This Model Context Protocol (MCP) server provides 43 tools focused on local file operations and automation tasks. Its scope includes filesystem access, process management, session handling, search, OCR, ZIP operations, and PDF export.
🛠️ Key Features
43 tools for filesystem, process management, sessions, search
OCR support
ZIP tooling
PDF export capabilities
🚀 Use Cases
Building MCP-based agents that interact with local files
Running and managing processes during workflows
Searching data and extracting text via OCR
Packaging results with ZIP and exporting documents as PDF
⚡ Developer Benefits
MCP integration for agent frameworks
Tool coverage across common file-management and document-export needs
Async-search and local-first workflow alignment (as indicated by topics)
⚠️ Limitations
Described capabilities are tool-oriented (filesystem/process/search/OCR/ZIP/PDF export); no additional scope is provided beyond the stated areas.
A comprehensive Model Context Protocol (MCP) server that gives AI assistants full filesystem access, bounded multi-file content search, process management, interactive shell sessions, and async filename search capabilities.
50 tools in a single server - everything an AI agent needs to interact with the local system.
Discovery keywords: local filesystem MCP server, multi-file content search MCP, safe delete MCP, Recycle Bin MCP server, process management MCP, interactive shell MCP, async file search for AI agents, cloud-lock-safe file operations, Markdown to PDF MCP, OCR MCP server, ZIP archive MCP.
Registry status: published on npm, indexed by jsDelivr, visible on LobeHub, listed on Glama, and prepared for the official MCP Registry via server.json. Some third-party directories still show older 43-tool metadata, so the canonical README/npm metadata should remain the source of truth until their reindex catches up.
NOTE
For AI Agents & LLM Integrations:
FileCommander provides 50 specialized tools accessible via standard stdio transport. All tool names use the fc_ prefix to prevent namespace collisions. For LLMs, compact context and schema overviews are available in llms.txt and server.json.
Overview & Why FileCommander?
Most filesystem MCP servers only cover basic read/write operations. FileCommander goes further:
Safe Delete - Moves files to Recycle Bin (Windows) or Trash (macOS/Linux) instead of permanent deletion
Interactive Sessions - Start and interact with REPLs (Python, Node.js, shells) through the MCP protocol
Async Search - Search large directory trees in the background while the AI continues working
Explicit Content Search - Search literal text or regex across a bounded list of files without recursion or glob expansion
Process Management - List, start, and terminate system processes
String Replace - Edit files by matching unique strings with context validation
Format Conversion - Convert between JSON, CSV, INI, YAML, TOML, XML, and TOON
ZIP Archives - Create, extract, and list ZIP archives
File Checksums - MD5, SHA-1, SHA-256, SHA-384, and SHA-512 hashing with compare
OCR - Extract text from images (optional tesseract.js dependency)
Safety Mode - Toggle to route all deletes through Recycle Bin / Trash
Markdown Export - Convert Markdown to professional HTML/PDF with code blocks, tables, nested lists, blockquotes
Cloud-Lock Safe - Automatic copy+delete fallback when cloud sync filters (OneDrive, Dropbox, Google Drive, iCloud) block rename operations
Cloud Lock Diagnosis - Check whether a path is at risk of sync-filter conflicts before operating
Cross-platform - Works on Windows, macOS, and Linux with platform-specific optimizations
sequenceDiagram
autonumber
participant AI as AI Assistant (Client)
participant FC as FileCommander Engine
participant FS as Host Filesystem
participant Trash as Recycle Bin / Trash
participant Cloud as Cloud Sync Filter
Note over AI,FC: 1. Safe Deletion & Recovery Protection
AI->>FC: fc_delete_file / fc_safe_delete(targetPath)
alt Safety Mode Active or fc_safe_delete invoked
FC->>Trash: Move item to Recycle Bin / Trash
Trash-->>FC: Moved safely (recoverable)
FC-->>AI: Success (item preserved in Trash/Recycle Bin)
else Permanent Unlink requested
FC->>FS: Direct unlink
FS-->>FC: Removed permanently
FC-->>AI: Success
end
Note over AI,Cloud: 2. Resilient Cloud-Lock Handling (OneDrive/Dropbox)
AI->>FC: fc_move(sourcePath, destPath)
alt Cloud Filter Locks Destination
FC->>Cloud: Attempt standard rename
Cloud-->>FC: EPERM / EBUSY (Cloud Filter Error)
FC->>FS: Fallback: copyFileSync + SHA-256 verify
FC->>FS: unlinkSync source
FC-->>AI: Move succeeded via resilient fallback
else Local Native Filesystem
FC->>FS: Rename (atomic)
FS-->>FC: Done
FC-->>AI: Move succeeded
end
Core Capabilities & Safety Invariants
Capability / Invariant
Guarantee & Implementation Details
Security & Operational Benefit
Local stdio & explicit egress
The MCP transport is local stdio, with no telemetry and no automatic network egress. fc_web_fetch makes outbound HTTP(S) requests only when a client explicitly invokes it; private targets are blocked by default unless allow_private is enabled.
Makes the network boundary visible to clients while retaining a local, port-free server transport.
Safe Deletion & Trash Protection
fc_safe_delete moves items to Windows Recycle Bin / macOS Trash / Linux FreeDesktop Trash. fc_set_safe_mode routes all deletes safely.
Prevents irreversible data loss from accidental recursive or bulk deletions.
Cloud-Lock Resilient Move (fc_move)
Automatic detection of cloud sync filters (OneDrive, Dropbox, iCloud reparse points) with seamless copy+verify+delete fallback.
Eliminates EPERM / EBUSY failures during automated agent operations in sync directories.
Cloud-Lock Diagnosis (fc_check_cloud_lock)
Read-only report of static cloud-path context plus target existence/type; Cloud Files hydration and process handles are explicitly reported as not checked when unavailable.
Agents can distinguish static OneDrive risk from an actual detected rename lock.
Bounded Multi-File Content Search
fc_search_content strictly caps inputs (max 50 explicit files, 10 MB per file, 200 matches, 200k chars) without glob recursion.
Prevents out-of-memory errors and catastrophic CPU lockups during large repository searches.
Automated Secret & Token Redaction
Content search excerpts automatically mask common API keys, bearer tokens, AWS credentials, and authorization headers.
Prevents LLM context contamination and accidental credential leakage in prompt history.
Interactive REPL & Session Isolation
Stateful interactive sessions (fc_start_session, fc_send_input, fc_read_output) for Python, Node.js, bash, and PowerShell with bounded buffers.
Allows multi-turn REPL debugging without unconstrained background process buildup.
Lossless Multi-Format Engine
Declarative conversion (fc_convert_format) across 7 structured formats (JSON, YAML, TOML, XML, CSV, INI, TOON).
Clean data normalization across heterogeneous configuration formats without data loss.
Mojibake & File Repair Engine
fc_fix_encoding, fc_fix_json, and fc_cleanup_file repair broken UTF-8 encoding (27+ patterns), malformed JSON syntax, BOMs, and NUL bytes.
Self-healing pipelines for corrupted files generated across divergent OS platforms.
Unprivileged Non-Elevation Execution
Designed and verified to run in standard unprivileged user-mode. Never requires administrative or root privileges.
Minimal attack surface; adheres to the principle of least privilege.
Six-language Runtime i18n Engine
Dynamic language switching and introspection (fc_set_language, fc_get_language) for German (de), English (en), Spanish (es), Chinese (zh), Japanese (ja), and Russian (ru).
Native multilingual developer experience and localized error reporting.
Multi-OS Verified Matrix
Tested across Windows, Ubuntu Linux, and macOS on Node.js 20, 22, and 24 with 292 automated assertions.
Continuous cross-platform parity and reliability.
Target Personas & Discoverability
FileCommander is purpose-built and validated for four core developer, agentic, and operations personas:
[PERSONA-01] Autonomous AI Coding Agents & LLM Swarms
Profile: Systems and automation engineers constructing cross-platform CLI tools, CI/CD validation pipelines, and multi-machine sync scripts across Windows, Linux, and macOS.
Key Operational Pain Points: Heterogeneous operating system semantics (Windows backslashes vs POSIX slashes, line-ending corruption, shell-specific syntax), zombie child processes, and file locking in shared OneDrive/Dropbox workspaces.
FileCommander Solution:
Cross-platform unified tool semantics across Windows, Linux, and macOS.
Stateful interactive REPL sessions (fc_start_session, fc_send_input, fc_read_output) with bounded circular ring buffers.
Batch file renaming (fc_batch_rename) and background directory search (fc_start_search, fc_get_search_results).
Process lifecycle management (fc_execute_command, fc_start_process, fc_kill_process) without process leaks.
Profile: Security officers, compliance auditors, and privacy teams overseeing AI tool integrations in enterprise and production environments.
Key Operational Pain Points: Undisclosed background telemetry beacons, unvetted network access from local plugins, credential/token leakage into model training or prompt histories, and unprivileged user privilege escalation.
FileCommander Solution:
Local stdio transport with strictly zero telemetry and zero open network listening ports.
Explicit outbound network egress strictly restricted to caller-invoked fc_web_fetch (internal/private IPs blocked by default).
Automated secret and bearer token masking in search excerpts (INV-MASK-06).
Strict unprivileged user execution (INV-PROC-09) and binding 48-hour vulnerability response SLA (security@open-bricks.org, security@ellmos.ai).
[PERSONA-04] Enterprise Platform Architects & Data Pipeline Developers
Profile: Solutions architects and data engineers integrating local files, normalizing heterogeneous configuration formats, validating cryptographic hashes, and generating reports.
Key Operational Pain Points: MCP server sprawl requiring 4-6 disparate single-purpose servers, corrupted UTF-8 byte sequences (Mojibake) across tools, and bespoke parsing scripts.
FileCommander Solution:
Comprehensive 50-tool single-server deployment eliminating multi-server sprawl and process overhead.
Lossless declarative conversion across 7 structured formats (fc_convert_format: JSON, YAML, TOML, XML, CSV, INI, TOON).
Built-in file repair engines (fc_fix_encoding, fc_fix_json, fc_cleanup_file) for self-healing pipelines.
Cryptographic checksums (fc_checksum: SHA-256, SHA-512, MD5, SHA-1) and Markdown to PDF/HTML rendering (fc_md_to_pdf, fc_md_to_html).
Replace a unique string in a file with context validation
fc_list_directory
List directory contents (recursive, configurable depth)
fc_create_directory
Create directories (including parents)
fc_delete_file
Delete a file (permanent)
fc_delete_directory
Delete a directory (with optional recursive flag)
fc_safe_delete
Move to Recycle Bin / Trash (recoverable!)
fc_move
Move or rename files and directories (cloud-lock safe)
fc_copy
Copy files and directories
fc_file_info
Get detailed file metadata (size, dates, type)
fc_search_files
Synchronous file search with wildcard patterns
fc_preview_file is the remote/headless fallback for local files. Its default call returns structured metadata only: resolved path, file:// URI, MIME type, byte size, preview kind, fixed 1 MiB limit, and the exact follow-up call. Content is read only after include_content=true. Eligible text and raster images use standard MCP text/image content blocks; PDFs use a bounded embedded resource. Files above 1 MiB and unsupported types remain metadata-only and are never read or Base64-encoded by the preview path.
Content Search (1 tool)
Tool
Description
fc_search_content
Read-only literal or regex search within an explicit ordered list of files, with case, context, global, and per-file limits
fc_search_content never expands globs, traverses directories, or recursively discovers files. It accepts at most 50 explicit UTF-8 text files, skips binary and files over 10 MB, and returns deterministic JSON. Matches are limited to 200 globally and 100 per file, context to 10 lines, excerpts to 500 characters, and serialized output to 200,000 characters. Missing, cloud-only, permission, encoding, binary, and size failures are reported per file so readable files still produce results. Common secret formats are redacted from excerpts.
Async Search (5 tools)
Tool
Description
fc_start_search
Start a background search (returns immediately)
fc_get_search_results
Retrieve results with pagination
fc_stop_search
Cancel a running search
fc_list_searches
List all active/completed searches
fc_clear_search
Remove completed searches from memory
Process Management (5 tools)
Tool
Description
fc_execute_command
Execute a shell command (blocking, with timeout)
fc_start_process
Start a background process (non-blocking)
fc_open_path
Validate and open an existing local file or directory with the OS default application
fc_list_processes
List running system processes
fc_kill_process
Terminate a process by PID or name
fc_open_path accepts only an existing file or directory and sends it to a fixed native default-handler launcher. Its structured result reports launcher_accepted=true|false, always reports user_visible="unknown", and identifies a machine-readable fallback: fc_preview_file with metadata-only arguments for files or fc_list_directory for directories. Launcher acceptance never claims that a GUI became visible. fc_start_process instead lets the caller choose an executable and arguments. fc_execute_command accepts an arbitrary shell command: Node's default shell is used for ordinary commands (COMSPEC/cmd.exe on Windows), while FileCommander's Windows special-character path can route through Windows PowerShell.
Interactive Sessions (5 tools)
Tool
Description
fc_start_session
Start an interactive process (Python, Node, shell...)
fc_read_output
Read session output
fc_send_input
Send input to a running session
fc_list_sessions
List all sessions
fc_close_session
Terminate a session
File Maintenance & Repair (9 tools)
Tool
Description
fc_fix_json
Repair broken JSON (BOM, trailing commas, comments, single quotes)
fc_validate_json
Validate JSON with detailed error position and context
fc_cleanup_file
Remove BOM, NUL bytes, trailing whitespace, normalize line endings
fc_fix_encoding
Fix Mojibake / double-encoded UTF-8 (27+ character patterns)
fc_folder_diff
Track directory changes with snapshots (new/modified/deleted)
Convert between JSON, CSV, INI, YAML, TOML, XML, and TOON formats
fc_detect_duplicates
Find duplicate files using SHA-256 hashing
fc_checksum
File hashing (MD5, SHA-1, SHA-256, SHA-384, SHA-512) with optional compare
Archive (1 tool)
Tool
Description
fc_archive
Create, extract, and list ZIP archives
OCR (1 tool)
Tool
Description
fc_ocr
Extract text from images via tesseract.js (optional dependency)
Cloud Sync (1 tool)
Tool
Description
fc_check_cloud_lock
Report static cloud-sync context and target state; never claim an active lock without evidence (Windows)
System (4 tools)
Tool
Description
fc_get_time
Get current system time with timezone info
fc_set_safe_mode
Toggle safe mode: all deletes go through Recycle Bin / Trash
fc_set_language
Set the runtime language (de, en, es, zh, ja, or ru)
fc_get_language
Read the active runtime language and all supported language codes
Export (2 tools)
Tool
Description
fc_md_to_html
Markdown to standalone HTML with CSS styling (headers, code blocks, tables, nested lists, blockquotes, images, checkboxes)
fc_md_to_pdf
Markdown to PDF via headless browser (Edge/Chrome). Falls back to HTML if no browser is available
Web (1 tool)
Tool
Description
fc_web_fetch
Fetch a web page and return content by mode: extract (clean main text), raw (HTTP body), links, forms, or headers. Read-only network tool; SSRF guard blocks internal/private targets by default.
Total: 50 tools
Comparative Matrix & Alternatives
FileCommander combines filesystem manipulation, bounded search, process control, data repair, format conversion, and document rendering into a single unified MCP interface. Below is an architectural comparison against standard alternatives across 10 key operational dimensions:
Operational Dimension
ellmos FileCommander MCP (50 Tools)
Official Filesystem MCP (@modelcontextprotocol/server-filesystem)
Desktop Commander MCP
Direct Host Shell (bash / PowerShell)
Ad-Hoc Scripts & Cloud APIs
Tool Breadth & Scope[INV-PROC-09]
50 unified tools across 6 domains
~11 basic file I/O tools
~15 tools (file + process)
Unconstrained CLI commands
Fragmented bespoke scripts
Safe Deletion & Recovery[INV-SAFE-02]
Native OS Recycle Bin / Trash (fc_safe_delete, Safety Mode)
Permanent deletion only (unlink)
Permanent deletion only
Irreversible rm -rf / Remove-Item
Custom trash implementations
Cloud-Lock & Sync Resilience[INV-LOCK-03]
Automatic fallback (copy + SHA-256 verify + unlink on EPERM/EBUSY)
Enables multi-turn REPL debugging while preventing zombie process buildup.
INV-PROC-09
Unprivileged Non-Elevation Execution
Executes entirely in standard unprivileged user-mode; never requests or requires administrative elevation or root rights.
Minimal attack surface; adheres strictly to the principle of least privilege.
INV-SLA-10
48h Security Response & 5-Day Triage SLA
Formal vulnerability commitment with multi-channel contacts (security@open-bricks.org, security@ellmos.ai).
Predictable, enterprise-ready incident response and triage lifecycle.
Security
This server has full filesystem access with the running user's permissions.
See SECURITY.md for detailed security information and recommendations.
Key points:
fc_execute_command runs arbitrary shell commands
fc_open_path invokes the operating system's associated application for a caller-selected existing path; that application runs with the user's permissions
fc_open_path reports launcher acceptance separately from the invariant user_visible="unknown"; fc_preview_file is the metadata-first remote fallback with an explicit 1 MiB inline-content boundary
fc_start_session starts an arbitrary interactive command, and subsequent fc_send_input calls can execute additional actions
fc_delete_* tools perform permanent deletion by default (use fc_safe_delete or enable safe mode via fc_set_safe_mode to route all deletes through Recycle Bin / Trash)
Safe mode protects only fc_delete_file and fc_delete_directory; it does not sandbox commands or interactive sessions
The server transport is local stdio and emits no telemetry, but an explicit fc_web_fetch call performs outbound HTTP(S) access
No built-in sandboxing - security is delegated to the MCP client layer
Development
bash
# Install dependencies
npm install
# Watch mode (auto-rebuild on changes)
npm run dev
# One-time build
npm run build
# Start the server
npm start
# Run test suite
npm test
Testing
The project includes 233 Vitest tests plus 71 standalone i18n checks (304 total) covering filesystem operations, metadata-first inline preview, bounded content search, native default-handler launching, format conversion, encoding repair, archive handling, duplicate detection, language packs, tool annotations, real stdio behavior, and security boundaries.
bash
npm test# Run all tests
node test-i18n.mjs # Run standalone i18n checks
npx vitest run # Same as above
npx vitest --watch # Watch mode
Tests are verified on Windows, macOS, and Linux.
Pushes and pull requests run CI on Node.js 20, 22, and 24 with npm ci, TypeScript build, Vitest, and an npm package dry-run.
This project was originally developed as BACH FileCommander (bach-filecommander-mcp). It has been renamed to ellmos FileCommander (ellmos-filecommander-mcp) as part of the ellmos-ai organization.
The legacy package name bach-filecommander-mcp is deprecated. Please use ellmos-filecommander-mcp instead:
Dieses Projekt ist eine unentgeltliche Open-Source-Schenkung im Sinne der §§ 516 ff. BGB (Gefälligkeitsrecht). Die Haftung des Urhebers und der Mitwirkenden ist gemäß § 521 BGB auf Vorsatz und grobe Fahrlässigkeit beschränkt. Ergänzend gilt der Haftungsausschluss der MIT-Lizenz.
Nutzung auf eigenes Risiko. Keine Wartungszusage, keine Verfügbarkeitsgarantie, keine Gewähr für Fehlerfreiheit oder Eignung für einen bestimmten Zweck.
Sicherheitsrelevante Vorfälle und Schwachstellen werden über das verbindliche 48-Stunden-SLA unter security@open-bricks.org und security@ellmos.ai entgegengenommen und innerhalb von 5 Werktagen triagiert.
This project is an unpaid open-source donation under German law (§§ 516 et seq. BGB). Liability is strictly limited to intent and gross negligence (§ 521 German Civil Code). The MIT license disclaimer applies complementarily. Use at your own risk. No warranty, no maintenance guarantee, no fitness-for-purpose assumed.
Security incidents and vulnerabilities are handled under a binding 48-hour response SLA via security@open-bricks.org and security@ellmos.ai with formal triage within 5 business days.