Mcp-worker
Mcp-worker lets ChatGPT operate one policy-controlled Windows machine through a public MCP server and an outbound-only worker connection.
The repository contains three parts:
src/remote: the Streamable HTTP MCP server and durable relay APIsrc/worker: the outbound worker client and exact-action approval bridgepackages/windows-worker: the complete Windows tool, policy, audit, desktop, clipboard, process, transfer, admin, and .NET helper implementation
The remote server advertises the complete 31-tool catalog even when the worker is offline. Tool execution remains subject to the worker's local policy. Prompt decisions use MCP elicitation and a short-lived ticket bound to the exact request.
What works
- OAuth-protected
/mcpand separately authenticated worker endpoints - SQLite jobs, leases, expiry, deduplicated results, cancellation, and indeterminate mutation handling
- file CRUD and search, process execution and interactive sessions, desktop and clipboard tools
- AppContainer execution through the included .NET 10 helper
- file import and chunked file export through expiring MCP resources
- local SQLite audit records with relay correlation IDs
- current-user scheduled-task scripts with hidden execution, restart behavior, and bounded logs
- Linux relay tests, Windows worker tests, and native-helper builds in CI
Local verification
npm install
npm run build
npm test
npm run test:windows
npm run native:build
Copy .env.example into the environment of each process before starting it. Run the remote service with npm run remote and the Windows client with npm run worker.
Public deployment still requires choices that cannot be inferred from this repository: domain and DNS control, ingress, administrator support, OAuth registration, the service account, persistent directories, backup and log policy, alerting, and size limits. See docs/operations.md.