com.local-mcp/local-mcp
REMOTE · LOCAL-MCP.COM · 2 COMPONENTS · SCANNED SEP 20
Let ChatGPT, Claude & Cursor use your Mac: email, calendar, iMessage, Teams, files. Local, free.
Available components
Recent critical change
Authorization (16 Sept 2026). See the changelog before you install this server.
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security97
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- The endpoint enforces authorisation, advertised via RFC 9728 protected-resource metadata. View diagnostics → Pass
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- The HSTS (Strict-Transport-Security) header is present. View diagnostics → Pass
- DNSSEC is configured correctly; the domain's records validate against the full chain to the root. View diagnostics → Pass
- The authorisation server offers only Dynamic Client Registration (RFC 7591), which MCP 2026-07-28 deprecated in favour of Client ID Metadata Documents. View diagnostics → Partial
Transport & Reachability0
- Transport blocked by authentication: the endpoint requires auth we don't have to verify streamable-http. See how to fix → View diagnostics → Unverified
Schema Quality & AI Usability0
- Schema blocked by authentication: the endpoint requires auth we don't have to read it. See how to fix → Unverified
Stability & Change Management0
- Stability not yet verified: not enough scan history yet (needs a 30-day window).Unverified
Tool Coverage0
- Tool coverage blocked by authentication: the endpoint requires auth we don't have to read its tools.Unverified
Tool Safety0
- Tool safety blocked by authentication: the endpoint requires auth we don't have to read its tools.Unverified
Capabilities0
- Capabilities blocked by authentication: the endpoint requires auth we don't have to read them. See how to fix → Unverified
Unverified: 6 categories
Categories scored 0 because we could not verify them: authentication we do not have, an unreachable endpoint, or not enough scan history. We only credit what we can confirm. Claim this server and supply a read-only token to verify it and lift the score.
How do I install the com.local-mcp/local-mcp server?
com.local-mcp/local-mcp is a hosted endpoint at https://local-mcp.com/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · local-mcp.com
claude mcp add --transport http com-local-mcp-local-mcp 'https://local-mcp.com/mcp'
{
"mcpServers": {
"com-local-mcp-local-mcp": {
"url": "https://local-mcp.com/mcp"
}
}
} {
"servers": {
"com-local-mcp-local-mcp": {
"type": "http",
"url": "https://local-mcp.com/mcp"
}
}
} [mcp_servers.com-local-mcp-local-mcp] url = "https://local-mcp.com/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"com-local-mcp-local-mcp": {
"type": "remote",
"url": "https://local-mcp.com/mcp",
"enabled": true
}
}
} openclaw mcp add com-local-mcp-local-mcp --url 'https://local-mcp.com/mcp' --transport streamable-http
mcp_servers:
com-local-mcp-local-mcp:
url: "https://local-mcp.com/mcp" {
"McpServers": {
"com-local-mcp-local-mcp": {
"Transport": "http",
"Url": "https://local-mcp.com/mcp"
}
}
} assistant mcp add com-local-mcp-local-mcp -t streamable-http -u 'https://local-mcp.com/mcp'
{
"mcpServers": {
"com-local-mcp-local-mcp": {
"type": "http",
"url": "https://local-mcp.com/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 17 Sept 26 −41
- Endpoint reachability: reachable → behind authorisation ▼ security
- Stability: fail → unverified ▼ security
- Tool safety: pass → unverified ▼ security
- Transport: pass → unverified ▼ security
- Authorization: fail → pass ▲ security
- First check of Authorization: partial security
- Tool coverage: 100 → unverified ▼ functional
- Schema quality: 75 → unverified ▼ functional
- Capabilities: pass → unverified ▼ functional
- 16 Sept 26 0
- Authorization: unverified → fail ▼ critical
- 15 Sept 26 0
- Authorization: fail → unverified ▼ security
- 13 Sept 26 0
- Authorization: unverified → fail ▼ critical
- 12 Sept 26 0
- Authorization: fail → unverified ▼ security
- Tool “run_diagnostics” rewrote its description, which is the text the model reads security
- Tool “configure_clients” rewrote its description, which is the text the model reads security
- New tool “lmcp_doctor” functional
- “configure_clients” reworded the description of “client” cosmetic
- “run_diagnostics” reworded the description of “focus” cosmetic
- 11 Sept 26 0
- Tool “finder_list” rewrote its description, which is the text the model reads security
- Tool “file_write” rewrote its description, which is the text the model reads security
- Tool “file_read” rewrote its description, which is the text the model reads security
- Tool “finder_search” rewrote its description, which is the text the model reads security
- 8 Sept 26 +29
- Authorization: unverified → fail ▼ critical
- Injection markers: unverified → pass ▲ security
- Tool “excel_write_cell” rewrote its description, which is the text the model reads security
- Tool “excel_create” rewrote its description, which is the text the model reads security
- Tool “reply_email” rewrote its description, which is the text the model reads security
- Schema quality: unverified → fail ▼ functional
- Schema quality: 223 → 127 ▲ functional
- Schema quality: 223 → 125 ▲ functional
- Tool coverage: unverified → 100 ▲ functional
- Schema quality: good → excellent functional
- This server's schema is too large to store in full, so we cannot compare its tools day to day functional
- “excel_read” added an optional parameter “force_download” cosmetic
- “pdf_read” added an optional parameter “force_download” cosmetic
- “ppt_read” added an optional parameter “force_download” cosmetic
- “reply_email” added an optional parameter “save_as_draft” cosmetic
- “word_read” added an optional parameter “force_download” cosmetic
- “reply_email” reworded the description of “confirm” cosmetic
- 7 Sept 26 −27
- Tool safety: pass → unverified ▼ security
- Authorization: fail → unverified ▼ security
- Schema quality: 125 → 223 ▼ functional
- Tool coverage: 100 → unverified ▼ functional
- Schema quality: fail → unverified ▼ functional
- MCP protocol: fail → pass ▲ functional
- Schema quality: excellent → good functional
- Server version: e57f9d66-d10 → c2609ba9-0f4 functional
- This server's schema is too large to store in full, so we cannot compare its tools day to day functional
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 20 Sept 2026 · Probed https://local-mcp.com/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=local-mcp.com | CN=YE1,O=Let's Encrypt,C=US | 16 Sept 2026 | 15 Dec 2026 | ECDSA 256 | ECDSA-SHA384 | 611e3e1599b7d3d83dea72ee1855d00484e |
| SANs: *.local-mcp.com, local-mcp.com | ||||||
| CN=YE1,O=Let's Encrypt,C=US (CA) | CN=Root YE,O=ISRG,C=US | 3 Sept 2025 | 2 Sept 2028 | ECDSA 384 | ECDSA-SHA384 | 5ddd70dd31f801c85c186a7a04b80afe |
| CN=Root YE,O=ISRG,C=US (CA) | CN=ISRG Root X2,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | ECDSA-SHA384 | 872165fc34b6e5fba8add5b3705fb53a |
| CN=ISRG Root X2,O=Internet Security Research Group,C=US (CA) | CN=ISRG Root X1,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | SHA256-RSA | 6c8f1dc727c7117f7baf853ac980f9cd |
Background: What to check on a remote MCP endpoint →
DNSSEC secure
Validation of local-mcp.com. — Secure
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| com. | present | 19718 | 13 | Verified |
| local-mcp.com. | present | 2371 | 13 | Verified |
| local-mcp.com. | Verified address RRset verified with the apex keys |
Authentication Enforced and verified
The endpoint asked for a token and published valid RFC 9728 metadata describing how to get one.
| Result | Enforced and verified |
|---|---|
| Enforced | On connection |
| HTTP status | 401 |
WWW-Authenticate challenge Bearer realm="OAuth", resource_metadata="https://local-mcp.com/.well-known/oauth-protected-resource/mcp", error="invalid_token", error_description="Missing or invalid access token"
Bearer realm="OAuth", resource_metadata="https://local-mcp.com/.well-known/oauth-protected-resource/mcp", error="invalid_token", error_description="Missing or invalid access token" | Header | Value |
|---|---|
| strict-transport-security | max-age=15552000 |
| content-security-policy | default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' static.cloudflareinsights.com plausible.io https://*.clarity.ms https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; img-src 'self' data: https: blob:; font-src 'self' data:; connect-src 'self' https://www.local-mcp.com https://office-mcp-production.up.railway.app https://plausible.io https://static.cloudflareinsights.com https://cloudflareinsights.com https://api.npmjs.org https://*.clarity.ms https://*.google-analytics.com https://*.analytics.google.com https://www.googletagmanager.com https://cdn.growthbook.io; frame-ancestors 'none'; base-uri 'self'; form-action 'self' https://www.local-mcp.com https://chatgpt.com https://claude.ai |
| x-content-type-options | nosniff |
| x-frame-options | DENY |
| referrer-policy | strict-origin-when-cross-origin |
| permissions-policy | camera=(), microphone=(), geolocation=(), payment=() |
| www-authenticate | Bearer realm="OAuth", resource_metadata="https://local-mcp.com/.well-known/oauth-protected-resource/mcp", error="invalid_token", error_description="Missing or invalid access token" |
Protected resource metadata
| Document | https://local-mcp.com/.well-known/oauth-protected-resource/mcp |
|---|---|
| Retrieved | Yes |
| Resource | https://local-mcp.com/mcp |
| Authorisation server | https://www.local-mcp.com |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://local-mcp.com/mcp | Auth required | 401 | |
| http (plaintext) | http://local-mcp.com/mcp | HTTPS enforced | 301 | https://local-mcp.com/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
survey_skip Survey Skip ~44
Skips the short in-product survey Local MCP showed the user, for now — use this when the user doesn't want to answer right now. They won't be asked again this session.
Input schema present but exposes no named parameters.
| Name | Type | Req | Description |
|---|---|---|---|
| message | string | – | – |
| ok | boolean | – | – |
No examples provided.
teams_call_history Teams Call History ~170
Reads Microsoft Teams call & meeting history from the Mac's local Teams cache — no Graph API, no token, no admin consent (the same local store the Teams Calls tab renders). Each call includes direction (incoming/outgoing/missed), participants (names + ids), start / answered / end times, duration, call type (1:1/group/meeting) and a stable call id. Optional since/until (YYYY-MM-DD) narrow the range — e.g. a daily collector pulls the previous day's calls.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | integer | – | Max calls to return (default 50), newest first |
| since | string | – | Only calls on/after this date, YYYY-MM-DD (optional) |
| until | string | – | Only calls on/before this date, YYYY-MM-DD (optional) |
| Name | Type | Req | Description |
|---|---|---|---|
| calls | array | – | – |
| count | integer | – | – |
| error | string | – | – |
No examples provided.
teams_list_channels Teams List Channels ~79
Lists channels in a Microsoft Teams workspace. Returns channels that are cached in the local Teams client. If the result is empty, the channels have not been loaded into the local cache yet — ask the user to open Microsoft Teams and browse to the team's channels, then try again.
| Name | Type | Req | Description |
|---|---|---|---|
| team_id | string | yes | Team ID from teams_list_teams |
| Name | Type | Req | Description |
|---|---|---|---|
| channels | array | – | – |
| count | integer | – | – |
| error | string | – | – |
No examples provided.
teams_list_chats Teams List Chats ~36
Lists Microsoft Teams chats (direct messages and group chats).
| Name | Type | Req | Description |
|---|---|---|---|
| limit | integer | – | Max chats to return (default 50) |
| Name | Type | Req | Description |
|---|---|---|---|
| chats | array | – | – |
| count | integer | – | – |
| error | string | – | – |
No examples provided.
teams_list_teams Teams List Teams ~61
Lists all the Microsoft Teams the user belongs to. Start here for Teams channels — the team id it returns feeds teams_list_channels / teams_read_channel_messages. (For 1:1 and group chats, list_message-style, use teams_list_chats.)
Input schema present but exposes no named parameters.
| Name | Type | Req | Description |
|---|---|---|---|
| count | integer | – | – |
| error | string | – | – |
| teams | array | – | – |
No examples provided.
teams_read_channel_messages Teams Read Channel Messages ~55
Reads messages from a Microsoft Teams channel.
| Name | Type | Req | Description |
|---|---|---|---|
| channel_id | string | yes | Channel ID from teams_list_channels |
| limit | integer | – | Max messages (default 50) |
| team_id | string | yes | Team ID |
| Name | Type | Req | Description |
|---|---|---|---|
| count | integer | – | – |
| error | string | – | – |
| messages | array | – | – |
No examples provided.
teams_read_chat_messages Teams Read Chat Messages ~49
Reads messages from a Teams chat or direct message thread.
| Name | Type | Req | Description |
|---|---|---|---|
| chat_id | string | yes | Chat ID from teams_list_chats |
| limit | integer | – | Max messages (default 50) |
| Name | Type | Req | Description |
|---|---|---|---|
| count | integer | – | – |
| error | string | – | – |
| messages | array | – | – |
No examples provided.
teams_search_messages Teams Search Messages ~170
Searches your Microsoft Teams chat and direct-message history (all conversations at once) by text, sender name, and/or date range. Use this to find where something was discussed in Teams without knowing which chat. Returns matching messages with the chat they came from. Provide at least one of query, from_sender, since, until.
| Name | Type | Req | Description |
|---|---|---|---|
| from_sender | string | – | Filter to a sender by display-name substring (optional) |
| limit | integer | – | Max results, newest first (default 50, max 200) |
| query | string | – | Text to find in message bodies (case-insensitive substring) |
| since | string | – | Only messages on/after this date, YYYY-MM-DD (optional) |
| until | string | – | Only messages on/before this date, YYYY-MM-DD (optional) |
| Name | Type | Req | Description |
|---|---|---|---|
| count | integer | – | – |
| error | string | – | – |
| messages | array | – | – |
No examples provided.
teams_send_channel_message Teams Send Channel Message ~133
Sends a text message to a Microsoft Teams channel via Graph API. Requires connect_m365_account with Chat.ReadWrite / ChannelMessage.Send permissions. team_id and channel_id must come from teams_list_teams / teams_list_channels. First call returns a preview; set confirm=true to send.
| Name | Type | Req | Description |
|---|---|---|---|
| channel_id | string | yes | Channel ID from teams_list_channels, or the channel's name |
| confirm | boolean | – | Set true to send; false returns preview |
| team_id | string | yes | Team ID from teams_list_teams, or the team's name |
| text | string | yes | Plain-text message body |
Structured output declared, but exposes no named fields.
No examples provided.
teams_send_message Teams Send Message ~308
Sends a text message to a Microsoft Teams chat or channel. Requires Microsoft Teams to be running and signed in (token is read fresh from Teams' local cookies on each call). The chat_id MUST come from a previous teams_list_chats call — never fabricate ids. This is a write operation: the first call returns a preview, the second call (with confirm=true) actually sends. sent:true means the message was read back from the conversation (delivery verified) — trust THAT field, not a follow-up read: teams_search_messages and teams_read_chat_messages read Teams' own local sync index, which can lag a verified send by minutes (single observed case: 3 min, #2285). A zero-result sibling read right after sending is NOT evidence the send failed. A response with status "sent_unconfirmed" means the server accepted the POST but the message could NOT be verified — tell the user to open Teams itself and check before assuming the recipient was notified.
| Name | Type | Req | Description |
|---|---|---|---|
| chat_id | string | yes | Thread id from teams_list_chats (e.g. '19:<uuid>_<uuid>@unq.gbl.spaces' for 1:1, '19:<uuid>@thread.tacv2' for group) |
| confirm | boolean | – | Must be true to actually send. Without it, returns a preview without making any network call. |
| text | string | yes | Plain-text message body. Max 28000 chars. No formatting / mentions / attachments in v1. |
Structured output declared, but exposes no named fields.
No examples provided.
todo_complete_task To Do Complete Task ~82
Marks a Microsoft To Do task as complete (via Reminders sync).
| Name | Type | Req | Description |
|---|---|---|---|
| confirm | boolean | – | Must be true to complete |
| list | string | – | List name to narrow search by title (optional) |
| task_id | string | – | Task ID from todo_list_tasks |
| title | string | – | Task title (partial match, alternative to task_id) |
Structured output declared, but exposes no named fields.
No examples provided.
todo_create_task To Do Create Task ~125
Creates a task in Microsoft To Do (via Reminders sync). Task appears in To Do automatically once synced.
| Name | Type | Req | Description |
|---|---|---|---|
| confirm | boolean | – | Must be true to create |
| due_date | string | – | Due date (YYYY-MM-DD, optional) |
| list | string | – | List name (from todo_get_folders). Defaults to first available list. |
| notes | string | – | Task notes (optional) |
| priority | integer | – | Priority: 1=high, 5=medium, 9=low (optional) |
| title | string | yes | Task title |
Structured output declared, but exposes no named fields.
No examples provided.
todo_get_folders To Do Get Folders ~38
Lists Microsoft To Do task lists. Requires Microsoft account in Reminders sync (System Settings → Internet Accounts → Microsoft Exchange → enable Reminders).
Input schema present but exposes no named parameters.
| Name | Type | Req | Description |
|---|---|---|---|
| count | integer | – | – |
| lists | array | – | – |
| note | string | – | – |
No examples provided.
todo_list_tasks To Do List Tasks ~82
Lists tasks from a Microsoft To Do list (or any Reminders list). Syncs via macOS Reminders.
| Name | Type | Req | Description |
|---|---|---|---|
| include_completed | boolean | – | Include completed tasks (default false) |
| limit | integer | – | Max tasks to return (default 50) |
| list | string | – | List name (from todo_get_folders). Leave empty to show all. |
| Name | Type | Req | Description |
|---|---|---|---|
| count | integer | – | – |
| tasks | array | – | – |
No examples provided.
todoist_complete_task Todoist Complete Task ~44
Mark a Todoist task complete (closes it). Pass the task_id from todoist_list_tasks.
| Name | Type | Req | Description |
|---|---|---|---|
| task_id | string | yes | The task id to complete |
| Name | Type | Req | Description |
|---|---|---|---|
| message | string | yes | – |
| ok | boolean | yes | – |
No examples provided.
todoist_create_task Todoist Create Task ~136
Create a Todoist task. Optionally set a project, a natural-language due date (due_string, e.g. 'tomorrow 5pm', 'every monday'), and priority (1=normal … 4=urgent).
| Name | Type | Req | Description |
|---|---|---|---|
| content | string | yes | The task text |
| due_string | string | – | Natural-language due date, e.g. 'tomorrow 5pm', 'next monday' |
| priority | integer | – | 1 (normal) to 4 (urgent). Todoist UI p1 = 4. |
| project_id | string | – | Project to add it to (default: Inbox) |
| Name | Type | Req | Description |
|---|---|---|---|
| content | string | – | – |
| due | string | – | – |
| id | string | – | – |
| priority | integer | – | – |
| project_id | string | – | – |
| url | string | – | – |
No examples provided.
todoist_list_projects Todoist List Projects ~36
List your Todoist projects (id + name). Use a project's id to scope todoist_list_tasks or todoist_create_task.
Input schema present but exposes no named parameters.
| Name | Type | Req | Description |
|---|---|---|---|
| count | integer | yes | – |
| projects | array | yes | – |
No examples provided.
todoist_list_tasks Todoist List Tasks ~113
List active (incomplete) Todoist tasks. Optionally scope to a project_id, or pass a Todoist filter (e.g. 'today', 'overdue', '#Work & p1').
| Name | Type | Req | Description |
|---|---|---|---|
| filter | string | – | A Todoist filter query, e.g. 'today', 'overdue', 'p1' |
| limit | integer | – | Max results (default 50, max 200) |
| project_id | string | – | Only tasks in this project (from todoist_list_projects) |
| Name | Type | Req | Description |
|---|---|---|---|
| count | integer | yes | – |
| tasks | array | yes | – |
No examples provided.
ui_click Ui Click ~216
Clicks an element (by element_ref, at its center) or a screen coordinate (by coords). button left|right, count 2 = double-click. Returns {clicked, at:{x,y}} — `clicked` means the click event was POSTED at those coordinates, NOT that the app acted on it: CGEvent carries no delivery confirmation, so a busy, modal or input-ignoring app reports exactly the same success. Confirm the effect with ui_wait_for_element or ui_read_tree rather than trusting `clicked`. element_disabled is returned ONLY when the app actually publishes AXEnabled=false; a control that does not publish AXEnabled at all is treated as unknown and clicked. Requires Accessibility permission.
| Name | Type | Req | Description |
|---|---|---|---|
| button | string | – | Default left. |
| by | string | – | Default element if element_ref given, else coords. |
| coords | object | – | {x,y} in global screen points. |
| count | integer | – | 1 (default) or 2 for double-click. |
| element_ref | string | – | – |
No output schema declared.
No examples provided.
ui_find_element Ui Find Element ~219
GUI automation — control a native app's interface. Finds an element (button, field, menu…) in an app's accessibility tree by role and/or label. Scope with app_bundle_id or window_id. Returns an opaque element_ref (usable by ui_click / ui_get_element this session) plus role, label, bounds, focused, and `enabled` only when the app publishes AXEnabled (otherwise `enabled_unknown: true`, which does NOT mean disabled). found=false when the app is reachable but no element matches; app_not_found is an explicit error. Requires Accessibility permission.
| Name | Type | Req | Description |
|---|---|---|---|
| app_bundle_id | string | – | Scope the search to this app. |
| index | integer | – | Which match to return if several (default 0). |
| label | string | – | AX title/description to match. |
| match | string | – | Default contains. |
| role | string | – | AX role, e.g. AXButton, AXMenuItem, AXTextField. |
| window_id | string | – | Alternatively scope by a window_id from list_windows. |
No output schema declared.
No examples provided.
ui_get_element Ui Get Element ~119
Re-resolves a previously returned element_ref (its bounds/state may have changed). Returns role, label, bounds, focused, value, and `enabled` ONLY when the app publishes AXEnabled — that attribute is optional, so many perfectly usable controls omit it (TextEdit's text area does). When it is missing you get `enabled_unknown: true` instead; that is 'unknown', NOT disabled, and ui_click will click it. stale_element if the handle is unknown or the element no longer exists.
| Name | Type | Req | Description |
|---|---|---|---|
| element_ref | string | yes | – |
No output schema declared.
No examples provided.
ui_keystroke Ui Keystroke ~180
Sends a key combination, e.g. "cmd+shift+5", "return", "cmd+,", "escape". Modifiers: cmd, shift, alt/option, ctrl, fn. The last token is the key. Returns {sent, delivery:"posted_not_confirmed"} — `sent` means the key events were POSTED, NOT that the app acted on them: CGEvent carries no delivery confirmation, and a keystroke's effect is arbitrary so nothing can be read back to prove it. Confirm the effect with ui_get_element / ui_read_tree rather than trusting `sent`. Modifiers are released after the combo, so a following ui_type is not swallowed. unknown_key if the key isn't recognized. Requires Accessibility permission.
| Name | Type | Req | Description |
|---|---|---|---|
| keys | string | yes | e.g. cmd+shift+5, return, cmd+, |
No output schema declared.
No examples provided.
ui_menu_bar_click Ui Menu Bar Click ~121
Clicks a status-bar (menu bar extra / NSStatusItem) item and optionally follows a nested menu path. Best-effort via the app's AX extras menu bar; apps that render fully custom (non-AX) menus may not be reachable (fall back to ui_click at known coords). Requires Accessibility permission.
| Name | Type | Req | Description |
|---|---|---|---|
| app_bundle_id | string | – | Owner of the status item. |
| label | string | – | Status item / menu item title. |
| path | array | – | Nested menu path, e.g. ["App","Settings…"]. |
No output schema declared.
No examples provided.
ui_read_tree Ui Read Tree ~286
Returns a COMPACT accessibility tree of a running native app's labeled + interactive elements (buttons, links, text fields, checkboxes, menus…) — the native equivalent of web_read's a11y mode. Use it to DISCOVER what to act on in an unfamiliar app when you don't already know an element's role/label (ui_find_element needs one up front). Each interactive node carries a `ref` you can pass straight to ui_click. Pass app_bundle_id of a running app (e.g. com.apple.finder — see list_windows); the tree is pruned to signal-bearing nodes and bounded by max_depth (default 12) and a node budget, so very large windows return partial. The app's macOS menu bar is skipped by default (it's hundreds of menu-item nodes) — pass include_menu_bar=true if you specifically need to act on menu-bar items.
| Name | Type | Req | Description |
|---|---|---|---|
| app_bundle_id | string | – | Bundle id of a RUNNING app (e.g. com.apple.finder) |
| include_menu_bar | boolean | – | Include the app's macOS menu bar (hundreds of menu-item nodes). Default false. |
| max_depth | integer | – | Max tree depth to descend (default 12, max 20) |
| window_id | string | – | Alternative to app_bundle_id: a window id from list_windows (targets that window's app) |
Structured output declared, but exposes no named fields.
No examples provided.
ui_type Ui Type ~154
Types text into the focused control (or focuses element_ref first, then types). Sends real key events so validation/handlers fire. The result is VERIFIED BY READING the control back, not by the write succeeding: {typed, verified:true} means its value actually changed; input_not_applied is an explicit error meaning the events were posted and the value did NOT change (nothing was typed — usually the window is not frontmost); verified:false + verification:'unavailable' means the target publishes no readable value, so delivery could not be confirmed and you should read it back yourself. Requires Accessibility permission.
| Name | Type | Req | Description |
|---|---|---|---|
| element_ref | string | – | Optional; focus this element first. |
| text | string | yes | The text to type. |
No output schema declared.
No examples provided.
ui_wait_for_element Ui Wait For Element ~188
Deterministic synchronization — replaces all sleeps. Polls for an element until it reaches state (present|enabled|focused|absent) or times out. A timeout is an EXPLICIT error, never a false success. Returns {satisfied, waited_ms, element_ref?, bounds?, enabled_unknown?}. state:'enabled' is satisfied unless the app publishes AXEnabled=false; if the app publishes no AXEnabled at all the result carries enabled_unknown:true — the wait did not block, but nothing was actually verified about enabled-ness.
| Name | Type | Req | Description |
|---|---|---|---|
| app_bundle_id | string | – | – |
| label | string | – | – |
| match | string | – | – |
| poll_ms | integer | – | Default 150. |
| role | string | – | – |
| state | string | – | Default present. |
| timeout_ms | integer | – | Default 5000. |
| window_id | string | – | – |
No output schema declared.
No examples provided.
update_calendar_event Update Calendar Event ~213
Updates an existing event in the Mac's Calendar app (Calendar.app) by ID. Pass only the fields you want to change — unspecified fields are left as-is. Get the event_id from list_calendar_events. For Microsoft 365 use the m365 calendar tools instead.
| Name | Type | Req | Description |
|---|---|---|---|
| confirm | boolean | – | Must be true to apply changes |
| end_date | string | – | New end datetime ISO 8601 (optional). Same timezone rules as start_date. |
| event_id | string | yes | Event identifier from list_calendar_events |
| location | string | – | New location — pass empty string to clear (optional) |
| notes | string | – | New notes — pass empty string to clear (optional) |
| span | string | – | For recurring events: 'this' (default) or 'future' |
| start_date | string | – | New start datetime ISO 8601 (optional). No timezone = Mac's local time; append Z/offset to pin the zone. |
| title | string | – | New title (optional) |
| Name | Type | Req | Description |
|---|---|---|---|
| all_day | boolean | – | – |
| attendees | array | – | – |
| attendees_total | integer | – | – |
| calendar | string | – | – |
| calendar_id | string | – | – |
| end | string | – | – |
| id | string | – | – |
| location | string | – | – |
| notes | string | – | – |
| start | string | – | – |
| title | string | – | – |
| updated | boolean | – | – |
No examples provided.
update_note Update Note ~87
Updates an existing note in Apple Notes. Change the title and/or body (the body accepts Markdown, converted to Apple Notes' native formatting). Find note_id with list_notes or search_notes. Requires confirm=true.
| Name | Type | Req | Description |
|---|---|---|---|
| body | string | – | – |
| confirm | boolean | – | – |
| note_id | string | – | – |
| note_name | string | – | – |
| title | string | – | – |
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | – | – |
| name | string | – | – |
| updated | boolean | – | – |
No examples provided.
update_reminder Update Reminder ~271
Updates an existing reminder in Reminders.app. Change the title, due date, notes, priority, or move it to another list (list_name). Get reminder_id from list_reminders. Requires confirm=true. IMPORTANT: moving to a list in a DIFFERENT account (e.g. iCloud ↔ Exchange) recreates the reminder, so its id changes — the response then has id_changed: true, the new id in reminder_id and the dead one in previous_reminder_id. Always take reminder_id from the response before any follow-up call.
| Name | Type | Req | Description |
|---|---|---|---|
| confirm | boolean | – | Must be true to apply changes |
| due_date | string | – | New ISO 8601 due date. Pass empty string to clear (optional) |
| list_name | string | – | Move the reminder to this list (a name from get_reminder_folders) (optional). Moving to a list in ANOTHER account recreates the reminder and CHANGES its id — read the new one from reminder_id in the… |
| notes | string | – | New notes text (optional) |
| priority | string | – | Priority: none | low | medium | high (optional) |
| reminder_id | string | yes | Reminder identifier from list_reminders |
| title | string | – | New title (optional) |
| Name | Type | Req | Description |
|---|---|---|---|
| id_changed | boolean | – | true when the update recreated the reminder (a move across accounts), which invalidates the id you passed in. |
| list | string | – | Destination list, when the update moved the reminder. |
| note | string | – | – |
| previous_reminder_id | string | – | Only when id_changed: the id you passed in, which no longer exists. |
| reminder_id | string | – | The reminder's id AFTER the update — use this one from now on. |
| title | string | – | – |
| updated | boolean | – | – |
No examples provided.
video_blur_region Video Blur Region ~152
Pixelates/blurs one or more rectangles over the video — the tool for redacting PII (an email pane, a name) before publishing a screen recording. Rects are in source pixels, top-left origin: [{x,y,w,h, start_ms?, end_ms?}] — omit the times to cover the whole clip. Great with a marker timeline's `bounds`. Returns the output path.
| Name | Type | Req | Description |
|---|---|---|---|
| input | string | yes | Path to the source video file. |
| output | string | – | Default: <input>_blurred.mov. Missing parent folders are created. |
| regions | array | yes | [{x,y,w,h, start_ms?, end_ms?}] in source pixels (top-left). |
No output schema declared.
No examples provided.
video_concat Video Concat ~87
Stitches multiple videos end-to-end, in order, into one NEW file (e.g. assemble separate acts). All inputs should share a resolution for a clean result. Returns the output path + duration.
| Name | Type | Req | Description |
|---|---|---|---|
| inputs | array | yes | Ordered list of video file paths. |
| output | string | – | Output path (default: <first-input>_joined.mov). Missing parent folders are created. |
No output schema declared.
No examples provided.
video_export_gif Video Export Gif ~169
Exports a video (or a [start_ms,end_ms] slice of it) to an optimized looping GIF — for README/social. fps (default 12) and width (default 640, height auto) control size. Returns the output path, frame count, and size.
| Name | Type | Req | Description |
|---|---|---|---|
| end_ms | integer | – | Slice end (default: end of video). |
| fps | integer | – | Frames per second in the GIF (default 12). |
| input | string | yes | Path to the source video. |
| output | string | – | Output path (default: <input>.gif). Missing parent folders are created. |
| start_ms | integer | – | Slice start (default 0). |
| width | integer | – | Output width in px, height scales to keep aspect (default 640). |
No output schema declared.
No examples provided.
video_reframe Video Reframe ~196
Crops a video to a target aspect ratio (e.g. "9:16" vertical, "1:1" square, "4:5") around a focus point — for social clips. Takes the LARGEST crop of that aspect that fits, centered on `focus` (x,y in source pixels, top-left origin; default = center) and clamped to the frame. Audio passes through. Returns the output path + new dimensions.
| Name | Type | Req | Description |
|---|---|---|---|
| aspect | string | yes | Target aspect "W:H", e.g. 9:16, 1:1, 4:5, 16:9. |
| focus | object | – | {x,y} center of interest in source pixels (top-left). Default: frame center. |
| input | string | yes | Path to the source video file. |
| output | string | – | Default: <input>_<aspect>.mov. Missing parent folders are created. |
No output schema declared.
No examples provided.
video_trim Video Trim ~136
Trims a video to one or more time ranges (milliseconds), concatenated in order into a NEW file — e.g. keep [{start_ms:0,end_ms:6000},{start_ms:126000,end_ms:223000}] to drop a dead segment. Audio is carried along. Returns the output path + duration. Never overwrites the input in place.
| Name | Type | Req | Description |
|---|---|---|---|
| input | string | yes | Path to the source video. |
| output | string | – | Output path (default: <input>_trimmed.mov). Missing parent folders are created. |
| ranges | array | yes | Ordered [{start_ms, end_ms}] to keep. |
No output schema declared.
No examples provided.
web_click Web Click ~222
Clicks an element on the current page. `target` is a CSS selector or visible text (resolved fresh each call). Clicks that SUBMIT a form preview first — call again with confirm:true to execute; plain links/buttons click directly. Returns {url, title, navigated, url_as_of}: `url_as_of` is "settled" when the page has finished changing, and "before_click" together with navigation_pending:true when the click started a navigation that had not finished — in that case url/title are the page BEFORE the click, NOT the destination, so do not read them as 'the click did nothing' and retry (the page is already changing); read the destination with web_read or wait for it with web_wait_for. `navigated:false` means the click changed no page.
| Name | Type | Req | Description |
|---|---|---|---|
| confirm | boolean | – | Required (true) to perform a click that submits a form. |
| session | string | – | Session name (default 'default'). |
| target | string | yes | CSS selector or visible text of the element to click. |
No output schema declared.
No examples provided.
web_extract Web Extract ~86
Scrapes structured data from the current page. Pass `selectors` = an object mapping field names to CSS selectors (e.g. {"title":"h1","price":".price"}); returns each field's first-match text/href, null when absent.
| Name | Type | Req | Description |
|---|---|---|---|
| selectors | object | yes | Field name → CSS selector map. |
| session | string | – | Session name (default 'default'). |
| Name | Type | Req | Description |
|---|---|---|---|
| data | object | – | One key per requested field; first-match text/href, null when absent. |
| title | string | – | – |
| url | string | – | – |
No examples provided.
web_find Web Find ~104
Finds elements on the current page of a web session so you can decide what to click or type into. `query` is a CSS selector OR visible text to match. Returns up to 30 matches with tag/text/name/type/href — never a silent empty.
| Name | Type | Req | Description |
|---|---|---|---|
| query | string | yes | A CSS selector (e.g. 'input[name=q]') or visible text (e.g. 'Sign in'). |
| session | string | – | Session name (default 'default'). |
| Name | Type | Req | Description |
|---|---|---|---|
| count | integer | – | Number of matching elements (max 30 returned). |
| matches | array | – | Matched elements with tag/text/name/type/href. |
| query | string | – | – |
No examples provided.
web_login Web Login ~144
Opens a real browser window on the Mac for the user to sign into a website themselves (you never handle their password). After they log in, the session is saved on this Mac and reused by web_navigate/web_read/web_screenshot — they won't need to log in again. Use a stable `session` name per site (e.g. 'linkedin'). NOTE: automating sites like Instagram/LinkedIn may violate their terms — the user accepts that risk.
| Name | Type | Req | Description |
|---|---|---|---|
| session | string | – | A stable name for this login profile, e.g. 'linkedin'. |
| url | string | yes | The site's login URL to open, e.g. https://www.linkedin.com/login |
No output schema declared.
No examples provided.
web_navigate Web Navigate ~128
Navigates a web session to a URL (using its saved login if any) and returns the resulting URL + page title. Opens the session if it doesn't exist. CHECK `loaded` before reading: when it is false the page did not load and `message` says why — reading the session then describes a blank document, not the site. Read the page with web_read.
| Name | Type | Req | Description |
|---|---|---|---|
| session | string | – | Session name (default 'default'). |
| timeout_seconds | integer | – | Max seconds to wait for load (default 25). |
| url | string | yes | URL to open (https). |
| Name | Type | Req | Description |
|---|---|---|---|
| error | string | – | Present only on failure: nav_failed (the browser rejected the load), nav_timeout, or nav_blank (it finished on a blank document). |
| loaded | boolean | – | True only when the browser ended on a real web page. False means nothing was loaded — do NOT read the session and treat the result as page content. |
| message | string | – | Present only on failure: why the page didn't load, and what to do about it. |
| ok | boolean | – | True only when the requested page actually loaded. |
| settle_rejected_by | string | – | Present only with nav_timeout: which check ruled out 'the page arrived and WebKit just did not say so' - navigation_started (another navigation began and hung, so the visible document is the old one)… |
| title | string | – | The resulting page title. |
| url | string | – | The URL the browser settled on (redirects followed). If it isn't the page you asked for, the navigation didn't deliver it. |
No examples provided.
web_read Web Read ~116
Reads the current page of a web session so you can reason over it. mode='text' (visible text, default), 'a11y' (compact accessible tree of links/buttons/fields — best for deciding what to click), or 'html' (raw DOM). Returns an explicit no_session error if the session isn't open, and no_page if it hasn't loaded a page — never a silent empty.
| Name | Type | Req | Description |
|---|---|---|---|
| mode | string | – | What to return (default text). |
| session | string | – | Session name (default 'default'). |
| Name | Type | Req | Description |
|---|---|---|---|
| content | string | – | The page content in the requested mode. |
| mode | string | – | The mode that was read (text/a11y/html). |
| title | string | – | – |
| url | string | – | – |
No examples provided.
web_screenshot Web Screenshot ~69
Captures a PNG screenshot of the current page of a web session (returned inline so web AIs can see it). Useful to ground what the page looks like before acting.
| Name | Type | Req | Description |
|---|---|---|---|
| session | string | – | Session name (a named login profile, e.g. 'linkedin'). Defaults to 'default'. |
| Name | Type | Req | Description |
|---|---|---|---|
| bytes | integer | – | PNG size in bytes (the image itself is an inline content block). |
| url | string | – | URL of the page that was captured. |
No examples provided.
web_session_close Web Session Close ~97
Closes a web-automation session's window and frees it. The saved login STAYS on disk (cookies included), so web_login/web_navigate can reopen it later without signing in again — it also means closing does NOT clean up: to erase a profile you no longer want stored, use web_session_delete.
| Name | Type | Req | Description |
|---|---|---|---|
| session | string | – | Session name (a named login profile, e.g. 'linkedin'). Defaults to 'default'. |
No output schema declared.
No examples provided.
web_session_delete Web Session Delete ~168
Deletes a SAVED web-automation login profile: closes its window if open, erases its cookies and site data from this Mac, and removes it from web_session_list. Use it to clean up a profile that is no longer needed — web_session_close only closes the window and leaves the login (and its cookies) on disk. IRREVERSIBLE: the next web_login for that name starts from a signed-out browser. Requires confirm=true; without it you get a preview. Verify with web_session_list, which must no longer list the name.
| Name | Type | Req | Description |
|---|---|---|---|
| confirm | boolean | – | Must be true to actually delete. Without it, returns a preview and deletes nothing. |
| session | string | – | Name of the profile to delete, as web_session_list reports it. Defaults to 'default'. |
| Name | Type | Req | Description |
|---|---|---|---|
| closed | boolean | – | Whether a live window had to be closed first |
| data_removed | boolean | – | Whether the cookies and site data were erased |
| deleted | string | – | The profile name that was deleted |
| name_forgotten | boolean | – | Whether the name was removed from web_session_list |
| ok | boolean | – | True only when BOTH halves are done: data erased and name removed from the list |
No examples provided.
web_session_list Web Session List ~98
Lists your web-automation login profiles: every SAVED login (persisted on disk, so web_login/web_navigate can reopen it without signing in again) plus which are currently OPEN. Each entry has `saved` (a persisted profile exists) and `open` (its window is live now, with url + title). Use it to check whether a login a recipe needs already exists before running it, instead of opening it and failing.
Input schema present but exposes no named parameters.
| Name | Type | Req | Description |
|---|---|---|---|
| sessions | array | – | – |
No examples provided.
web_show Web Show ~131
Brings a web session's browser window to the FRONT so the USER can take over directly — solve a CAPTCHA, complete 2FA, or make a choice the AI shouldn't. Local MCP never solves CAPTCHAs itself; this hands control to the user. Pair with web_screenshot first to show them what's on the page. After they finish, tell the agent to continue — the session keeps its state.
| Name | Type | Req | Description |
|---|---|---|---|
| reason | string | – | Short reason shown to the user, e.g. 'a CAPTCHA appeared' or 'confirm which account'. |
| session | string | – | Session name (default 'default'). |
No output schema declared.
No examples provided.
web_type Web Type ~178
Types text into a form field (input/textarea) on the current page. `target` is a CSS selector or the field's visible label/placeholder. Does NOT submit — use web_click on the submit button afterwards (that step is gated). SPECIAL CASE — file inputs: if `target` resolves to an <input type="file">, `text` is instead treated as a LOCAL FILE PATH on this Mac and the file is attached (JS can't set a file input's value directly; this answers the native file panel programmatically without ever showing it).
| Name | Type | Req | Description |
|---|---|---|---|
| session | string | – | Session name (default 'default'). |
| target | string | yes | CSS selector or visible label/placeholder of the field. |
| text | string | yes | The text to type. For an input[type=file], this is instead the LOCAL FILE PATH to upload. |
No output schema declared.
No examples provided.
web_wait_for Web Wait For ~204
Waits (polls, not a fixed sleep) until an element appears on the page, or times out. Use for SPA pages that hydrate after load. Prefer `selector` (a CSS selector, e.g. "input[name=password]"). `condition` also accepts the form "document.querySelector('...')"; any OTHER JavaScript condition runs arbitrary code on the page (same power as web_eval) and is disabled when LMCP is in read-only mode. Returns met:true/false.
| Name | Type | Req | Description |
|---|---|---|---|
| condition | string | – | Alternative to selector: "document.querySelector('...')" is accepted as-is; any other JS expression runs arbitrary code on the page (same power as web_eval). |
| selector | string | – | CSS selector to wait for (preferred; treated as data, never executed). e.g. .feed |
| session | string | – | Session name (default 'default'). |
| timeout_seconds | integer | – | Max seconds to wait (default 15). |
| Name | Type | Req | Description |
|---|---|---|---|
| message | string | – | Present when the condition was not met. |
| met | boolean | – | True if the condition became truthy before the timeout. |
| ok | boolean | – | – |
No examples provided.
window_focus Window Focus ~49
Brings a window (by window_id from list_windows) to the front and activates its app. window_not_found if it can't be resolved. Requires Accessibility permission.
| Name | Type | Req | Description |
|---|---|---|---|
| window_id | string | yes | – |
No output schema declared.
No examples provided.
window_set_frame Window Set Frame ~75
Pins a window (by window_id) to fixed bounds {x,y,w,h} in global points, so every take is framed identically across runs. Returns the actual post-constraint bounds. Requires Accessibility permission.
| Name | Type | Req | Description |
|---|---|---|---|
| bounds | object | yes | {x,y,w,h} global points. |
| window_id | string | yes | – |
No output schema declared.
No examples provided.
word_append Word Append ~138
Appends text to the end of an existing Word (.docx) document at `path`, preserving the document's existing content and formatting. Requires confirm=true — called without it, returns a preview instead of modifying the file. Same file-access rules as word_create (Desktop/Documents/Downloads may need a Files-and-Folders grant). Returns {appended, chars_appended, path}. To create a new document use word_create; to read one use word_read.
| Name | Type | Req | Description |
|---|---|---|---|
| confirm | boolean | – | Must be true to modify |
| content | string | yes | Text to append |
| path | string | yes | Path to the existing .docx file |
Structured output declared, but exposes no named fields.
No examples provided.
What is the com.local-mcp/local-mcp server?
com.local-mcp/local-mcp is listed in the public MCP registry as com.local-mcp/local-mcp. Let ChatGPT, Claude & Cursor use your Mac: email, calendar, iMessage, Teams, files. Local, free. This page covers its hosted endpoint (https://local-mcp.com/mcp).
Is the com.local-mcp/local-mcp server safe to use?
com.local-mcp/local-mcp scores 39 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the com.local-mcp/local-mcp server expose?
com.local-mcp/local-mcp exposes 204 tools: setup_install, complete_omnifocus_task, complete_reminder, configure_clients, connect_m365_account, and 199 more. Their descriptions and schemas cost roughly 25,946 tokens of context every time the server is loaded.
Does the com.local-mcp/local-mcp server require authentication?
Yes. com.local-mcp/local-mcp asked us for credentials when we connected, so you will need to authorise it in your MCP client before it can do anything.
Is the com.local-mcp/local-mcp server still maintained?
com.local-mcp/local-mcp is still listed as active in the MCP registry. We last reached this channel on 20 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.