
Company News
Jerod Santo Joins Socket as Head of Media
Allow myself to introduce... myself.
mcp-agentic-server
Advanced tools
Agentic MCP — local coding tools for ChatGPT Developer Mode and other MCP clients. Tested with ChatGPT Plus via HTTPS tunnel; availability varies by plan and rollout. Independent project, not affiliated with OpenAI.
Connect compatible ChatGPT Web accounts to local coding tools through MCP Developer Mode.
Agentic MCP connects ChatGPT Web Developer Mode to your local repositories through a secure Model Context Protocol (MCP) server. It supports structured file editing, shell execution, Git worktrees, semantic navigation and checkpoints.
ChatGPT Web → Developer Mode → HTTPS Tunnel → Agentic MCP → Local Repository
[!WARNING] Security Notice: This tool runs on your local machine and can execute shell commands. A managed Git worktree provides an isolated Git checkout to prevent polluting your main repository, but it is not an operating system sandbox. It does not restrict network access or subprocesses. Always review what the LLM intends to run.
[!NOTE] Disclaimer: Agentic MCP is an independent open-source project and is not affiliated with, sponsored by, or endorsed by OpenAI. ChatGPT and OpenAI are trademarks of OpenAI. Tested by the maintainer with ChatGPT Plus using Developer Mode and an HTTPS tunnel. Availability of MCP capabilities depends on the user's ChatGPT plan, workspace configuration and current OpenAI rollout.
Agentic MCP is published in the Official MCP Registry as:
io.github.hugolsramos01-bit/mcp-agentic-server
Install and run locally for Claude Desktop, Cursor, or other local MCP clients:
npx -y mcp-agentic-server@latest stdio
Turn ChatGPT Web into your primary local coding agent using your existing Web plan:
Initialize and start the server:
npx -y mcp-agentic-server@latest init
npx -y mcp-agentic-server@latest serve
Expose the local port (7676) via an HTTPS tunnel:
ngrok http 7676
Enable Developer Mode in ChatGPT Web:
Connect the Custom MCP App:
/mcp:
https://YOUR-SUBDOMAIN.ngrok.app/mcp
Complete OAuth Authentication:
Start Coding:
"Open workspace
C:/path/to/projectusing open_workspace and summarize the architecture."
Tested by the maintainer with ChatGPT Plus via Developer Mode and a public HTTPS tunnel (ngrok, Cloudflare Tunnel, etc.). Availability may vary by account, region, plan, and rollout.
When connected directly through ChatGPT Developer Mode, model usage is handled by the user's ChatGPT account rather than by an OpenAI Platform API key. Applicable limits depend on the user's plan and OpenAI policies.
No OpenAI model API key is required. Authentication for the MCP server and tunnel is separate from model API billing.
Yes. It gives ChatGPT Web full local coding capabilities: file inspection, structured line-precise editing, shell execution, Git worktrees, AST navigation, and checkpoints.
Version 1.8.0 turns read_many into a bounded composite inspection primitive instead of merely a multi-file reader:
include globs.paths calls remain supported, and composite reads cap path/file/source-byte loading plus diagnostic string sizes so a narrow request cannot accidentally create an oversized filesystem or response payload.Version 1.6.0 focuses on lower-latency coding loops without weakening the security and verification boundaries introduced in 1.5.0:
safe remains the default, trusted
enables practical inline scripting and shell file writes while retaining
destructive-command protections, and full is available for explicitly
unrestricted local execution.read_many defaults to 12k tokens, fast task
context caps large code-region reads at 160-line anchor windows, and file
indexes stay warm across normal model reasoning gaps.AGENTIC_WIDGETS=changes, single-file
edit/write mutations carry their review UI directly and no longer need a
redundant aggregate show_changes round trip.Stop melting your LLM context windows and preserve your ChatGPT Web message limits.
workspace_summary: Instead of a massive unified file dump, returns a compact, high-level map of the workspace (git status, package manager, key scripts, and schemas).read tool forces offset/limit paginations and strict line-range constraints. The model gets exactly what it needs, down to the line, preventing catastrophic token bloat on large files.Running experimental code, tests, or destructive LLM edits in your main directory can break your Hot Module Replacement (HMR), trigger infinite loops in Next.js/Vite, or mess up your node_modules.
open_workspace (mode="worktree"): Automatically spins up an isolated, detached git worktree outside your project's main directory (e.g., ~/.agentic/worktrees/).worktree_install_deps (with allowLifecycleScripts safely controlled), or sync uncommitted changes via worktree_sync_changes, all without touching your live development environment.The server parses TypeScript and JavaScript dynamically (with an in-memory LRU cache to save CPU) to provide the model with semantic maps of your architecture.
next_route_map: Maps out Next.js App Router and Pages Router dynamically, showing roles (api, page, layout) and dynamic segments.payload_schema_map: Analyzes Payload CMS collections to return a clean map of fields, hooks, and relationships.file_dependencies: Maps outward (what a file imports) and inward (who imports the file) dependencies instantly.edit_dry_run: Simulates replacements to validate exact string matching and uniqueness, returning the surrounding context of the would-be edit without saving to disk.changed_files_summary: Fast, accurate summaries of modified and newly staged files using git status --porcelain.For long autonomous sessions, the agent can save point-in-time snapshots of the workspace (checkpoint_save), list them (checkpoint_list), and roll back (checkpoint_restore) if it goes down a bad architectural path.
If you prefer using desktop MCP hosts, configure your client configuration file to use the stdio transport:
{
"mcpServers": {
"agentic-mcp": {
"command": "npx",
"args": ["-y", "mcp-agentic-server@latest", "stdio"],
"env": {
"AGENTIC_ALLOWED_ROOTS": "C:/path/to/projects"
}
}
}
}
The tool surface depends on the AGENTIC_TOOL_MODE setting.
| Mode | Tools included | Use case |
|---|---|---|
assistant (default) | Canonical coding workflow: workspace, context, read/search, Git, checkpoints, edit/dry-run, package scripts, worktrees, diagnostics, and semantic maps. | Full coding-agent workflow with curated model instructions. |
full | Base tools + grep, glob, ls | Manual inspection via shell |
minimal | open_workspace, read, write, edit, bash | Restricted surface |
Note: The
assistantmode is recommended for the full agentic coding experience. SetAGENTIC_TOOL_MODE=assistantin your.envor environment.
Tool mode and command security are separate. AGENTIC_SECURITY_MODE controls what shell commands may pass the policy engine:
| Security mode | Behavior |
|---|---|
safe (default) | Strict command policy. Blocks inline scripting/file-writing shell constructs and destructive commands. |
trusted | Allows python -c, node -e, redirects, heredocs and in-place shell writes, while destructive operations remain protected. |
full | Bypasses command-policy restrictions, including destructive-command rules. |
Persist the setting with agentic config set securityMode safe|trusted|full, then restart the server. OAuth remains required. The shell is not an OS sandbox and may access anything available to the local user account, so trusted and especially full should only be enabled intentionally.
| Tool | Description |
|---|---|
open_workspace | Opens a project. Supports mode="checkout" or mode="worktree". |
read | Hardened file reader with startLine, endLine, offset, limit. |
write | Create or overwrite files. |
edit | Targeted string replacements. |
bash | Fallback for shell interactions that have no typed tool; prefer run_package_script for package scripts and the Git tools for Git. |
visual_review | Capture a local web app at responsive desktop/laptop/tablet/mobile viewports and return PNG screenshots directly to the model. Supports custom viewports; local URLs only. |
assistant)| Tool | Description |
|---|---|
workspace_summary | Compact architectural summary of the workspace. |
project_bootstrap | Scans package managers, monorepo bounds, and base dependencies. |
read_many | Composite bounded inspection: exact reads/ranges, scoped match+context (with optional file include glob), and scoped globs in one ordered call with shared serialized-evidence/line/file budgets and payload-cost reporting. |
tree | Directory tree visualization. |
next_route_map / payload_schema_map | Next.js / Payload CMS schema extraction. |
file_dependencies | Inward and outward dependency map. |
checkpoint_* | Save, restore, list, or delete snapshots. |
edit_dry_run | Preview edits without writing. |
worktree_* | Manage isolated git worktrees (create, list, sync, teardown). |
worktree_install_deps | Install dependencies in a managed worktree; use verify: true to load native bindings. |
agentic_doctor | Diagnose Node, package managers, Git and native SQLite availability. |
semantic_pack | Compact goal-relevant summary with token budget. |
context_budget | Estimate token count for files. |
expand_compressed_block | Expand omitted blocks from read_compressed. |
token_audit | Analyze token usage across files read. |
tournament_* | Autonomous evaluation and judgment of changes. |
risk_assess_command | Preview policy assessment before bash. |
changed_files_summary | Fast Git status and diff abstraction. |
task_context | Computes a RiskProfile (risk level, score, blast radius) from focused paths. |
suggest_checks | Advisory planner returning a deterministic VerificationPlan. |
The risk and verification pipeline enforces strict, deterministic planning.
task_context now produces a RiskProfile accounting for sensitive configuration, fan-out, test proximity, and analysis confidence.suggest_checks returns a VerificationPlan and is advisory only (commands are not executed). Mutating checks and non-existent scripts are excluded. Low confidence can elevate policyLevel without altering the intrinsic riskLevel. When local Git metadata is unavailable, the planner uses goal_discovery from the stated goal and focused paths instead of inheriting an ancestor repository.Supported Inputs:
{
workspaceId: string;
changedPaths?: string[]; // Actual paths changed
goal?: string; // Optional goal for discovery
taskType?: "auto" | "bug_fix" | "feature" | "refactor" | "security_review" | "migration" | "frontend" | "release";
focusPaths?: string[]; // Specific files to focus on
// Legacy compatibility transition (deprecated)
paths?: string[];
scope?: "changed" | "workspace";
level?: "minimal" | "recommended" | "full";
}
Deprecated compatibility aliases are hidden by default and never appear in the model's standard workflow. Existing clients can temporarily opt in with AGENTIC_LEGACY_ALIASES=1; they will be removed in the next major release. New clients must use the canonical names above: edit_dry_run, next_route_map, payload_schema_map, changed_files_summary, and project_bootstrap.
This server is designed to act as the "hands and eyes" of a remote AGI. If you are building an autonomous agent or using Claude/ChatGPT for coding, instruct your agent to:
task_context; if a strong target is already known, skip broad discovery.read_many to batch related exact reads, match+context inspections, and scoped globs in one round trip. Put the most important items first because item order is budget priority.semantic_pack only when broad domain structure or inter-file relationships are genuinely unknown; stop broad discovery once implementation targets are strong enough.read_compressed for large whole-file orientation — expand omitted blocks before editing them.mode="worktree" if the task involves running complex shell commands or destructive tests, and use edit_dry_run before ambiguous or risky replacements.A managed worktree is an isolated Git checkout, not an operating-system sandbox. It keeps experiments out of the primary checkout, but it does not restrict network access, subprocesses, credentials, CPU/memory use, or paths that are otherwise allowed to the server. Treat scripts as real local commands and use the typed Git/script tools first. Git tools only operate when the opened workspace itself is the repository root; an ancestor repository is rejected rather than exposing sibling projects.
Licensed under the MIT License. See LICENSE for more details.
This project uses components heavily inspired by internal security architectures, with thanks to standard best practices in the open source community.
We welcome contributions! Please see CONTRIBUTING.md for details on how to get started.
FAQs
Agentic MCP — local coding tools for ChatGPT Developer Mode and other MCP clients. Tested with ChatGPT Plus via HTTPS tunnel; availability varies by plan and rollout. Independent project, not affiliated with OpenAI.
The npm package mcp-agentic-server receives a total of 276 weekly downloads. As such, mcp-agentic-server popularity was classified as not popular.
We found that mcp-agentic-server demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Company News
Allow myself to introduce... myself.

Research
/Security News
A Twitch browser extension on Chrome and Firefox forwards users’ live OAuth session tokens through proxies controlled by a Russian bot service.

Security News
Anthropic found biased reasoning and recklessness drove Claude Mythos 5 to publish malware on PyPI and compromise a security vendor.