# Desktop Commander (npm · @wonderwhy-er/desktop-commander)

MCP server for terminal commands, file operations, and process management

- Trust score: 52/100 (low)
- Change this week: +47
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-08-08

## Components

- npm · `@wonderwhy-er/desktop-commander`: 52/100 (this document), [markdown](https://verifymcp.io/servers/wonderwhy-er-desktop-commander/wonderwhy-er-desktop-commander.md), [page](https://verifymcp.io/servers/wonderwhy-er-desktop-commander/wonderwhy-er-desktop-commander)

## Channel facts

- Registry: `npm`
- Package: `@wonderwhy-er/desktop-commander`
- Version: `0.2.47`
- Transport: `stdio`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-08-08.

- **Supply Chain Security**: 66/100
  - No malware found by supply-chain analysis.
  - CVE check failed: a known high-severity CVE affects sharp 0.34.5, a direct dependency. A fixed version is available.
  - Install-script check failed: the install command fetches or executes arbitrary code (pipe_to_shell,inline_eval). An install hook runs on every machine, in CI, and on transitive installs, whether or not you ever run the server.
  - Dependency health was assessed across the 400 of 584 dependencies we could resolve, so this covers what we could see, not the whole tree.
- **Provenance & Transparency**: 48/100
  - Source repository is publicly reachable at the declared URL.
  - Provenance check failed: no build-provenance attestation is published.
  - Clear OSI-approved license (MIT).
  - Actively maintained (last published 3 days ago).
  - Publishes a security disclosure policy (SECURITY.md).
- **Schema Quality & AI Usability**: 53/100
  - 100% of prompts and resources have a non-trivial description (not blank, and not just the item's name).
  - AI-judged instruction clarity (poor).
  - Context-footprint check failed: tool/resource definitions use about 9106 tokens (~325/item across 28 items; 26 tools + 2 resources), over budget; trim descriptions and params.
  - Usage-examples check failed: none of the tools include examples.
- **Stability & Change Management**: 0/100
  - Stability not yet verified: not enough scan history yet (needs a 30-day window).
- **Tool Coverage**: 67/100
  - 100% of tools have a non-trivial description (not blank, and not just the tool's name).
  - 0% of tool parameters carry a description.
- **Capabilities**: 100/100
  - Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.
  - Supports UI / widget rendering.

**Unverified: 1 category.** A category scored 0 because we could not verify it: a data source with nothing on this package, evidence we could not reach, or a check we could not run. We only credit what we can confirm.

## Install

### Claude

```bash
claude mcp add wonderwhy-er-desktop-commander -- npx -y @wonderwhy-er/desktop-commander
```

### Codex

```bash
codex mcp add wonderwhy-er-desktop-commander -- npx -y @wonderwhy-er/desktop-commander
```

### opencode

```json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "wonderwhy-er-desktop-commander": {
      "type": "local",
      "command": [
        "npx",
        "-y",
        "@wonderwhy-er/desktop-commander"
      ],
      "enabled": true
    }
  }
}
```

### OpenClaw

```bash
openclaw mcp add wonderwhy-er-desktop-commander --command npx --arg -y --arg @wonderwhy-er/desktop-commander
```

### Hermes

```yaml
mcp_servers:
  wonderwhy-er-desktop-commander:
    command: "npx"
    args: ["-y", "@wonderwhy-er/desktop-commander"]
```

### Other

```json
{
  "mcpServers": {
    "wonderwhy-er-desktop-commander": {
      "command": "npx",
      "args": [
        "-y",
        "@wonderwhy-er/desktop-commander"
      ]
    }
  }
}
```

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-08-08 (score 52, +1)

- [functional improvement] Security disclosure: fail → pass

### 2026-08-07 (score 51, +1)

No change was recorded against any check on this day. Supply Chain Security went from 62 to 66.

### 2026-08-06 (score 50, +23)

- [security] Stability: Stability not yet verified: not enough scan history yet (needs a 30-day window).
- [functional improvement] Schema quality: unverified → 100
- [functional improvement] MCP protocol: unverified → pass
- [functional improvement] Tool coverage: unverified → 100
- [functional] First check of Schema quality: fail
- [functional] First check of Tool coverage: 0
- [functional] First check of Capabilities: pass
- [functional] First check of Schema quality: fail
- [functional] First check of Schema quality: poor

### 2026-08-05 (score 27, +3)

- [security regression] Known CVEs: unverified → fail
- [functional improvement] Dependency health: unverified → partial

### 2026-08-04 (score 24, −4)

- [security regression] Known CVEs: fail → unverified
- [functional regression] Dependency health: partial → unverified
- [functional] Package version: 0.2.44 → 0.2.47

### 2026-08-03 (score 28, +1)

No change was recorded against any check on this day. Supply Chain Security went from 61 to 63.

### 2026-08-02 (score 27, +22)

- [security regression] CVE-2026-41907 affects this package: high
- [security regression] GHSA-f88m-g3jw-g9cj affects this package: high
- [security regression] Install scripts: unverified → fail
- [security regression] Provenance: unverified → fail
- [security regression] Known CVEs: unverified → fail
- [security improvement] Malware scan: unverified → pass
- [security] The scripts that run when this package is installed changed: postinstall
- [functional improvement] License: unverified → pass
- [functional improvement] Dependency health: unverified → partial
- [functional improvement] Maintenance: unverified → pass
- [functional] Licence: MIT

### 2026-08-01 (score 5, 0)

- [security] Stability: Stability not yet verified: our sandbox run of this package did not complete, so we have no schema to compare.
- [functional] Tool coverage: Tool coverage not yet verified: our sandbox run of this package did not complete, so we have no tool definitions to assess.
- [functional] Capabilities: Protocol version not yet verified: our sandbox run of this package did not complete, so we never saw its MCP handshake.
- [functional] Schema quality: Schema quality not yet verified: our sandbox run of this package did not complete, so we have no schema to assess.

## MCP tools (26)

### `get_config` (~181 tokens)

Get the complete server configuration as JSON. Config includes fields for:
                        - blockedCommands (array of blocked shell commands)
                        - defaultShell (shell to use for commands)
                        - allowedDirectories (paths the server can access)
                        - fileReadLineLimit (max lines for read_file, default 1000)
                        - fileWriteLineLimit (max lines per write_file call, default 50)
                        - telemetryEnabled (boolean for telemetry opt-in/out)
                        - currentClient (information about the currently connected MCP client)
                        - clientHistory (history of all clients that have connected)
                        - version (version of the DesktopCommander)
                        - systemInfo (operating system and environment details)
                        This command can be referenced as "DC: ..." or "use Desktop Commander to ..." in your instructions.

Input parameters:

- `origin` (string)

### `set_config_value` (~182 tokens)

Set a specific configuration value by key.
                        
                        WARNING: Should be used in a separate chat from file operations and 
                        command execution to prevent security issues.
                        
                        Config keys include:
                        - blockedCommands (array)
                        - defaultShell (string)
                        - allowedDirectories (array of paths)
                        - fileReadLineLimit (number, max lines for read_file)
                        - fileWriteLineLimit (number, max lines per write_file call)
                        - telemetryEnabled (boolean)
                        
                        IMPORTANT: Setting allowedDirectories to an empty array ([]) allows full access 
                        to the entire file system, regardless of the operating system.
                        
                        This command can be referenced as "DC: ..." or "use Desktop Commander to ..." in your instructions.

Input parameters:

- `key` (string, required)
- `origin` (string)
- `value` (required)

### `read_file` (~843 tokens)

Read contents from files and URLs.
                        Read PDF files and extract content as markdown and images.
                        
                        Prefer this over 'execute_command' with cat/type for viewing files.
                        
                        Supports partial file reading with:
                        - 'offset' (start line, default: 0)
                          * Positive: Start from line N (0-based indexing)
                          * Negative: Read last N lines from end (tail behavior)
                        - 'length' (max lines to read, default: configurable via 'fileReadLineLimit' setting, initially 1000)
                          * Used with positive offsets for range reading
                          * Ignored when offset is negative (reads all requested tail lines)
                        
                        Examples:
                        - offset: 0, length: 10     → First 10 lines
                        - offset: 100, length: 5    → Lines 100-104
                        - offset: -20               → Last 20 lines  
                        - offset: -5, length: 10    → Last 5 lines (length ignored)
                        
                        Performance optimizations:
                        - Large files with negative offsets use reverse reading for efficiency
                        - Large files with deep positive offsets use byte estimation
                        - Small files use fast readline streaming
                        
                        When reading from the file system, only works within allowed directories.
                        Can fetch content from URLs when isUrl parameter is set to true
                        (URLs are always read in full regardless of offset/length).
                        
                        FORMAT HANDLING (by extension):
                        - Text: Uses offset/length for line-based pagination…

Input parameters:

- `isUrl` (boolean)
- `length` (number)
- `offset` (number)
- `options` (object)
- `origin` (string)
- `path` (string, required)
- `range` (string)
- `sheet` (string)

### `read_multiple_files` (~170 tokens)

Read the contents of multiple files simultaneously.
                        
                        Each file's content is returned with its path as a reference.
                        Handles text files normally and renders images as viewable content.
                        Recognized image types: PNG, JPEG, GIF, WebP.
                        
                        Failed reads for individual files won't stop the entire operation.
                        Only works within allowed directories.
                        
                        IMPORTANT: Always use absolute paths for reliability. Paths are automatically normalized regardless of slash direction. Relative paths may fail as they depend on the current working directory. Tilde paths (~/...) might not work in all contexts. Unless the user explicitly asks for relative paths, use absolute paths.
                        This command can be referenced as "DC: ..." or "use Desktop Commander to ..." in your instructions.

Input parameters:

- `paths` (array, required)

### `write_file` (~552 tokens)

Write or append to file contents.

                        IMPORTANT: DO NOT use this tool to create PDF files. Use 'write_pdf' for all PDF creation tasks.
                        DO NOT use this tool to edit DOCX files. Use 'edit_block' with old_string/new_string instead.
                        To CREATE a new DOCX, use write_file with .docx extension — text content with markdown headings (#, ##, ###) is converted to styled DOCX paragraphs.

                        CHUNKING IS STANDARD PRACTICE: Always write files in chunks of 25-30 lines maximum.
                        This is the normal, recommended way to write files - not an emergency measure.

                        STANDARD PROCESS FOR ANY FILE:
                        1. FIRST → write_file(filePath, firstChunk, {mode: 'rewrite'})  [≤30 lines]
                        2. THEN → write_file(filePath, secondChunk, {mode: 'append'})   [≤30 lines]
                        3. CONTINUE → write_file(filePath, nextChunk, {mode: 'append'}) [≤30 lines]

                        ALWAYS CHUNK PROACTIVELY - don't wait for performance warnings!

                        WHEN TO CHUNK (always be proactive):
                        1. Any file expected to be longer than 25-30 lines
                        2. When writing multiple files in sequence
                        3. When creating documentation, code files, or configuration files

                        HANDLING CONTINUATION ("Continue" prompts):
                        If user asks to "Continue" after an incomplete operation:
                        1. Read the file to see what was successfully written
                        2. Continue writing ONLY the remaining content using {mode: 'append'}
                        3. Keep chunks to 25-30 lines each

                        FORMAT HANDLING (by extension):
                        - Text files: String content
                        - Excel (.xlsx, .xls, .xlsm): JSON 2D array or {"SheetName"…

Input parameters:

- `content` (string, required)
- `mode` (string)
- `origin` (string)
- `path` (string, required)

### `write_pdf` (~602 tokens)

Create a new PDF file or modify an existing one.

                        THIS IS THE ONLY TOOL FOR CREATING AND MODIFYING PDF FILES.

                        RULES ABOUT FILENAMES:
                        - When creating a new PDF, 'outputPath' MUST be provided and MUST use a new unique filename (e.g., "result_01.pdf", "analysis_2025_01.pdf", etc.).

                        MODES:
                        1. CREATE NEW PDF:
                           - Pass a markdown string as 'content'.
                           write_pdf(path="doc.pdf", content="# Title\n\nBody text...")

                        2. MODIFY EXISTING PDF:
                           - Pass array of operations as 'content'.
                           - NEVER overwrite the original file.
                           - ALWAYS provide a new filename in 'outputPath'.
                           - After modifying, show original file path and new file path to user.

                           write_pdf(path="doc.pdf", content=[
                               { type: "delete", pageIndexes: [0, 2] },
                               { type: "insert", pageIndex: 1, markdown: "# New Page" }
                           ])

                        OPERATIONS:
                        - delete: Remove pages by 0-based index.
                          { type: "delete", pageIndexes: [0, 1, 5] }

                        - insert: Add pages at a specific 0-based index.
                          { type: "insert", pageIndex: 0, markdown: "..." }
                          { type: "insert", pageIndex: 5, sourcePdfPath: "/path/to/source.pdf" }

                        PAGE BREAKS:
                        To force a page break, use this HTML element:
                        <div style="page-break-before: always;"></div>
                        
                        Example:
                        "# Page 1\n\n<div style=\"page-break-before: always;\"></div>\n\n# Page 2"

                        ADVAN…

Input parameters:

- `content` (required)
- `options` (object)
- `outputPath` (string)
- `path` (string, required)

### `create_directory` (~126 tokens)

Create a new directory or ensure a directory exists.
                        
                        Can create multiple nested directories in one operation.
                        Only works within allowed directories.
                        
                        IMPORTANT: Always use absolute paths for reliability. Paths are automatically normalized regardless of slash direction. Relative paths may fail as they depend on the current working directory. Tilde paths (~/...) might not work in all contexts. Unless the user explicitly asks for relative paths, use absolute paths.
                        This command can be referenced as "DC: ..." or "use Desktop Commander to ..." in your instructions.

Input parameters:

- `path` (string, required)

### `list_directory` (~395 tokens)

Get a detailed listing of all files and directories in a specified path.
                        
                        Use this instead of 'execute_command' with ls/dir commands.
                        Results distinguish between files and directories with [FILE] and [DIR] prefixes.
                        
                        Supports recursive listing with the 'depth' parameter (default: 2):
                        - depth=1: Only direct contents of the directory
                        - depth=2: Contents plus one level of subdirectories
                        - depth=3+: Multiple levels deep
                        
                        CONTEXT OVERFLOW PROTECTION:
                        - Top-level directory shows ALL items
                        - Nested directories are limited to 100 items maximum per directory
                        - When a nested directory has more than 100 items, you'll see a warning like:
                          [WARNING] node_modules: 500 items hidden (showing first 100 of 600 total)
                        - This prevents overwhelming the context with large directories like node_modules
                        
                        Results show full relative paths from the root directory being listed.
                        Example output with depth=2:
                        [DIR] src
                        [FILE] src/index.ts
                        [DIR] src/tools
                        [FILE] src/tools/filesystem.ts
                        
                        If a directory cannot be accessed, it will show [DENIED] instead.
                        If a path does not exist, it will show [NOT_FOUND] instead.
                        Only works within allowed directories.
                        
                        IMPORTANT: Always use absolute paths for reliability. Paths are automatically normalized regardless of slash direction. Relative paths may fail as they depend on the…

Input parameters:

- `depth` (number)
- `origin` (string)
- `path` (string, required)

### `move_file` (~138 tokens)

Move or rename files and directories.
                        
                        Can move files between directories and rename them in a single operation.
                        Both source and destination must be within allowed directories.
                        
                        IMPORTANT: Always use absolute paths for reliability. Paths are automatically normalized regardless of slash direction. Relative paths may fail as they depend on the current working directory. Tilde paths (~/...) might not work in all contexts. Unless the user explicitly asks for relative paths, use absolute paths.
                        This command can be referenced as "DC: ..." or "use Desktop Commander to ..." in your instructions.

Input parameters:

- `destination` (string, required)
- `source` (string, required)

### `start_search` (~1179 tokens)

Start a streaming search that can return results progressively.
                        
                        SEARCH STRATEGY GUIDE:
                        Choose the right search type based on what the user is looking for:
                        
                        USE searchType="files" WHEN:
                        - User asks for specific files: "find package.json", "locate config files"
                        - Pattern looks like a filename: "*.js", "README.md", "test-*.tsx" 
                        - User wants to find files by name/extension: "all TypeScript files", "Python scripts"
                        - Looking for configuration/setup files: ".env", "dockerfile", "tsconfig.json"
                        
                        USE searchType="content" WHEN:
                        - User asks about code/logic: "authentication logic", "error handling", "API calls"
                        - Looking for functions/variables: "getUserData function", "useState hook"
                        - Searching for text/comments: "TODO items", "FIXME comments", "documentation"
                        - Finding patterns in code: "console.log statements", "import statements"
                        - User describes functionality: "components that handle login", "files with database queries"
                        
                        WHEN UNSURE OR USER REQUEST IS AMBIGUOUS:
                        Run TWO searches in parallel - one for files and one for content:
                        
                        Example approach for ambiguous queries like "find authentication stuff":
                        1. Start file search: searchType="files", pattern="auth"
                        2. Simultaneously start content search: searchType="content", pattern="authentication"  
                        3. Present combined results: "Found 3 auth-related files and 8 files containing authentication code"…

Input parameters:

- `contextLines` (number)
- `earlyTermination` (boolean)
- `filePattern` (string)
- `ignoreCase` (boolean)
- `includeHidden` (boolean)
- `literalSearch` (boolean)
- `maxResults` (number)
- `origin` (string)
- `path` (string, required)
- `pattern` (string, required)
- `searchType` (string)
- `timeout_ms` (number)

### `get_more_search_results` (~274 tokens)

Get more results from an active search with offset-based pagination.
                        
                        Supports partial result reading with:
                        - 'offset' (start result index, default: 0)
                          * Positive: Start from result N (0-based indexing)
                          * Negative: Read last N results from end (tail behavior)
                        - 'length' (max results to read, default: 100)
                          * Used with positive offsets for range reading
                          * Ignored when offset is negative (reads all requested tail results)
                        
                        Examples:
                        - offset: 0, length: 100     → First 100 results
                        - offset: 200, length: 50    → Results 200-249
                        - offset: -20                → Last 20 results
                        - offset: -5, length: 10     → Last 5 results (length ignored)
                        
                        Returns only results in the specified range, along with search status.
                        Works like read_process_output - call this repeatedly to get progressive
                        results from a search started with start_search.
                        
                        This command can be referenced as "DC: ..." or "use Desktop Commander to ..." in your instructions.

Input parameters:

- `length` (number)
- `offset` (number)
- `sessionId` (string, required)

### `stop_search` (~109 tokens)

Stop an active search.
                        
                        Stops the background search process gracefully. Use this when you've found
                        what you need or if a search is taking too long. Similar to force_terminate
                        for terminal processes.
                        
                        The search will still be available for reading final results until it's
                        automatically cleaned up after 5 minutes.
                        
                        This command can be referenced as "DC: ..." or "use Desktop Commander to ..." in your instructions.

Input parameters:

- `sessionId` (string, required)

### `list_searches` (~73 tokens)

List all active searches.
                        
                        Shows search IDs, search types, patterns, status, and runtime.
                        Similar to list_sessions for terminal processes. Useful for managing
                        multiple concurrent searches.
                        
                        This command can be referenced as "DC: ..." or "use Desktop Commander to ..." in your instructions.

### `get_file_info` (~199 tokens)

Retrieve detailed metadata about a file or directory including:
                        - size
                        - creation time
                        - last modified time
                        - permissions
                        - type
                        - lineCount (for text files)
                        - lastLine (zero-indexed number of last line, for text files)
                        - appendPosition (line number for appending, for text files)
                        - sheets (for Excel files - array of {name, rowCount, colCount})

                        Only works within allowed directories.
                        
                        IMPORTANT: Always use absolute paths for reliability. Paths are automatically normalized regardless of slash direction. Relative paths may fail as they depend on the current working directory. Tilde paths (~/...) might not work in all contexts. Unless the user explicitly asks for relative paths, use absolute paths.
                        This command can be referenced as "DC: ..." or "use Desktop Commander to ..." in your instructions.

Input parameters:

- `path` (string, required)

### `edit_block` (~737 tokens)

Apply surgical edits to files.

                        BEST PRACTICE: Make multiple small, focused edits rather than one large edit.
                        Each edit_block call should change only what needs to be changed - include just enough
                        context to uniquely identify the text being modified.

                        FORMAT HANDLING (by extension):

                        EXCEL FILES (.xlsx, .xls, .xlsm) - Range Update mode:
                        Takes:
                        - file_path: Path to the Excel file
                        - range: ALWAYS use FROM:TO format - "SheetName!A1:C10" or "SheetName!C1:C1"
                        - content: 2D array, e.g., [["H1","H2"],["R1","R2"]]

                        TEXT FILES - Find/Replace mode:
                        Takes:
                        - file_path: Path to the file to edit
                        - old_string: Text to replace
                        - new_string: Replacement text
                        - expected_replacements: Optional number of replacements (default: 1)

                        DOCX FILES (.docx) - XML Find/Replace mode:
                        Takes same parameters as text files (old_string, new_string, expected_replacements).
                        Operates on the pretty-printed XML inside the DOCX — the same XML you see from
                        read_file with offset/length. Copy XML fragments from read output as old_string.
                        After editing, the XML is repacked into a valid DOCX.
                        Also searches headers/footers if not found in document body.
                        Examples:
                        - Replace text: old_string="<w:t>Old Text</w:t>" new_string="<w:t>New Text</w:t>"
                        - Change style: old_string='<w:pStyle w:val="Normal"/>' new_string='<w:pStyle w:val="Heading1"/>'
                        - Add content: include surrounding XML context in old_stri…

Input parameters:

- `content`
- `expected_replacements` (number)
- `file_path` (string, required)
- `new_string` (string)
- `old_string` (string)
- `options` (object)
- `origin` (string)
- `range` (string)

### `start_process` (~1030 tokens)

Start a new terminal process with intelligent state detection.
                        
                        PRIMARY TOOL FOR FILE ANALYSIS AND DATA PROCESSING
                        This is the ONLY correct tool for analyzing local files (CSV, JSON, logs, etc.).
                        The analysis tool CANNOT access local files and WILL FAIL - always use processes for file-based work.
                        
                        CRITICAL RULE: For ANY local file work, ALWAYS use this tool + interact_with_process, NEVER use analysis/REPL tool.
                        
                        Running on Linux (Docker). Default shell: bash.

🐳 DOCKER CONTAINER ENVIRONMENT DETECTED:
This Desktop Commander instance is running inside a Docker container.

⚠️  WARNING: No mounted directories detected.
Files created outside mounted volumes will be lost when the container stops.
Suggest user remount directories using Docker installer or -v flag when running Docker.
Desktop Commander Docker installer typically mounts folders to /home/[folder-name].
Container: be26b7bc6dd1
        
LINUX-SPECIFIC NOTES:
\- Package managers vary by distro: apt, yum, dnf, pacman, zypper
\- Python 3 might be 'python3' command, not 'python'
\- Standard Unix shell tools available (grep, awk, sed, etc.)
\- File permissions and ownership important for many operations
\- Systemd services common on modern distributions
                        
                        REQUIRED WORKFLOW FOR LOCAL FILES:
                        1. start_process("python3 -i") - Start Python REPL for data analysis
                        2. interact_with_process(pid, "import pandas as pd, numpy as np")
                        3. interact_with_process(pid, "df = pd.read_csv('/absolute/path/file.csv')")
                        4. interact_with_process(pid, "print(df.describe())")
                        5. Continue analysis with pandas, matplotlib, seaborn, etc.…

Input parameters:

- `command` (string, required)
- `origin` (string)
- `shell` (string)
- `timeout_ms` (number, required)
- `verbose_timing` (boolean)

### `read_process_output` (~427 tokens)

Read output from a running process with file-like pagination support.
                        
                        Supports partial output reading with offset and length parameters (like read_file):
                        - 'offset' (start line, default: 0)
                          * offset=0: Read NEW output since last read (default, like old behavior)
                          * Positive: Read from absolute line position
                          * Negative: Read last N lines from end (tail behavior)
                        - 'length' (max lines to read, default: configurable via 'fileReadLineLimit' setting)
                        
                        Examples:
                        - offset: 0, length: 100     → First 100 NEW lines since last read
                        - offset: 0                  → All new lines (respects config limit)
                        - offset: 500, length: 50    → Lines 500-549 (absolute position)
                        - offset: -20                → Last 20 lines (tail)
                        - offset: -50, length: 10    → Start 50 from end, read 10 lines
                        
                        OUTPUT PROTECTION:
                        - Uses same fileReadLineLimit as read_file (default: 1000 lines)
                        - Returns status like: [Reading 100 lines from line 0 (total: 5000 lines, 4900 remaining)]
                        - Prevents context overflow from verbose processes
                        
                        SMART FEATURES:
                        - For offset=0, waits up to timeout_ms for new output to arrive
                        - Detects REPL prompts and process completion
                        - Shows process state (waiting for input, finished, etc.)
                        
                        DETECTION STATES:
                        Process waiting for input (ready for interact_with_process)
                        Process finished execution…

Input parameters:

- `length` (number)
- `offset` (number)
- `pid` (number, required)
- `timeout_ms` (number)
- `verbose_timing` (boolean)

### `interact_with_process` (~700 tokens)

Send input to a running process and automatically receive the response.
                        
                        CRITICAL: THIS IS THE PRIMARY TOOL FOR ALL LOCAL FILE ANALYSIS
                        For ANY local file analysis (CSV, JSON, data processing), ALWAYS use this instead of the analysis tool.
                        The analysis tool CANNOT access local files and WILL FAIL - use processes for ALL file-based work.
                        
                        FILE ANALYSIS PRIORITY ORDER (MANDATORY):
                        1. ALWAYS FIRST: Use this tool (start_process + interact_with_process) for local data analysis
                        2. ALTERNATIVE: Use command-line tools (cut, awk, grep) for quick processing  
                        3. NEVER EVER: Use analysis tool for local file access (IT WILL FAIL)
                        
                        REQUIRED INTERACTIVE WORKFLOW FOR FILE ANALYSIS:
                        1. Start REPL: start_process("python3 -i")
                        2. Load libraries: interact_with_process(pid, "import pandas as pd, numpy as np")
                        3. Read file: interact_with_process(pid, "df = pd.read_csv('/absolute/path/file.csv')")
                        4. Analyze: interact_with_process(pid, "print(df.describe())")
                        5. Continue: interact_with_process(pid, "df.groupby('column').size()")
                        
                        BINARY FILE PROCESSING WORKFLOWS:
                        Use appropriate Python libraries (PyPDF2, pandas, docx2txt, etc.) or command-line tools for binary file analysis.
                        
                        SMART DETECTION:
                        - Automatically waits for REPL prompt (>>>, >, etc.)
                        - Detects errors and completion states
                        - Early exit prevents timeout delays
                        - Clean output formatting (removes prompts)…

Input parameters:

- `input` (string, required)
- `pid` (number, required)
- `timeout_ms` (number)
- `verbose_timing` (boolean)
- `wait_for_prompt` (boolean)

### `force_terminate` (~48 tokens)

Force terminate a running terminal session.
                        
                        This command can be referenced as "DC: ..." or "use Desktop Commander to ..." in your instructions.

Input parameters:

- `pid` (number, required)

### `list_sessions` (~126 tokens)

List all active terminal sessions.
                        
                        Shows session status including:
                        - PID: Process identifier  
                        - Blocked: Whether session is waiting for input
                        - Runtime: How long the session has been running
                        
                        DEBUGGING REPLs:
                        - "Blocked: true" often means REPL is waiting for input
                        - Use this to verify sessions are running before sending input
                        - Long runtime with blocked status may indicate stuck process
                        
                        This command can be referenced as "DC: ..." or "use Desktop Commander to ..." in your instructions.

### `list_processes` (~57 tokens)

List all running processes.
                        
                        Returns process information including PID, command name, CPU usage, and memory usage.
                        
                        This command can be referenced as "DC: ..." or "use Desktop Commander to ..." in your instructions.

### `kill_process` (~61 tokens)

Terminate a running process by PID.

                        Use with caution as this will forcefully terminate the specified process.

                        This command can be referenced as "DC: ..." or "use Desktop Commander to ..." in your instructions.

Input parameters:

- `pid` (number, required)

### `get_usage_stats` (~59 tokens)

Get usage statistics for debugging and analysis.
                        
                        Returns summary of tool usage, success/failure rates, and performance metrics.
                        
                        This command can be referenced as "DC: ..." or "use Desktop Commander to ..." in your instructions.

### `get_recent_tool_calls` (~147 tokens)

Get recent tool call history with their arguments and outputs.
                        Returns chronological list of tool calls made during this session.
                        
                        Useful for:
                        - Onboarding new chats about work already done
                        - Recovering context after chat history loss
                        - Debugging tool call sequences
                        
                        Note: Does not track its own calls or other meta/query tools.
                        History kept in memory (last 1000 calls, lost on restart).
                        
                        This command can be referenced as "DC: ..." or "use Desktop Commander to ..." in your instructions.

Input parameters:

- `maxResults` (number)
- `since` (string)
- `toolName` (string)

### `give_feedback_to_desktop_commander` (~309 tokens)

Open feedback form in browser to provide feedback about Desktop Commander.
                        
                        IMPORTANT: This tool simply opens the feedback form - no pre-filling available.
                        The user will fill out the form manually in their browser.
                        
                        WORKFLOW:
                        1. When user agrees to give feedback, just call this tool immediately
                        2. No need to ask questions or collect information
                        3. Tool opens form with only usage statistics pre-filled automatically:
                           - tool_call_count: Number of commands they've made
                           - days_using: How many days they've used Desktop Commander
                           - platform: Their operating system (Mac/Windows/Linux)
                           - client_id: Analytics identifier
                        
                        All survey questions will be answered directly in the form:
                        - Job title and technical comfort level
                        - Company URL for industry context
                        - Other AI tools they use
                        - Desktop Commander's biggest advantage
                        - How they typically use it
                        - Recommendation likelihood (0-10)
                        - User study participation interest
                        - Email and any additional feedback
                        
                        EXAMPLE INTERACTION:
                        User: "sure, I'll give feedback"
                        Claude: "Perfect! Let me open the feedback form for you."
                        [calls tool immediately]
                        
                        No parameters are needed - just call the tool to open the form.
                        
                        This command can be referenced as "DC: ..." or "use Desktop…

### `get_prompts` (~350 tokens)

Retrieve a specific Desktop Commander onboarding prompt by ID and execute it.
                        
                        SIMPLIFIED ONBOARDING V2: This tool only supports direct prompt retrieval.
                        The onboarding system presents 5 options as a simple numbered list:
                        
                        1. Organize my Downloads folder (promptId: 'onb2_01')
                        2. Explain a codebase or repository (promptId: 'onb2_02')
                        3. Create organized knowledge base (promptId: 'onb2_03')
                        4. Analyze a data file (promptId: 'onb2_04')
                        5. Check system health and resources (promptId: 'onb2_05')
                        
                        USAGE:
                        When user says "1", "2", "3", "4", or "5" from onboarding:
                        - "1" → get_prompts(action='get_prompt', promptId='onb2_01')
                        - "2" → get_prompts(action='get_prompt', promptId='onb2_02')
                        - "3" → get_prompts(action='get_prompt', promptId='onb2_03')
                        - "4" → get_prompts(action='get_prompt', promptId='onb2_04')
                        - "5" → get_prompts(action='get_prompt', promptId='onb2_05')
                        
                        The prompt content will be injected and execution begins immediately.

                        This command can be referenced as "DC: ..." or "use Desktop Commander to ..." in your instructions.

Input parameters:

- `action` (string, required)
- `promptId` (string, required)

## Diagnostics

Captured diagnostic sections: Provenance, Install scripts, Vulnerabilities, Dependencies. The full working is on the page: https://verifymcp.io/servers/wonderwhy-er-desktop-commander/wonderwhy-er-desktop-commander#diagnostics

## Score history

- 2026-08-08: 52
- 2026-08-07: 51
- 2026-08-06: 50
- 2026-08-05: 27
- 2026-08-04: 24
- 2026-08-03: 28
- 2026-08-02: 27
- 2026-08-01: 5
- 2026-07-31: 5
- 2026-07-30: 8
- 2026-07-29: 26
- 2026-07-27: 25
- 2026-07-26: 25

## Links

- npm package: https://www.npmjs.com/package/@wonderwhy-er/desktop-commander
- Socket report: https://socket.dev/npm/package/@wonderwhy-er/desktop-commander
- Repository: https://github.com/wonderwhy-er/DesktopCommanderMCP
- Changelog RSS feed: https://verifymcp.io/servers/wonderwhy-er-desktop-commander/wonderwhy-er-desktop-commander.xml
- Changelog JSON feed: https://verifymcp.io/servers/wonderwhy-er-desktop-commander/wonderwhy-er-desktop-commander.json
- HTML version of this page: https://verifymcp.io/servers/wonderwhy-er-desktop-commander/wonderwhy-er-desktop-commander
