Ellmos Filecommander Mcp
๐ ๐ ๐ ๐ช ๐ง - Comprehensive local filesystem MCP server with file management, process control, interactive sessions, async search, and safe delete via Recycle Bin.
Quick Install
{
"mcpServers": {
"ellmos-ai-ellmos-filecommander-mcp": {
"command": "npx",
"args": [
"-y",
"ellmos-ai-ellmos-filecommander-mcp"
]
}
}
}Using an AI coding agent (Claude Code, Cursor, etc.)? Copy a ready-made prompt that tells it to fetch the setup instructions and install this server for you.
Documentation Overview
ellmos FileCommander MCP Server
๐ฉ๐ช Deutsche Version
Part of the ellmos-ai family.
A comprehensive Model Context Protocol (MCP) server that gives AI assistants full filesystem access, bounded multi-file content search, process management, interactive shell sessions, and async filename search capabilities.
47 tools in a single server - everything an AI agent needs to interact with the local system.
Discovery keywords: local filesystem MCP server, multi-file content search MCP, safe delete MCP, Recycle Bin MCP server, process management MCP, interactive shell MCP, async file search for AI agents, cloud-lock-safe file operations, Markdown to PDF MCP, OCR MCP server, ZIP archive MCP.
Registry status: published on npm, indexed by jsDelivr, visible on LobeHub, listed on Glama, and prepared for the official MCP Registry via server.json. Some third-party directories still show older 43-tool metadata, so the canonical README/npm metadata should remain the source of truth until their reindex catches up.
[!NOTE] For AI Agents & LLM Integrations: FileCommander provides 47 specialized tools accessible via standard stdio transport. All tool names use the
fc_prefix to prevent namespace collisions. For LLMs, compact context and schema overviews are available inllms.txtandserver.json.
Why FileCommander?
Most filesystem MCP servers only cover basic read/write operations. FileCommander goes further:
- Safe Delete - Moves files to Recycle Bin (Windows) or Trash (macOS/Linux) instead of permanent deletion
- Interactive Sessions - Start and interact with REPLs (Python, Node.js, shells) through the MCP protocol
- Async Search - Search large directory trees in the background while the AI continues working
- Explicit Content Search - Search literal text or regex across a bounded list of files without recursion or glob expansion
- Process Management - List, start, and terminate system processes
- String Replace - Edit files by matching unique strings with context validation
- Format Conversion - Convert between JSON, CSV, INI, YAML, TOML, XML, and TOON
- ZIP Archives - Create, extract, and list ZIP archives
- File Checksums - MD5, SHA-1, SHA-256, SHA-384, and SHA-512 hashing with compare
- OCR - Extract text from images (optional tesseract.js dependency)
- Safety Mode - Toggle to route all deletes through Recycle Bin / Trash
- Markdown Export - Convert Markdown to professional HTML/PDF with code blocks, tables, nested lists, blockquotes
- Cloud-Lock Safe - Automatic copy+delete fallback when cloud sync filters (OneDrive, Dropbox, Google Drive, iCloud) block rename operations
- Cloud Lock Diagnosis - Check whether a path is at risk of sync-filter conflicts before operating
- Cross-platform - Works on Windows, macOS, and Linux with platform-specific optimizations
System Architecture
flowchart TD
subgraph Client["MCP Client Layer"]
Claude["Claude Desktop / Claude Code"]
Custom["Custom LLM Agents / Frameworks"]
end
subgraph Transport["Transport Layer"]
Stdio["Stdio Transport (JSON-RPC)"]
end
subgraph Core["ellmos FileCommander Engine (47 Tools)"]
FS["Filesystem & Cloud-Lock Guard\n(14 tools: read, write, edit, safe-delete, cloud-lock safe)"]
Search["Search Engine\n(6 tools: explicit content search plus 5 async filename-search tools)"]
Proc["Process & REPL Sessions\n(9 tools: exec, background proc, interactive REPLs)"]
Repair["Repair & Format Converter\n(9 tools: JSON fix, Mojibake fix, duplicates, format convert)"]
Export["Export & Web Scraper\n(3 tools: Markdown->HTML/PDF, web_fetch)"]
Sys["System & Utilities\n(6 tools: OCR, ZIP, checksums, safe-mode, time)"]
end
Client -->|JSON-RPC| Stdio
Stdio --> Core
Core --> FS
Core --> Search
Core --> Proc
Core --> Repair
Core --> Export
Core --> Sys
Installation
Prerequisites
- Node.js 20 or higher
- npm
Option 1: Install from NPM
npm install -g ellmos-filecommander-mcp
Option 2: Install from Source
git clone https://github.com/ellmos-ai/ellmos-filecommander-mcp.git
cd ellmos-filecommander-mcp
npm install
npm run build
Configuration
Claude Desktop
Add to your claude_desktop_config.json:
Windows: %APPDATA%\Claude\claude_desktop_config.json
macOS: ~/Library/Application Support/Claude/claude_desktop_config.json
If installed globally via NPM:
{
"mcpServers": {
"filecommander": {
"command": "ellmos-filecommander"
}
}
}
If installed from source:
{
"mcpServers": {
"filecommander": {
"command": "node",
"args": ["/absolute/path/to/filecommander-mcp/dist/index.js"]
}
}
}
Restart Claude Desktop after saving.
Other MCP Clients
The server communicates via stdio transport. Point your MCP client to the dist/index.js entry point or the ellmos-filecommander binary.
Tools Overview
Filesystem Operations (14 tools)
| Tool | Description |
|---|---|
fc_read_file | Read file contents with optional line limit |
fc_read_multiple_files | Read up to 20 files in a single call |
fc_write_file | Write/create/append to files |
fc_edit_file | Line-based editing (replace, insert, delete lines) |
fc_str_replace | Replace a unique string in a file with context validation |
fc_list_directory | List directory contents (recursive, configurable depth) |
fc_create_directory | Create directories (including parents) |
fc_delete_file | Delete a file (permanent) |
fc_delete_directory | Delete a directory (with optional recursive flag) |
fc_safe_delete | Move to Recycle Bin / Trash (recoverable!) |
fc_move | Move or rename files and directories (cloud-lock safe) |
fc_copy | Copy files and directories |
fc_file_info | Get detailed file metadata (size, dates, type) |
fc_search_files | Synchronous file search with wildcard patterns |
Content Search (1 tool)
| Tool | Description |
|---|---|
fc_search_content | Read-only literal or regex search within an explicit ordered list of files, with case, context, global, and per-file limits |
fc_search_content never expands globs, traverses directories, or recursively discovers files. It accepts at most 50 explicit UTF-8 text files, skips binary and files over 10 MB, and returns deterministic JSON. Matches are limited to 200 globally and 100 per file, context to 10 lines, excerpts to 500 characters, and serialized output to 200,000 characters. Missing, cloud-only, permission, encoding, binary, and size failures are reported per file so readable files still produce results. Common secret formats are redacted from excerpts.
Async Search (5 tools)
| Tool | Description |
|---|---|
fc_start_search | Start a background search (returns immediately) |
fc_get_search_results | Retrieve results with pagination |
fc_stop_search | Cancel a running search |
fc_list_searches | List all active/completed searches |
fc_clear_search | Remove completed searches from memory |
Process Management (4 tools)
| Tool | Description |
|---|---|
fc_execute_command | Execute a shell command (blocking, with timeout) |
fc_start_process | Start a background process (non-blocking) |
fc_list_processes | List running system processes |
fc_kill_process | Terminate a process by PID or name |
Interactive Sessions (5 tools)
| Tool | Description |
|---|---|
fc_start_session | Start an interactive process (Python, Node, shell...) |
fc_read_output | Read session output |
fc_send_input | Send input to a running session |
fc_list_sessions | List all sessions |
fc_close_session | Terminate a session |
File Maintenance & Repair (9 tools)
| Tool | Description |
|---|---|
fc_fix_json | Repair broken JSON (BOM, trailing commas, comments, single quotes) |
fc_validate_json | Validate JSON with detailed error position and context |
fc_cleanup_file | Remove BOM, NUL bytes, trailing whitespace, normalize line endings |
fc_fix_encoding | Fix Mojibake / double-encoded UTF-8 (27+ character patterns) |
fc_folder_diff | Track directory changes with snapshots (new/modified/deleted) |
fc_batch_rename | Pattern-based batch renaming (prefix/suffix, replace, auto-detect) |
fc_convert_format | Convert between JSON, CSV, INI, YAML, TOML, XML, and TOON formats |
fc_detect_duplicates | Find duplicate files using SHA-256 hashing |
fc_checksum | File hashing (MD5, SHA-1, SHA-256, SHA-384, SHA-512) with optional compare |
Archive (1 tool)
| Tool | Description |
|---|---|
fc_archive | Create, extract, and list ZIP archives |
OCR (1 tool)
| Tool | Description |
|---|---|
fc_ocr | Extract text from images via tesseract.js (optional dependency) |
Cloud Sync (1 tool)
| Tool | Description |
|---|---|
fc_check_cloud_lock | Diagnose whether a path may be blocked by cloud sync filters (Windows) |
System (2 tools)
| Tool | Description |
|---|---|
fc_get_time | Get current system time with timezone info |
fc_set_safe_mode | Toggle safe mode: all deletes go through Recycle Bin / Trash |
Export (2 tools)
| Tool | Description |
|---|---|
fc_md_to_html | Markdown to standalone HTML with CSS styling (headers, code blocks, tables, nested lists, blockquotes, images, checkboxes) |
fc_md_to_pdf | Markdown to PDF via headless browser (Edge/Chrome). Falls back to HTML if no browser is available |
Web (1 tool)
| Tool | Description |
|---|---|
fc_web_fetch | Fetch a web page and return content by mode: extract (clean main text), raw (HTTP body), links, forms, or headers. Read-only network tool; SSRF guard blocks internal/private targets by default. |
Total: 47 tools
Comparison with Alternatives
| Feature | FileCommander | Desktop Commander | Official Filesystem |
|---|---|---|---|
| File read/write/copy/move | 14 tools | Yes | Yes |
| Safe delete (Recycle Bin) | Yes | No | No |
| Explicit multi-file content search | Yes | No | No |
| Async background search | 5 tools | No | No |
| Interactive sessions (REPL) | 5 tools | Yes | No |
| Process management | 4 tools | Yes | No |
| Shell command execution | Yes | Yes | No |
| String replace with validation | Yes | Yes | No |
| Line-based file editing | Yes | No | No |
| JSON repair & validation | 2 tools | No | No |
| Encoding fix (Mojibake) | Yes | No | No |
| Duplicate detection (SHA-256) | Yes | No | No |
| Folder diff / change tracking | Yes | No | No |
| Batch rename (pattern-based) | Yes | No | No |
| Format conversion (JSON/CSV/INI/YAML/TOML/XML/TOON) | Yes | No | No |
| ZIP archive (create/extract/list) | Yes | No | No |
| File checksums (MD5/SHA-1/SHA-256/SHA-384/SHA-512) | Yes | No | No |
| OCR (image to text) | Optional | No | No |
| Safety mode (delete โ Recycle Bin) | Yes | No | No |
| Path allowlist / sandboxing | No | No | Yes |
| Excel / PDF support | PDF (via browser) | Yes | No |
| HTTP transport | No | No | No |
| Markdown to HTML/PDF export | Yes | No | No |
| Total tools | 47 | ~15 | ~11 |
| Servers needed | 1 | 1 | + extra for processes |
Key differentiators:
- Only MCP server with recoverable delete (Recycle Bin / Trash)
- Only MCP server with async background search with pagination
- Built-in JSON repair, encoding fix, and duplicate detection
- Only MCP server with cloud-lock-safe file operations (automatic copy+delete fallback)
- Most comprehensive single-server solution (47 tools)
- Built-in safety mode to prevent accidental permanent deletion
Tool Prefix
All tools use the fc_ prefix (FileCommander) to avoid conflicts with other MCP servers.
Discoverability
FileCommander is designed to be discoverable by both people and AI agents:
package.jsonexposes the officialmcpName(io.github.ellmos-ai/ellmos-filecommander-mcp) and MCP-specific npm keywords.server.jsonfollows the official MCP Registry schema and points to the npm package.glama.jsonprovides MCP-directory metadata for Glama-compatible indexes.llms.txtgives compact context for LLMs, agent catalogs, and documentation crawlers.
Primary search terms: ellmos-filecommander-mcp, FileCommander MCP, filesystem MCP server, multi-file content search MCP, safe delete MCP, async file search MCP, process management MCP, Markdown PDF MCP.
External discovery notes: npm and jsDelivr may show the previously published metadata until version 1.10.0 is released. LobeHub indexes the GitHub repo as an MCP server. Use the package description and this README as the canonical 47-tool source for the current repository.
Security
This server has full filesystem access with the running user's permissions.
See SECURITY.md for detailed security information and recommendations.
Key points:
fc_execute_commandruns arbitrary shell commandsfc_delete_*tools perform permanent deletion by default (usefc_safe_deleteor enable safe mode viafc_set_safe_modeto route all deletes through Recycle Bin / Trash)- No built-in sandboxing - security is delegated to the MCP client layer
- Designed for local use via stdio transport only
Development
# Install dependencies
npm install
# Watch mode (auto-rebuild on changes)
npm run dev
# One-time build
npm run build
# Start the server
npm start
# Run test suite
npm test
Testing
The project includes 175 Vitest tests plus 69 standalone i18n checks (244 total) covering filesystem operations, bounded content search, format conversion, encoding repair, archive handling, duplicate detection, language packs, and more.
npm test # Run all tests
node test-i18n.mjs # Run standalone i18n checks
npx vitest run # Same as above
npx vitest --watch # Watch mode
Tests are verified on Windows, macOS, and Linux.
Pushes and pull requests run CI on Node.js 20, 22, and 24 with npm ci, TypeScript build, Vitest, and an npm package dry-run.
See CONTRIBUTING.md for contribution guidelines.
Changelog
See CHANGELOG.md for the full version history.
License
MIT - Lukas Geiger (ellmos-ai)
History
This project was originally developed as BACH FileCommander (bach-filecommander-mcp). It has been renamed to ellmos FileCommander (ellmos-filecommander-mcp) as part of the ellmos-ai organization.
The legacy package name bach-filecommander-mcp is deprecated. Please use ellmos-filecommander-mcp instead:
npm uninstall -g bach-filecommander-mcp
npm install -g ellmos-filecommander-mcp
ellmos-ai Ecosystem
This MCP server is part of the ellmos-ai ecosystem โ AI infrastructure, MCP servers, and intelligent tools.
MCP Server Family
| Server | Tools | Focus | npm |
|---|---|---|---|
| FileCommander | 47 | Filesystem, content search, process management, interactive sessions, cloud-lock-safe operations | ellmos-filecommander-mcp |
| CodeCommander | 22 | Code analysis, JSON repair, imports, diffs, regex | ellmos-codecommander-mcp |
| Clatcher | 12 | File repair, format conversion, batch operations | ellmos-clatcher-mcp |
| n8n Manager | 18 | n8n workflow management via AI assistants | n8n-manager-mcp |
| ControlCenter | 20 | MCP stack discovery, profile management, control plane | ellmos-controlcenter-mcp |
| Homebase | 45 | Local-first LLM memory, knowledge, state, routing, swarm orchestration | ellmos-homebase-mcp (alpha) |
| ServerCommander | 8 | Server operations: health checks, log analysis, deploy dry-runs, mail diagnostics | ellmos-servercommander-mcp (alpha) |
| Blender Use | 3 | Headless Blender asset QA and FBX reimport verification | ellmos-blender-use-mcp (alpha) |
| Open Compute | 10 | Model-agnostic computer use: capture, safety-gated actions, Windows UIA | open-compute-mcp (alpha) |
AI Infrastructure
| Project | Description |
|---|---|
| BACH | Local-first text-based OS for LLM agents โ 113+ handlers, 550+ tools, SQLite memory |
| open-compute | Model-agnostic computer-use core powering Open Compute MCP |
| clutch | Provider-neutral LLM orchestration with auto-routing and budget tracking |
| rinnsal | Lightweight agent memory, connectors, and automation infrastructure |
| ellmos-stack | Self-hosted AI research stack (Ollama + n8n + Rinnsal + KnowledgeDigest) |
| MarbleRun | Autonomous agent chain framework for Claude Code |
| gardener | Minimalist database-driven LLM OS prototype (4 functions, 1 table) |
| ellmos-tests | Testing framework for LLM operating systems (7 dimensions) |
Desktop Software
Our partner organization open-bricks bundles AI-native desktop applications โ a modern, open-source software suite built for the age of AI. Categories include file management, document tools, developer utilities, and more.
Haftung / Liability
Dieses Projekt ist eine unentgeltliche Open-Source-Schenkung im Sinne der ยงยง 516 ff. BGB. Die Haftung des Urhebers ist gemรคร ยง 521 BGB auf Vorsatz und grobe Fahrlรคssigkeit beschrรคnkt. Ergรคnzend gilt der Haftungsausschluss der MIT-Lizenz.
Nutzung auf eigenes Risiko. Keine Wartungszusage, keine Verfรผgbarkeitsgarantie, keine Gewรคhr fรผr Fehlerfreiheit oder Eignung fรผr einen bestimmten Zweck.
This project is an unpaid open-source donation. Liability is limited to intent and gross negligence (ยง 521 German Civil Code). The MIT license disclaimer also applies. Use at your own risk. No warranty, no maintenance guarantee, no fitness-for-purpose assumed.