Local-first MCP runtime for coding agents with safe workspace access, AST/LSP navigation, and Git.
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β or use 1-click editor setup below.
One-click editor setup isnβt available for this listing yet β we donβt have a confirmed install command, and weβd rather show nothing than point your editor at the wrong package or host. Follow the projectβs own setup instructions, linked above.
Local-first MCP runtime for coding agents β safer workspace access without an unrestricted shell
Bounded filesystem Β· content-preconditioned writes Β· Tree-Sitter AST search Β· LSP navigation Β· Git tooling
my-pi is a deterministic local coding capability runtime exposed through the official Model Context Protocol (MCP). It gives MCP-capable coding agents controlled access to a real workspace through explicit workspace authority, bounded reads, guarded writes, structural search, language-server intelligence, and Git operations.
It is aimed at developers who want agentic coding tools to understand and modify code without handing the agent a general-purpose shell or silently granting the current working directory.
trusted elevation.Release channel: Alpha. The npm badge above is authoritative for the currently published package version. This repository may contain a newer release candidate before publication completes. Suitable for evaluation and controlled local development; review the security model before enabling the trusted profile.
Requires Node.js >=24.0.0 (Node 24 LTS is the normative runtime).
The server starts read-only. For a workspace you explicitly trust:
Or inspect a host configuration without a global install:
Generate host-specific configuration snippets:
Starting without --workspace or MY_PI_WORKSPACE_ROOT fails closed. Use --allow-cwd only when granting the current directory is intentional.
The published npm package is the stable MCP server. The coordination daemon and local UI are private workspace packages used by the experimental source build; build the repository before using those components.
| Area | Tools | Purpose |
|---|---|---|
| Filesystem | fs_read, fs_write, fs_patch, fs_stat | Bounded reads, guarded writes/patches, metadata |
| Search & workspace | search, workspace_info | Repository exploration and authoritative workspace state |
| AST & LSP | ast_search, lsp_status, lsp_symbols, lsp_navigate, lsp_diagnostics | Structural and semantic code intelligence |
| Git | vcs_status, vcs_diff | Repository status and bounded/filtered diffs |
| Capability | Behavior |
|---|---|
| Content-preconditioned mutation | File updates verify raw SHA-256 fingerprints and reject stale guarded overwrites |
| Pre-read sensitive-path policy | Sensitive paths such as .env*, .aws/, .ssh/, and *.key are denied before content is allocated to model context |
| Explicit security profiles | Default is read-only; mutation and LSP process startup require explicit elevation |
| Encoding/mode fidelity | File replacement preserves relevant encoding, line endings, BOM, and POSIX executable mode behavior |
| Cancellation | Long-running Git/search/LSP subprocess work supports cancellation and cleanup |
The stable public claim is the 13-tool MCP capability surface. The repository also contains two opt-in candidates that never change the default mode:
Prerequisites for repository development:
v24.0.0+ (Node 24 LTS normative; exact-minimum 24.0.0 lane is qualified in CI)v11.2.2+The configured CI matrix covers Ubuntu, Windows, and macOS lanes. See the live workflow badges above for current status rather than relying on static claims in this document.
| Contract | Document | Enforced by |
|---|---|---|
| Runtime compatibility (engines/types/CI parity) | docs/RUNTIME_CONTRACT.md | node scripts/check-runtime-contract.mjs |
| Test/invariant coverage | docs/TEST_CONTRACT.md | pnpm check:contract (scripts/verify-test-contract.mjs) |
| Merge/release governance | docs/GITHUB_GOVERNANCE.md | ci-required + CodeQL required checks |
| Worktree identity isolation | packages/code-state/IDENTITY.md | ownership guard + invariant suites |
The repository contains deterministic synthetic benchmarks for MCP stdio overhead, search/traversal throughput, memory sampling, runtime boundaries, coordination behavior, impact routing, evaluation feedback, and local reliability. Benchmark outputs are candidate evidence; performance claims should be interpreted alongside their qualification criteria and runner variance.
The self-hosted program keeps implementation, measurement, and promotion as separate decisions:
The current evidence files under evidence/ are candidate-bound records, not a
release or promotion claim. A passing test, a qualified sample, or an accepted
individual evidence record does not by itself open PN11. Use the read-only
promotion verifier as the authority:
No reviews yet β be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/my-pi)<a href="https://allmcps.com/mcp/my-pi"><img src="https://allmcps.com/api/badge/my-pi?style=directory" alt="My Pi on AllMCPs" /></a>