← Back to directory
D

Desktop Commander

Community
Search, update, manage files and run terminal commands with AI
Category
Dev Tools #199 of 438
Stars
★ 10.0k Very popular
Transport
stdio (local process)
Runtime
Node.js · Docker
Credentials
No credential needed
License
MIT
Last commit
Tools
25
54FMRS · D

Desktop Commander is a powerful MCP server providing terminal control, file management, and process management. It has broad client support and rich file format support (Excel, PDF, DOCX). However, users must be aware of security limitations and follow recommendations to use Docker isolation for stronger security.

Strongest · Documentation 15/20 Weakest · Security and permissions 6/20

Reliability
7/20
Security and permissions
6/20
Maintenance
12/20
Documentation
15/20
Setup experience
14/20
Why each score
Reliability 7/20
Based only on the README and server.json, the tool list and descriptions look complete and a stdio/npx launch path is plausible, but no server source code, tests, or CI evidence was provided to verify the MCP initialization handshake or actual tool behavior. Naming inconsistencies in the README (execute_command vs start_process, read_output vs read_process_output) further reduce confidence that documented behavior matches real behavior. Per static calibration this cannot exceed 12; conservatively scored 7.
Security and permissions 6/20
The README explicitly states this is not a sandbox: allowedDirectories does not restrict terminal commands, and symlinks, command substitution, absolute paths, or code execution can bypass restrictions. There are a command blocklist, symlink traversal prevention, and Docker isolation, but no explicit confirmation mechanism is documented for destructive operations such as deleting files or killing processes. Remote MCP requires user-initiated startup and uses OAuth plus an encrypted channel. No direct evidence of credential theft or covert exfiltration was found, so the 0-4 red-line range was not triggered, but permission boundaries and confirmation controls are clearly incomplete; scored 6.
Maintenance 12/20
The repository is not archived, has an MIT license, version 0.2.47, auto-update mechanisms, a security reporting channel, Discord, and sponsor links, indicating active maintenance. However, the supplied materials contain no commit history, release dates, issue response metrics, or dependency update records, so maintenance velocity cannot be verified and a high score is not justified; scored 12.
Documentation 15/20
The README covers multi-client installation, a tool table, configuration, security warnings, Docker, FAQ, troubleshooting, and logging, providing good layered documentation. However, there are tool naming inconsistencies (execute_command vs start_process, read_output vs read_process_output), and some sections appear truncated or contain placeholders (e.g., Handling Long-Running Commands, Mount Your Machine Folders Coming Soon), so points are deducted; scored 15.
Setup experience 14/20
The project provides npx setup, bash/PowerShell installers, Docker installation, and JSON configuration examples for Claude, Cursor, VS Code, Gemini CLI, and other clients, making the setup path clear. However, Node.js or Docker is required, and no CI or test evidence in the supplied files verifies that a connection works reliably after installation. Per the static calibration rule, setup cannot exceed 15; scored 14.

Static review · not runListed 2026-08-07

Read the FMRS scoring method →

Fit and risk

What it can accessReads local filesWrites / deletes local filesRuns commands or codeUses the network

Best for

  • Developers who want AI assistants to directly control terminal and file system.
  • Users who need enhanced code editing, automation, and codebase exploration within MCP clients like Claude Desktop.
  • Scenarios requiring handling of complex file formats like Excel, PDF, DOCX.

Not for

  • Users needing a fully sandboxed environment (unless using Docker installation).
  • Security-sensitive environments, as terminal commands can bypass directory restrictions.
  • Users who don't need terminal control and only basic file operations.

Required permissions

  • Filesystem read/write permissions, including terminal commands that can access files outside allowedDirectories.
  • Ability to execute arbitrary terminal commands (subject to blockedCommands).
  • Manage processes (start, interact, terminate).
  • Access network to fetch URL content (read_file).

Risks and side effects

  • Terminal commands can access files outside allowedDirectories, posing a security risk.
  • Command blocklist may be bypassed via symlinks, command substitution, or absolute paths.
  • Configuration changes should be made in a separate chat window to avoid accidental modification by Claude.
  • Potential risk to host system if not using Docker isolation.

Setup

Before you start

Runtime:Node.js · Docker

  1. Ensure Node.js is installed.
  2. Run npx @wonderwhy-er/desktop-commander@latest setup (or use other installation methods like Smithery, manual config, Docker).
  3. Restart Claude Desktop.
claude_desktop_config.json
{
  "mcpServers": {
    "desktop-commander": {
      "command": "npx",
      "args": [
        "-y",
        "@wonderwhy-er/desktop-commander@latest"
      ]
    }
  }
}

Shown for Claude Desktop. Other clients may use a different file or key (VS Code uses "servers") — the configurator below converts it.

.vscode/mcp.json
{
  "servers": {
    "desktop-commander": {
      "command": "npx",
      "args": [
        "-y",
        "@wonderwhy-er/desktop-commander@latest"
      ]
    }
  }
}

Goes in your project's .vscode/mcp.json (VS Code uses a "servers" key).

Terminal
claude mcp add desktop-commander -- npx -y @wonderwhy-er/desktop-commander@latest

Run it in a terminal; replace any <…> placeholders with your own values first.

Check that it works

After installing and restarting Claude Desktop, the desktop-commander tools (such as get_config, read_file, start_process) should appear in the client's tool list; you can also ask Claude to run get_config to confirm the connection works.

Troubleshooting

  1. If Claude won't start, check JSON syntax in claude_desktop_config.json.
  2. If commands time out, use background execution or read output features.
  3. If searches fail, check search patterns or analyze fuzzy search logs.
  4. If Claude times out during debugging, ensure debugger is properly attached.

Things to try

Once connected, you can ask your AI assistant things like:

  • Analyze sales.csv and show the top customers
  • SSH to my server and check disk space
  • Start Node.js and test this API
  • Search my project folder for all files containing TODO

Tools 25

get_config read-only
Get the complete server configuration as JSON, including blockedCommands, defaultShell, allowedDirectories, fileReadLineLimit, fileWriteLineLimit, telemetryEnabled.
set_config_value writes
Set a specific configuration value by key, such as blockedCommands, defaultShell, allowedDirectories, fileReadLineLimit, fileWriteLineLimit, telemetryEnabled.
start_process writes
Start programs with smart detection of when they're ready for input.
interact_with_process writes
Send commands to running programs and get responses.
read_process_output read-only
Read output from running processes.
force_terminate destructive
Force terminate a running terminal session.
list_sessions read-only
List all active terminal sessions.
list_processes read-only
List all running processes with detailed information.
Show 17 more tools
kill_process destructive
Terminate a running process by PID.
read_file read-only
Read contents from local filesystem, URLs, Excel files (.xlsx, .xls, .xlsm), and PDFs with line/page-based pagination.
read_multiple_files read-only
Read multiple files simultaneously.
write_file writes
Write file contents with options for rewrite or append mode. Supports Excel files (JSON 2D array format). For PDFs, use write_pdf.
write_pdf writes
Create new PDF files from markdown or modify existing PDFs (insert/delete pages). Supports HTML/CSS styling and SVG graphics.
create_directory writes
Create a new directory or ensure it exists.
list_directory read-only
Get detailed recursive listing of files and directories (supports depth parameter, default depth=2).
move_file writes
Move or rename files and directories.
start_search read-only
Start streaming search for files by name or content patterns (searches text files and Excel content).
get_more_search_results read-only
Get paginated results from active search with offset support.
stop_search writes
Stop an active search gracefully.
list_searches read-only
List all active search sessions.
get_file_info read-only
Retrieve detailed metadata about a file or directory (includes sheet info for Excel files).
edit_block writes
Apply targeted text replacements for text files, or range-based cell updates for Excel files.
get_usage_stats read-only
Get usage statistics for your own insight.
get_recent_tool_calls read-only
Get recent tool call history with arguments and outputs for debugging and context recovery.
give_feedback_to_desktop_commander writes
Open feedback form in browser to provide feedback to Desktop Commander Team.

Use cases

Data analysis: Let Claude run Python code in memory to analyze CSV/Excel files.
Remote access: SSH to a server and check disk space.
Development: Start Node.js and test an API, or run interactive Node sessions.
Codebase exploration: Recursively search files and content to understand complex codebases.
File operations: Read, write, edit Excel, PDF, DOCX files.

Supported clients

Claude Desktop
Cursor
Windsurf
VS Code / GitHub Copilot
Cline
Roo Code
Claude Code
Trae
Kiro
Codex
JetBrains IDEs
Gemini CLI
Augment Code
Qwen Code

Listed from the project's documentation, not tested by this site.

Overview

Desktop Commander is an MCP server that gives AI like Claude terminal control, file system search, and diff file editing capabilities. Built on top of the MCP Filesystem Server, it supports remote AI control, file preview UI, enhanced terminal interaction, in-memory code execution (Python/Node.js/R), native Excel/PDF/DOCX support, process management, audit logging, and safety guardrails (symlink protection, command blocklist, Docker isolation).

Similar servers

Context7 80 · B

Upstash's official server providing up-to-date third-party library docs for AI coding assistants

★ 62.9k · Tools 2 Compare with this →

Source revision ea3ed35a7be9 Data synced 2026-10-11 Read the FMRS scoring method