The full upstream README, mirrored here for reference. Install config, tool schemas, adoption signals, and an original overview live on the Wyrd listing page.
An MCP server that exposes one folder of Markdown to an AI client, read-only.
Point Claude Code, Codex, Cursor, ChatGPT or Claude Desktop at a folder of notes and let it read them. Wyrd serves exactly the folder you grant and refuses everything else, and it tells you plainly what that means before you grant anything.
If the folder happens to be a Mage vault — one organised into Arc/ and Mage/ layers — wyrd
notices and says which layers it found. If it is an ordinary folder of notes, it works the same
way; vault structure is a detected bonus, never a requirement.
Node 20 or newer.
Wyrd refuses to start until you grant it a folder. Grant one on the command line or in the environment:
Claude Code — save as wyrd.mcp.json and pass --mcp-config wyrd.mcp.json:
Codex — MCP servers arrive as config overrides:
Other clients take a command and args in their own MCP configuration; the shape is the same.
Wyrd serves the folder you name, read-only. It does not serve anything above it.
⚠ EVERY file inside that folder can be read, of any type, including hidden files and directories
such as .git, .env and .ssh. There is no extension filter and no ignore-file support. Grant a
subfolder containing only what you mean to share.
A path that resolves outside the granted folder is refused, and the refusal names the rule that fired rather than pretending the file is absent.
A containment claim without its limits would be false, so:
This list is what is known, not a proof that nothing else exists. The limits were measured on Windows; behaviour on macOS and Linux is reasoned but unmeasured, and the package declares no OS restriction.
Nothing, by wyrd. It is a local stdio server: it reads files and hands them to the client that launched it. It opens no network connection and phones nothing home.
⚠ What your AI client does with the content is between you and that client. Wyrd cannot see or control that, and no server on this side of the protocol can.
⚠ npm test needs the Windows symlink privilege (Developer Mode, or an elevated shell) because
most fence arms build link fixtures. Without it the suite refuses to run rather than skipping, so
a green never means "the arms that could run, ran."
npm run test:portable runs the arms that need no privilege and states its own denominator — how
many ran, how many were held back, and which. A green there is not a green fence; it is a partial run
that says so.
MIT. See LICENSE.
wyrd — Old English, "that which has become": the accumulated weight of what has already happened, constraining what can happen next.