | Recursively search for files/directories using glob-style patterns with hard traversal, depth, time and output bounds. |
search_log | read | Search a bounded tail region of a text log using literal or regular-expression matching. |
search_text | read | Search UTF-8 text content recursively with literal/regex modes, path/line/column evidence, context, binary/error reporting, and hard files/bytes/matches/output bounds. |
session_status | read | Read immediate compact status for one managed process session without waiting. Output is omitted by default; request a bounded tail only when needed. |
set_service_startup | write | Set Windows service startup mode by exact service Name. |
start_process | write | Start a long-running local process and return a session ID. |
start_service | write | Start one Windows service selected by exact service Name and wait for Running state. |
stop_log_follow | destructive | Stop and remove a log follower session. |
stop_service | write | Stop one Windows service selected by exact service Name and wait for Stopped state. |
stop_watch | destructive | Stop and remove a filesystem watcher session. |
storage_health | read | Return physical storage health when Windows exposes it; otherwise return an explicit fallback/unavailable result. |
structured_data_inspect | read | Parse a bounded UTF-8 JSON, YAML, or TOML file and inspect one node using RFC 6901 JSON Pointer. Returns compact metadata plus a bounded structured value preview without modifying the file. |
system_info | read | Return basic local machine and Node runtime information. |
tail_file | read | Read the last lines of a text log with a bounded byte scan. |
tcp_connections | read | List structured local TCP connections using lightweight netstat parsing. |
terminate_process | destructive | Terminate a process session started by LConnect. |
tool_telemetry | destructive | Inspect or clear bounded metadata-only telemetry for LConnect tool handlers. Arguments, command text, file contents, environment values, and result contents are never recorded. |
type_text | read | Type Unicode text into a guarded foreground HWND target using KEYEVENTF_UNICODE. |
udp_endpoints | read | List structured local UDP endpoints using lightweight netstat parsing. |
wait_process | read | Wait a bounded time for a specific process identity to exit. Creation time is required to detect PID reuse. |
wait_session | read | Wait briefly (default 1s, maximum 3s) for a managed process session. Prefer session_status for non-blocking checks. Timeout never terminates managed work. |
watch_events | read | Read buffered filesystem events after a sequence cursor without waiting. |
watch_path | write | Start a bounded filesystem watcher session and return a watcher ID after backend readiness. |
watch_status | read | Return status for one filesystem watcher session. |
which | read | Resolve an executable/file command using the current LConnect process PATH and Windows PATHEXT semantics. |
write_file | destructive | Create or overwrite a text file. |
write_process_input | write | Write text to stdin of a running process session. |
zeta_fixture | read | fixture |
Trust audit
BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | FAIL |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (3 observation(s))
- Network
- declared (7 observation(s))
- Shell
- declared (5 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (17)
Read one environment variable from the LConnect process, user profile, or machine environment.
const endpoint = `http://127.0.0.1:${port}`;const endpoint = `http://127.0.0.1:${port}`;import { McpServer } from "@modelcontextprotocol/sdk/server/mcp.js";const tokenLike = "ghp_ABCDEFGHIJKLMNOPQRSTUVWXYZ123456";
clipboard_clear, env_set, git_branch, git_fetch, git_push, git_worktree, kill_process, stop_log_follow, stop_watch, terminate_process, tool_telemetry, write_file
LCN-20260928-050-post-retry-auto-round-and-github-wait-payload-containment.md
LCN-050-post-retry-auto-round-and-github-wait-payload-containment.md
try { await adapter.attach({ endpoint: "http://192.0.2.1:9222" }); } catch (error) { remoteError = error; }const endpoint = `http://127.0.0.1:${address.port}`;await remoteLayer.attach({ browser: "firefox", endpoint: "http://192.0.2.1:4444", options: { session_id: "x" } });import fsp from "node:fs/promises";
import path from "node:path";
import path from "node:path";
import fsp from "node:fs/promises";
@modelcontextprotocol/sdk, zod
Operational note: the first non-interactive start call omitted explicit script parameters and correctly refused to read credentials through `Read-Host`. The subsequent invocation passed the already-pr
Gates applied: no_behavioural_pass.
b7048eb6f195full audit observations/trust-audit/mcp-server/funggier__lconnect.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | b7048eb6f195 | BLOCK | D | 69 | first audit |
Questions
What is the LConnect MCP server?
MCP-LocalConnect
What tools does LConnect expose?
152 in total: 98 read-only, 42 that write, and 12 that can delete or overwrite (clipboard_clear, env_set, git_branch, git_fetch, git_push). Every one is listed on this page with its risk.
Is LConnect safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 12 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does LConnect need?
It reads GH_TOKEN and GITHUB_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does LConnect run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as lconnect-mcp at 1.3.1.
How current is this page?
The grade is for one exact copy of the source (b7048eb6f195), read on 2026-10-08. The repository is watched and re-audited when it changes.