Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, get in touch and we’ll put it right.

com.local-mcp/local-mcp

REMOTE · LOCAL-MCP.COM · 2 COMPONENTS · SCANNED SEP 20

Let ChatGPT, Claude & Cursor use your Mac: email, calendar, iMessage, Teams, files. Local, free.

−41 this week 39 Trust /100

Recent critical change

Authorization (16 Sept 2026). See the changelog before you install this server.

Trust breakdown (7 categories)

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →

Endpoint Security97
  • The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
  • The endpoint enforces authorisation, advertised via RFC 9728 protected-resource metadata. View diagnostics → Pass
  • HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
  • The HSTS (Strict-Transport-Security) header is present. View diagnostics → Pass
  • DNSSEC is configured correctly; the domain's records validate against the full chain to the root. View diagnostics → Pass
  • The authorisation server offers only Dynamic Client Registration (RFC 7591), which MCP 2026-07-28 deprecated in favour of Client ID Metadata Documents. View diagnostics → Partial
Transport & Reachability0
Schema Quality & AI Usability0
  • Schema blocked by authentication: the endpoint requires auth we don't have to read it. See how to fix → Unverified
Stability & Change Management0
  • Stability not yet verified: not enough scan history yet (needs a 30-day window).Unverified
Tool Coverage0
  • Tool coverage blocked by authentication: the endpoint requires auth we don't have to read its tools.Unverified
Tool Safety0
  • Tool safety blocked by authentication: the endpoint requires auth we don't have to read its tools.Unverified
Capabilities0
  • Capabilities blocked by authentication: the endpoint requires auth we don't have to read them. See how to fix → Unverified

Unverified: 6 categories

Categories scored 0 because we could not verify them: authentication we do not have, an unreachable endpoint, or not enough scan history. We only credit what we can confirm. Claim this server and supply a read-only token to verify it and lift the score.

Install

How do I install the com.local-mcp/local-mcp server?

com.local-mcp/local-mcp is a hosted endpoint at https://local-mcp.com/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

remote · local-mcp.com

# add to Claude Code
claude mcp add --transport http com-local-mcp-local-mcp 'https://local-mcp.com/mcp'
// .cursor/mcp.json
{
  "mcpServers": {
    "com-local-mcp-local-mcp": {
      "url": "https://local-mcp.com/mcp"
    }
  }
}
// .vscode/mcp.json
{
  "servers": {
    "com-local-mcp-local-mcp": {
      "type": "http",
      "url": "https://local-mcp.com/mcp"
    }
  }
}
# ~/.codex/config.toml
[mcp_servers.com-local-mcp-local-mcp]
url = "https://local-mcp.com/mcp"
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "com-local-mcp-local-mcp": {
      "type": "remote",
      "url": "https://local-mcp.com/mcp",
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add com-local-mcp-local-mcp --url 'https://local-mcp.com/mcp' --transport streamable-http
# ~/.hermes/config.yaml
mcp_servers:
  com-local-mcp-local-mcp:
    url: "https://local-mcp.com/mcp"
// ~/.netclaw/config/netclaw.json
{
  "McpServers": {
    "com-local-mcp-local-mcp": {
      "Transport": "http",
      "Url": "https://local-mcp.com/mcp"
    }
  }
}
# add to Vellum
assistant mcp add com-local-mcp-local-mcp -t streamable-http -u 'https://local-mcp.com/mcp'
// mcp.json
{
  "mcpServers": {
    "com-local-mcp-local-mcp": {
      "type": "http",
      "url": "https://local-mcp.com/mcp"
    }
  }
}

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 17 Sept 26 −41
    • Endpoint reachability: reachable → behind authorisation security
    • Stability: fail → unverified security
    • Tool safety: pass → unverified security
    • Transport: pass → unverified security
    • Authorization: fail → pass security
    • First check of Authorization: partial security
    • Tool coverage: 100 → unverified functional
    • Schema quality: 75 → unverified functional
    • Capabilities: pass → unverified functional
  • 16 Sept 26 0
    • Authorization: unverified → fail critical
  • 15 Sept 26 0
    • Authorization: fail → unverified security
  • 13 Sept 26 0
    • Authorization: unverified → fail critical
  • 12 Sept 26 0
    • Authorization: fail → unverified security
    • Tool “run_diagnostics” rewrote its description, which is the text the model reads security
    • Tool “configure_clients” rewrote its description, which is the text the model reads security
    • New tool “lmcp_doctor” functional
    • “configure_clients” reworded the description of “client” cosmetic
    • “run_diagnostics” reworded the description of “focus” cosmetic
  • 11 Sept 26 0
    • Tool “finder_list” rewrote its description, which is the text the model reads security
    • Tool “file_write” rewrote its description, which is the text the model reads security
    • Tool “file_read” rewrote its description, which is the text the model reads security
    • Tool “finder_search” rewrote its description, which is the text the model reads security
  • 8 Sept 26 +29
    • Authorization: unverified → fail critical
    • Injection markers: unverified → pass security
    • Tool “excel_write_cell” rewrote its description, which is the text the model reads security
    • Tool “excel_create” rewrote its description, which is the text the model reads security
    • Tool “reply_email” rewrote its description, which is the text the model reads security
    • Schema quality: unverified → fail functional
    • Schema quality: 223 → 127 functional
    • Schema quality: 223 → 125 functional
    • Tool coverage: unverified → 100 functional
    • Schema quality: good → excellent functional
    • This server's schema is too large to store in full, so we cannot compare its tools day to day functional
    • “excel_read” added an optional parameter “force_download” cosmetic
    • “pdf_read” added an optional parameter “force_download” cosmetic
    • “ppt_read” added an optional parameter “force_download” cosmetic
    • “reply_email” added an optional parameter “save_as_draft” cosmetic
    • “word_read” added an optional parameter “force_download” cosmetic
    • “reply_email” reworded the description of “confirm” cosmetic
  • 7 Sept 26 −27
    • Tool safety: pass → unverified security
    • Authorization: fail → unverified security
    • Schema quality: 125 → 223 functional
    • Tool coverage: 100 → unverified functional
    • Schema quality: fail → unverified functional
    • MCP protocol: fail → pass functional
    • Schema quality: excellent → good functional
    • Server version: e57f9d66-d10 → c2609ba9-0f4 functional
    • This server's schema is too large to store in full, so we cannot compare its tools day to day functional
Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 20 Sept 2026 · Probed https://local-mcp.com/mcp

TLS valid

Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .

Subject Issuer Valid from Valid until Key Signature Serial
CN=local-mcp.com CN=YE1,O=Let's Encrypt,C=US 16 Sept 2026 15 Dec 2026 ECDSA 256 ECDSA-SHA384 611e3e1599b7d3d83dea72ee1855d00484e
SANs: *.local-mcp.com, local-mcp.com
CN=YE1,O=Let's Encrypt,C=US (CA) CN=Root YE,O=ISRG,C=US 3 Sept 2025 2 Sept 2028 ECDSA 384 ECDSA-SHA384 5ddd70dd31f801c85c186a7a04b80afe
CN=Root YE,O=ISRG,C=US (CA) CN=ISRG Root X2,O=Internet Security Research Group,C=US 13 May 2026 2 Sept 2032 ECDSA 384 ECDSA-SHA384 872165fc34b6e5fba8add5b3705fb53a
CN=ISRG Root X2,O=Internet Security Research Group,C=US (CA) CN=ISRG Root X1,O=Internet Security Research Group,C=US 13 May 2026 2 Sept 2032 ECDSA 384 SHA256-RSA 6c8f1dc727c7117f7baf853ac980f9cd

Background: What to check on a remote MCP endpoint →

DNSSEC secure

Validation of local-mcp.com. Secure

Zone DS Keys Algorithms Outcome
. trust_anchor 20326, 38696 8, 8 Verified
com. present 19718 13 Verified
local-mcp.com. present 2371 13 Verified
local-mcp.com. Verified address RRset verified with the apex keys
Authentication Enforced and verified

The endpoint asked for a token and published valid RFC 9728 metadata describing how to get one.

Result Enforced and verified
Enforced On connection
HTTP status 401

WWW-Authenticate challenge Bearer realm="OAuth", resource_metadata="https://local-mcp.com/.well-known/oauth-protected-resource/mcp", error="invalid_token", error_description="Missing or invalid access token"

Bearer realm="OAuth", resource_metadata="https://local-mcp.com/.well-known/oauth-protected-resource/mcp", error="invalid_token", error_description="Missing or invalid access token"
Header Value
strict-transport-security max-age=15552000
content-security-policy default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' static.cloudflareinsights.com plausible.io https://*.clarity.ms https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; img-src 'self' data: https: blob:; font-src 'self' data:; connect-src 'self' https://www.local-mcp.com https://office-mcp-production.up.railway.app https://plausible.io https://static.cloudflareinsights.com https://cloudflareinsights.com https://api.npmjs.org https://*.clarity.ms https://*.google-analytics.com https://*.analytics.google.com https://www.googletagmanager.com https://cdn.growthbook.io; frame-ancestors 'none'; base-uri 'self'; form-action 'self' https://www.local-mcp.com https://chatgpt.com https://claude.ai
x-content-type-options nosniff
x-frame-options DENY
referrer-policy strict-origin-when-cross-origin
permissions-policy camera=(), microphone=(), geolocation=(), payment=()
www-authenticate Bearer realm="OAuth", resource_metadata="https://local-mcp.com/.well-known/oauth-protected-resource/mcp", error="invalid_token", error_description="Missing or invalid access token"

Protected resource metadata

Document https://local-mcp.com/.well-known/oauth-protected-resource/mcp
Retrieved Yes
Resource https://local-mcp.com/mcp
Authorisation server https://www.local-mcp.com

Background: How OAuth 2.1 works in the 2026 MCP spec →

Transports 2 probes
Transport URL Outcome Status Location
streamable-http https://local-mcp.com/mcp Auth required 401
http (plaintext) http://local-mcp.com/mcp HTTPS enforced 301 https://local-mcp.com/mcp
MCP tools · 204 exposed · ~25,946 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →

Tool Tokens
survey_skip ~44

Skips the short in-product survey Local MCP showed the user, for now — use this when the user doesn't want to answer right now. They won't be asked again this session.

Input schema present but exposes no named parameters.

NameTypeReqDescription
messagestring
okboolean

No examples provided.

teams_call_history ~170

Reads Microsoft Teams call & meeting history from the Mac's local Teams cache — no Graph API, no token, no admin consent (the same local store the Teams Calls tab renders). Each call includes direction (incoming/outgoing/missed), participants (names + ids), start / answered / end times, duration, call type (1:1/group/meeting) and a stable call id. Optional since/until (YYYY-MM-DD) narrow the range — e.g. a daily collector pulls the previous day's calls.

NameTypeReqDescription
limitintegerMax calls to return (default 50), newest first
sincestringOnly calls on/after this date, YYYY-MM-DD (optional)
untilstringOnly calls on/before this date, YYYY-MM-DD (optional)
NameTypeReqDescription
callsarray
countinteger
errorstring

No examples provided.

teams_list_channels ~79

Lists channels in a Microsoft Teams workspace. Returns channels that are cached in the local Teams client. If the result is empty, the channels have not been loaded into the local cache yet — ask the user to open Microsoft Teams and browse to the team's channels, then try again.

NameTypeReqDescription
team_idstringyesTeam ID from teams_list_teams
NameTypeReqDescription
channelsarray
countinteger
errorstring

No examples provided.

teams_list_chats ~36

Lists Microsoft Teams chats (direct messages and group chats).

NameTypeReqDescription
limitintegerMax chats to return (default 50)
NameTypeReqDescription
chatsarray
countinteger
errorstring

No examples provided.

teams_list_teams ~61

Lists all the Microsoft Teams the user belongs to. Start here for Teams channels — the team id it returns feeds teams_list_channels / teams_read_channel_messages. (For 1:1 and group chats, list_message-style, use teams_list_chats.)

Input schema present but exposes no named parameters.

NameTypeReqDescription
countinteger
errorstring
teamsarray

No examples provided.

teams_read_channel_messages ~55

Reads messages from a Microsoft Teams channel.

NameTypeReqDescription
channel_idstringyesChannel ID from teams_list_channels
limitintegerMax messages (default 50)
team_idstringyesTeam ID
NameTypeReqDescription
countinteger
errorstring
messagesarray

No examples provided.

teams_read_chat_messages ~49

Reads messages from a Teams chat or direct message thread.

NameTypeReqDescription
chat_idstringyesChat ID from teams_list_chats
limitintegerMax messages (default 50)
NameTypeReqDescription
countinteger
errorstring
messagesarray

No examples provided.

teams_search_messages ~170

Searches your Microsoft Teams chat and direct-message history (all conversations at once) by text, sender name, and/or date range. Use this to find where something was discussed in Teams without knowing which chat. Returns matching messages with the chat they came from. Provide at least one of query, from_sender, since, until.

NameTypeReqDescription
from_senderstringFilter to a sender by display-name substring (optional)
limitintegerMax results, newest first (default 50, max 200)
querystringText to find in message bodies (case-insensitive substring)
sincestringOnly messages on/after this date, YYYY-MM-DD (optional)
untilstringOnly messages on/before this date, YYYY-MM-DD (optional)
NameTypeReqDescription
countinteger
errorstring
messagesarray

No examples provided.

teams_send_channel_message ~133

Sends a text message to a Microsoft Teams channel via Graph API. Requires connect_m365_account with Chat.ReadWrite / ChannelMessage.Send permissions. team_id and channel_id must come from teams_list_teams / teams_list_channels. First call returns a preview; set confirm=true to send.

NameTypeReqDescription
channel_idstringyesChannel ID from teams_list_channels, or the channel's name
confirmbooleanSet true to send; false returns preview
team_idstringyesTeam ID from teams_list_teams, or the team's name
textstringyesPlain-text message body

Structured output declared, but exposes no named fields.

No examples provided.

teams_send_message ~308

Sends a text message to a Microsoft Teams chat or channel. Requires Microsoft Teams to be running and signed in (token is read fresh from Teams' local cookies on each call). The chat_id MUST come from a previous teams_list_chats call — never fabricate ids. This is a write operation: the first call returns a preview, the second call (with confirm=true) actually sends. sent:true means the message was read back from the conversation (delivery verified) — trust THAT field, not a follow-up read: teams_search_messages and teams_read_chat_messages read Teams' own local sync index, which can lag a verified send by minutes (single observed case: 3 min, #2285). A zero-result sibling read right after sending is NOT evidence the send failed. A response with status "sent_unconfirmed" means the server accepted the POST but the message could NOT be verified — tell the user to open Teams itself and check before assuming the recipient was notified.

NameTypeReqDescription
chat_idstringyesThread id from teams_list_chats (e.g. '19:<uuid>_<uuid>@unq.gbl.spaces' for 1:1, '19:<uuid>@thread.tacv2' for group)
confirmbooleanMust be true to actually send. Without it, returns a preview without making any network call.
textstringyesPlain-text message body. Max 28000 chars. No formatting / mentions / attachments in v1.

Structured output declared, but exposes no named fields.

No examples provided.

todo_complete_task ~82

Marks a Microsoft To Do task as complete (via Reminders sync).

NameTypeReqDescription
confirmbooleanMust be true to complete
liststringList name to narrow search by title (optional)
task_idstringTask ID from todo_list_tasks
titlestringTask title (partial match, alternative to task_id)

Structured output declared, but exposes no named fields.

No examples provided.

todo_create_task ~125

Creates a task in Microsoft To Do (via Reminders sync). Task appears in To Do automatically once synced.

NameTypeReqDescription
confirmbooleanMust be true to create
due_datestringDue date (YYYY-MM-DD, optional)
liststringList name (from todo_get_folders). Defaults to first available list.
notesstringTask notes (optional)
priorityintegerPriority: 1=high, 5=medium, 9=low (optional)
titlestringyesTask title

Structured output declared, but exposes no named fields.

No examples provided.

todo_get_folders ~38

Lists Microsoft To Do task lists. Requires Microsoft account in Reminders sync (System Settings → Internet Accounts → Microsoft Exchange → enable Reminders).

Input schema present but exposes no named parameters.

NameTypeReqDescription
countinteger
listsarray
notestring

No examples provided.

todo_list_tasks ~82

Lists tasks from a Microsoft To Do list (or any Reminders list). Syncs via macOS Reminders.

NameTypeReqDescription
include_completedbooleanInclude completed tasks (default false)
limitintegerMax tasks to return (default 50)
liststringList name (from todo_get_folders). Leave empty to show all.
NameTypeReqDescription
countinteger
tasksarray

No examples provided.

todoist_complete_task ~44

Mark a Todoist task complete (closes it). Pass the task_id from todoist_list_tasks.

NameTypeReqDescription
task_idstringyesThe task id to complete
NameTypeReqDescription
messagestringyes
okbooleanyes

No examples provided.

todoist_create_task ~136

Create a Todoist task. Optionally set a project, a natural-language due date (due_string, e.g. 'tomorrow 5pm', 'every monday'), and priority (1=normal … 4=urgent).

NameTypeReqDescription
contentstringyesThe task text
due_stringstringNatural-language due date, e.g. 'tomorrow 5pm', 'next monday'
priorityinteger1 (normal) to 4 (urgent). Todoist UI p1 = 4.
project_idstringProject to add it to (default: Inbox)
NameTypeReqDescription
contentstring
duestring
idstring
priorityinteger
project_idstring
urlstring

No examples provided.

todoist_list_projects ~36

List your Todoist projects (id + name). Use a project's id to scope todoist_list_tasks or todoist_create_task.

Input schema present but exposes no named parameters.

NameTypeReqDescription
countintegeryes
projectsarrayyes

No examples provided.

todoist_list_tasks ~113

List active (incomplete) Todoist tasks. Optionally scope to a project_id, or pass a Todoist filter (e.g. 'today', 'overdue', '#Work & p1').

NameTypeReqDescription
filterstringA Todoist filter query, e.g. 'today', 'overdue', 'p1'
limitintegerMax results (default 50, max 200)
project_idstringOnly tasks in this project (from todoist_list_projects)
NameTypeReqDescription
countintegeryes
tasksarrayyes

No examples provided.

ui_click ~216

Clicks an element (by element_ref, at its center) or a screen coordinate (by coords). button left|right, count 2 = double-click. Returns {clicked, at:{x,y}} — `clicked` means the click event was POSTED at those coordinates, NOT that the app acted on it: CGEvent carries no delivery confirmation, so a busy, modal or input-ignoring app reports exactly the same success. Confirm the effect with ui_wait_for_element or ui_read_tree rather than trusting `clicked`. element_disabled is returned ONLY when the app actually publishes AXEnabled=false; a control that does not publish AXEnabled at all is treated as unknown and clicked. Requires Accessibility permission.

NameTypeReqDescription
buttonstringDefault left.
bystringDefault element if element_ref given, else coords.
coordsobject{x,y} in global screen points.
countinteger1 (default) or 2 for double-click.
element_refstring

No output schema declared.

No examples provided.

ui_find_element ~219

GUI automation — control a native app's interface. Finds an element (button, field, menu…) in an app's accessibility tree by role and/or label. Scope with app_bundle_id or window_id. Returns an opaque element_ref (usable by ui_click / ui_get_element this session) plus role, label, bounds, focused, and `enabled` only when the app publishes AXEnabled (otherwise `enabled_unknown: true`, which does NOT mean disabled). found=false when the app is reachable but no element matches; app_not_found is an explicit error. Requires Accessibility permission.

NameTypeReqDescription
app_bundle_idstringScope the search to this app.
indexintegerWhich match to return if several (default 0).
labelstringAX title/description to match.
matchstringDefault contains.
rolestringAX role, e.g. AXButton, AXMenuItem, AXTextField.
window_idstringAlternatively scope by a window_id from list_windows.

No output schema declared.

No examples provided.

ui_get_element ~119

Re-resolves a previously returned element_ref (its bounds/state may have changed). Returns role, label, bounds, focused, value, and `enabled` ONLY when the app publishes AXEnabled — that attribute is optional, so many perfectly usable controls omit it (TextEdit's text area does). When it is missing you get `enabled_unknown: true` instead; that is 'unknown', NOT disabled, and ui_click will click it. stale_element if the handle is unknown or the element no longer exists.

NameTypeReqDescription
element_refstringyes

No output schema declared.

No examples provided.

ui_keystroke ~180

Sends a key combination, e.g. "cmd+shift+5", "return", "cmd+,", "escape". Modifiers: cmd, shift, alt/option, ctrl, fn. The last token is the key. Returns {sent, delivery:"posted_not_confirmed"} — `sent` means the key events were POSTED, NOT that the app acted on them: CGEvent carries no delivery confirmation, and a keystroke's effect is arbitrary so nothing can be read back to prove it. Confirm the effect with ui_get_element / ui_read_tree rather than trusting `sent`. Modifiers are released after the combo, so a following ui_type is not swallowed. unknown_key if the key isn't recognized. Requires Accessibility permission.

NameTypeReqDescription
keysstringyese.g. cmd+shift+5, return, cmd+,

No output schema declared.

No examples provided.

ui_menu_bar_click ~121

Clicks a status-bar (menu bar extra / NSStatusItem) item and optionally follows a nested menu path. Best-effort via the app's AX extras menu bar; apps that render fully custom (non-AX) menus may not be reachable (fall back to ui_click at known coords). Requires Accessibility permission.

NameTypeReqDescription
app_bundle_idstringOwner of the status item.
labelstringStatus item / menu item title.
patharrayNested menu path, e.g. ["App","Settings…"].

No output schema declared.

No examples provided.

ui_read_tree ~286

Returns a COMPACT accessibility tree of a running native app's labeled + interactive elements (buttons, links, text fields, checkboxes, menus…) — the native equivalent of web_read's a11y mode. Use it to DISCOVER what to act on in an unfamiliar app when you don't already know an element's role/label (ui_find_element needs one up front). Each interactive node carries a `ref` you can pass straight to ui_click. Pass app_bundle_id of a running app (e.g. com.apple.finder — see list_windows); the tree is pruned to signal-bearing nodes and bounded by max_depth (default 12) and a node budget, so very large windows return partial. The app's macOS menu bar is skipped by default (it's hundreds of menu-item nodes) — pass include_menu_bar=true if you specifically need to act on menu-bar items.

NameTypeReqDescription
app_bundle_idstringBundle id of a RUNNING app (e.g. com.apple.finder)
include_menu_barbooleanInclude the app's macOS menu bar (hundreds of menu-item nodes). Default false.
max_depthintegerMax tree depth to descend (default 12, max 20)
window_idstringAlternative to app_bundle_id: a window id from list_windows (targets that window's app)

Structured output declared, but exposes no named fields.

No examples provided.

ui_type ~154

Types text into the focused control (or focuses element_ref first, then types). Sends real key events so validation/handlers fire. The result is VERIFIED BY READING the control back, not by the write succeeding: {typed, verified:true} means its value actually changed; input_not_applied is an explicit error meaning the events were posted and the value did NOT change (nothing was typed — usually the window is not frontmost); verified:false + verification:'unavailable' means the target publishes no readable value, so delivery could not be confirmed and you should read it back yourself. Requires Accessibility permission.

NameTypeReqDescription
element_refstringOptional; focus this element first.
textstringyesThe text to type.

No output schema declared.

No examples provided.

ui_wait_for_element ~188

Deterministic synchronization — replaces all sleeps. Polls for an element until it reaches state (present|enabled|focused|absent) or times out. A timeout is an EXPLICIT error, never a false success. Returns {satisfied, waited_ms, element_ref?, bounds?, enabled_unknown?}. state:'enabled' is satisfied unless the app publishes AXEnabled=false; if the app publishes no AXEnabled at all the result carries enabled_unknown:true — the wait did not block, but nothing was actually verified about enabled-ness.

NameTypeReqDescription
app_bundle_idstring
labelstring
matchstring
poll_msintegerDefault 150.
rolestring
statestringDefault present.
timeout_msintegerDefault 5000.
window_idstring

No output schema declared.

No examples provided.

update_calendar_event ~213

Updates an existing event in the Mac's Calendar app (Calendar.app) by ID. Pass only the fields you want to change — unspecified fields are left as-is. Get the event_id from list_calendar_events. For Microsoft 365 use the m365 calendar tools instead.

NameTypeReqDescription
confirmbooleanMust be true to apply changes
end_datestringNew end datetime ISO 8601 (optional). Same timezone rules as start_date.
event_idstringyesEvent identifier from list_calendar_events
locationstringNew location — pass empty string to clear (optional)
notesstringNew notes — pass empty string to clear (optional)
spanstringFor recurring events: 'this' (default) or 'future'
start_datestringNew start datetime ISO 8601 (optional). No timezone = Mac's local time; append Z/offset to pin the zone.
titlestringNew title (optional)
NameTypeReqDescription
all_dayboolean
attendeesarray
attendees_totalinteger
calendarstring
calendar_idstring
endstring
idstring
locationstring
notesstring
startstring
titlestring
updatedboolean

No examples provided.

update_note ~87

Updates an existing note in Apple Notes. Change the title and/or body (the body accepts Markdown, converted to Apple Notes' native formatting). Find note_id with list_notes or search_notes. Requires confirm=true.

NameTypeReqDescription
bodystring
confirmboolean
note_idstring
note_namestring
titlestring
NameTypeReqDescription
idstring
namestring
updatedboolean

No examples provided.

update_reminder ~271

Updates an existing reminder in Reminders.app. Change the title, due date, notes, priority, or move it to another list (list_name). Get reminder_id from list_reminders. Requires confirm=true. IMPORTANT: moving to a list in a DIFFERENT account (e.g. iCloud ↔ Exchange) recreates the reminder, so its id changes — the response then has id_changed: true, the new id in reminder_id and the dead one in previous_reminder_id. Always take reminder_id from the response before any follow-up call.

NameTypeReqDescription
confirmbooleanMust be true to apply changes
due_datestringNew ISO 8601 due date. Pass empty string to clear (optional)
list_namestringMove the reminder to this list (a name from get_reminder_folders) (optional). Moving to a list in ANOTHER account recreates the reminder and CHANGES its id — read the new one from reminder_id in the…
notesstringNew notes text (optional)
prioritystringPriority: none | low | medium | high (optional)
reminder_idstringyesReminder identifier from list_reminders
titlestringNew title (optional)
NameTypeReqDescription
id_changedbooleantrue when the update recreated the reminder (a move across accounts), which invalidates the id you passed in.
liststringDestination list, when the update moved the reminder.
notestring
previous_reminder_idstringOnly when id_changed: the id you passed in, which no longer exists.
reminder_idstringThe reminder's id AFTER the update — use this one from now on.
titlestring
updatedboolean

No examples provided.

video_blur_region ~152

Pixelates/blurs one or more rectangles over the video — the tool for redacting PII (an email pane, a name) before publishing a screen recording. Rects are in source pixels, top-left origin: [{x,y,w,h, start_ms?, end_ms?}] — omit the times to cover the whole clip. Great with a marker timeline's `bounds`. Returns the output path.

NameTypeReqDescription
inputstringyesPath to the source video file.
outputstringDefault: <input>_blurred.mov. Missing parent folders are created.
regionsarrayyes[{x,y,w,h, start_ms?, end_ms?}] in source pixels (top-left).

No output schema declared.

No examples provided.

video_concat ~87

Stitches multiple videos end-to-end, in order, into one NEW file (e.g. assemble separate acts). All inputs should share a resolution for a clean result. Returns the output path + duration.

NameTypeReqDescription
inputsarrayyesOrdered list of video file paths.
outputstringOutput path (default: <first-input>_joined.mov). Missing parent folders are created.

No output schema declared.

No examples provided.

video_export_gif ~169

Exports a video (or a [start_ms,end_ms] slice of it) to an optimized looping GIF — for README/social. fps (default 12) and width (default 640, height auto) control size. Returns the output path, frame count, and size.

NameTypeReqDescription
end_msintegerSlice end (default: end of video).
fpsintegerFrames per second in the GIF (default 12).
inputstringyesPath to the source video.
outputstringOutput path (default: <input>.gif). Missing parent folders are created.
start_msintegerSlice start (default 0).
widthintegerOutput width in px, height scales to keep aspect (default 640).

No output schema declared.

No examples provided.

video_reframe ~196

Crops a video to a target aspect ratio (e.g. "9:16" vertical, "1:1" square, "4:5") around a focus point — for social clips. Takes the LARGEST crop of that aspect that fits, centered on `focus` (x,y in source pixels, top-left origin; default = center) and clamped to the frame. Audio passes through. Returns the output path + new dimensions.

NameTypeReqDescription
aspectstringyesTarget aspect "W:H", e.g. 9:16, 1:1, 4:5, 16:9.
focusobject{x,y} center of interest in source pixels (top-left). Default: frame center.
inputstringyesPath to the source video file.
outputstringDefault: <input>_<aspect>.mov. Missing parent folders are created.

No output schema declared.

No examples provided.

video_trim ~136

Trims a video to one or more time ranges (milliseconds), concatenated in order into a NEW file — e.g. keep [{start_ms:0,end_ms:6000},{start_ms:126000,end_ms:223000}] to drop a dead segment. Audio is carried along. Returns the output path + duration. Never overwrites the input in place.

NameTypeReqDescription
inputstringyesPath to the source video.
outputstringOutput path (default: <input>_trimmed.mov). Missing parent folders are created.
rangesarrayyesOrdered [{start_ms, end_ms}] to keep.

No output schema declared.

No examples provided.

web_click ~222

Clicks an element on the current page. `target` is a CSS selector or visible text (resolved fresh each call). Clicks that SUBMIT a form preview first — call again with confirm:true to execute; plain links/buttons click directly. Returns {url, title, navigated, url_as_of}: `url_as_of` is "settled" when the page has finished changing, and "before_click" together with navigation_pending:true when the click started a navigation that had not finished — in that case url/title are the page BEFORE the click, NOT the destination, so do not read them as 'the click did nothing' and retry (the page is already changing); read the destination with web_read or wait for it with web_wait_for. `navigated:false` means the click changed no page.

NameTypeReqDescription
confirmbooleanRequired (true) to perform a click that submits a form.
sessionstringSession name (default 'default').
targetstringyesCSS selector or visible text of the element to click.

No output schema declared.

No examples provided.

web_extract ~86

Scrapes structured data from the current page. Pass `selectors` = an object mapping field names to CSS selectors (e.g. {"title":"h1","price":".price"}); returns each field's first-match text/href, null when absent.

NameTypeReqDescription
selectorsobjectyesField name → CSS selector map.
sessionstringSession name (default 'default').
NameTypeReqDescription
dataobjectOne key per requested field; first-match text/href, null when absent.
titlestring
urlstring

No examples provided.

web_find ~104

Finds elements on the current page of a web session so you can decide what to click or type into. `query` is a CSS selector OR visible text to match. Returns up to 30 matches with tag/text/name/type/href — never a silent empty.

NameTypeReqDescription
querystringyesA CSS selector (e.g. 'input[name=q]') or visible text (e.g. 'Sign in').
sessionstringSession name (default 'default').
NameTypeReqDescription
countintegerNumber of matching elements (max 30 returned).
matchesarrayMatched elements with tag/text/name/type/href.
querystring

No examples provided.

web_login ~144

Opens a real browser window on the Mac for the user to sign into a website themselves (you never handle their password). After they log in, the session is saved on this Mac and reused by web_navigate/web_read/web_screenshot — they won't need to log in again. Use a stable `session` name per site (e.g. 'linkedin'). NOTE: automating sites like Instagram/LinkedIn may violate their terms — the user accepts that risk.

NameTypeReqDescription
sessionstringA stable name for this login profile, e.g. 'linkedin'.
urlstringyesThe site's login URL to open, e.g. https://www.linkedin.com/login

No output schema declared.

No examples provided.

web_navigate ~128

Navigates a web session to a URL (using its saved login if any) and returns the resulting URL + page title. Opens the session if it doesn't exist. CHECK `loaded` before reading: when it is false the page did not load and `message` says why — reading the session then describes a blank document, not the site. Read the page with web_read.

NameTypeReqDescription
sessionstringSession name (default 'default').
timeout_secondsintegerMax seconds to wait for load (default 25).
urlstringyesURL to open (https).
NameTypeReqDescription
errorstringPresent only on failure: nav_failed (the browser rejected the load), nav_timeout, or nav_blank (it finished on a blank document).
loadedbooleanTrue only when the browser ended on a real web page. False means nothing was loaded — do NOT read the session and treat the result as page content.
messagestringPresent only on failure: why the page didn't load, and what to do about it.
okbooleanTrue only when the requested page actually loaded.
settle_rejected_bystringPresent only with nav_timeout: which check ruled out 'the page arrived and WebKit just did not say so' - navigation_started (another navigation began and hung, so the visible document is the old one)…
titlestringThe resulting page title.
urlstringThe URL the browser settled on (redirects followed). If it isn't the page you asked for, the navigation didn't deliver it.

No examples provided.

web_read ~116

Reads the current page of a web session so you can reason over it. mode='text' (visible text, default), 'a11y' (compact accessible tree of links/buttons/fields — best for deciding what to click), or 'html' (raw DOM). Returns an explicit no_session error if the session isn't open, and no_page if it hasn't loaded a page — never a silent empty.

NameTypeReqDescription
modestringWhat to return (default text).
sessionstringSession name (default 'default').
NameTypeReqDescription
contentstringThe page content in the requested mode.
modestringThe mode that was read (text/a11y/html).
titlestring
urlstring

No examples provided.

web_screenshot ~69

Captures a PNG screenshot of the current page of a web session (returned inline so web AIs can see it). Useful to ground what the page looks like before acting.

NameTypeReqDescription
sessionstringSession name (a named login profile, e.g. 'linkedin'). Defaults to 'default'.
NameTypeReqDescription
bytesintegerPNG size in bytes (the image itself is an inline content block).
urlstringURL of the page that was captured.

No examples provided.

web_session_close ~97

Closes a web-automation session's window and frees it. The saved login STAYS on disk (cookies included), so web_login/web_navigate can reopen it later without signing in again — it also means closing does NOT clean up: to erase a profile you no longer want stored, use web_session_delete.

NameTypeReqDescription
sessionstringSession name (a named login profile, e.g. 'linkedin'). Defaults to 'default'.

No output schema declared.

No examples provided.

web_session_delete ~168

Deletes a SAVED web-automation login profile: closes its window if open, erases its cookies and site data from this Mac, and removes it from web_session_list. Use it to clean up a profile that is no longer needed — web_session_close only closes the window and leaves the login (and its cookies) on disk. IRREVERSIBLE: the next web_login for that name starts from a signed-out browser. Requires confirm=true; without it you get a preview. Verify with web_session_list, which must no longer list the name.

NameTypeReqDescription
confirmbooleanMust be true to actually delete. Without it, returns a preview and deletes nothing.
sessionstringName of the profile to delete, as web_session_list reports it. Defaults to 'default'.
NameTypeReqDescription
closedbooleanWhether a live window had to be closed first
data_removedbooleanWhether the cookies and site data were erased
deletedstringThe profile name that was deleted
name_forgottenbooleanWhether the name was removed from web_session_list
okbooleanTrue only when BOTH halves are done: data erased and name removed from the list

No examples provided.

web_session_list ~98

Lists your web-automation login profiles: every SAVED login (persisted on disk, so web_login/web_navigate can reopen it without signing in again) plus which are currently OPEN. Each entry has `saved` (a persisted profile exists) and `open` (its window is live now, with url + title). Use it to check whether a login a recipe needs already exists before running it, instead of opening it and failing.

Input schema present but exposes no named parameters.

NameTypeReqDescription
sessionsarray

No examples provided.

web_show ~131

Brings a web session's browser window to the FRONT so the USER can take over directly — solve a CAPTCHA, complete 2FA, or make a choice the AI shouldn't. Local MCP never solves CAPTCHAs itself; this hands control to the user. Pair with web_screenshot first to show them what's on the page. After they finish, tell the agent to continue — the session keeps its state.

NameTypeReqDescription
reasonstringShort reason shown to the user, e.g. 'a CAPTCHA appeared' or 'confirm which account'.
sessionstringSession name (default 'default').

No output schema declared.

No examples provided.

web_type ~178

Types text into a form field (input/textarea) on the current page. `target` is a CSS selector or the field's visible label/placeholder. Does NOT submit — use web_click on the submit button afterwards (that step is gated). SPECIAL CASE — file inputs: if `target` resolves to an <input type="file">, `text` is instead treated as a LOCAL FILE PATH on this Mac and the file is attached (JS can't set a file input's value directly; this answers the native file panel programmatically without ever showing it).

NameTypeReqDescription
sessionstringSession name (default 'default').
targetstringyesCSS selector or visible label/placeholder of the field.
textstringyesThe text to type. For an input[type=file], this is instead the LOCAL FILE PATH to upload.

No output schema declared.

No examples provided.

web_wait_for ~204

Waits (polls, not a fixed sleep) until an element appears on the page, or times out. Use for SPA pages that hydrate after load. Prefer `selector` (a CSS selector, e.g. "input[name=password]"). `condition` also accepts the form "document.querySelector('...')"; any OTHER JavaScript condition runs arbitrary code on the page (same power as web_eval) and is disabled when LMCP is in read-only mode. Returns met:true/false.

NameTypeReqDescription
conditionstringAlternative to selector: "document.querySelector('...')" is accepted as-is; any other JS expression runs arbitrary code on the page (same power as web_eval).
selectorstringCSS selector to wait for (preferred; treated as data, never executed). e.g. .feed
sessionstringSession name (default 'default').
timeout_secondsintegerMax seconds to wait (default 15).
NameTypeReqDescription
messagestringPresent when the condition was not met.
metbooleanTrue if the condition became truthy before the timeout.
okboolean

No examples provided.

window_focus ~49

Brings a window (by window_id from list_windows) to the front and activates its app. window_not_found if it can't be resolved. Requires Accessibility permission.

NameTypeReqDescription
window_idstringyes

No output schema declared.

No examples provided.

window_set_frame ~75

Pins a window (by window_id) to fixed bounds {x,y,w,h} in global points, so every take is framed identically across runs. Returns the actual post-constraint bounds. Requires Accessibility permission.

NameTypeReqDescription
boundsobjectyes{x,y,w,h} global points.
window_idstringyes

No output schema declared.

No examples provided.

word_append ~138

Appends text to the end of an existing Word (.docx) document at `path`, preserving the document's existing content and formatting. Requires confirm=true — called without it, returns a preview instead of modifying the file. Same file-access rules as word_create (Desktop/Documents/Downloads may need a Files-and-Folders grant). Returns {appended, chars_appended, path}. To create a new document use word_create; to read one use word_read.

NameTypeReqDescription
confirmbooleanMust be true to modify
contentstringyesText to append
pathstringyesPath to the existing .docx file

Structured output declared, but exposes no named fields.

No examples provided.

Common questions

What is the com.local-mcp/local-mcp server?

com.local-mcp/local-mcp is listed in the public MCP registry as com.local-mcp/local-mcp. Let ChatGPT, Claude & Cursor use your Mac: email, calendar, iMessage, Teams, files. Local, free. This page covers its hosted endpoint (https://local-mcp.com/mcp).

Is the com.local-mcp/local-mcp server safe to use?

com.local-mcp/local-mcp scores 39 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

What tools does the com.local-mcp/local-mcp server expose?

com.local-mcp/local-mcp exposes 204 tools: setup_install, complete_omnifocus_task, complete_reminder, configure_clients, connect_m365_account, and 199 more. Their descriptions and schemas cost roughly 25,946 tokens of context every time the server is loaded.

Does the com.local-mcp/local-mcp server require authentication?

Yes. com.local-mcp/local-mcp asked us for credentials when we connected, so you will need to authorise it in your MCP client before it can do anything.

Is the com.local-mcp/local-mcp server still maintained?

com.local-mcp/local-mcp is still listed as active in the MCP registry. We last reached this channel on 20 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.