Skip to content

Blog

Desktop Commander MCP setup: files and terminal access

Work with files or run programs as well? Choose the scope you need and check the first connection against a dedicated test folder.

Published on · by tracevero · Reading time 4 minutes (673 words)

Desktop Commander combines file operations with terminal and process tools. Start with one small task: read a prepared text file and independently compare its contents. Create a separate folder containing copies of unimportant data. Record its absolute path and a short passage before connecting. This gives you an expectation that was not produced by the connection you are trying to check.

Filesystem or Desktop Commander?

Choose by the task
Your taskStarting pointCheck first
Read files in an allowed directoryFilesystem guideAllowed paths and file permissions
Edit files and operate processesDesktop CommanderOperating-system permissions and execution environment
Click pages and inspect formsPlaywright guideBrowser profile and signed-in accounts

The Filesystem guide covers scoped file access. For websites, follow the Playwright guide. Desktop Commander suits tasks that also need terminal processes. Extra functions bring additional decisions about permissions and execution context; they do not replace an explicit task. Decide which result you intend to inspect before choosing the connection.

Local setup in VS Code

Put this example in the workspace .vscode/mcp.json. If that file already contains connections, add the entry inside servers without replacing the others. Node.js and npx must be reachable from the environment that launches the editor process. Starting the server downloads the published package. The @latest tag can change; record the version you tested before relying on a repeatable workflow.

{
  "servers": {
    "desktop-commander": {
      "type": "stdio",
      "command": "npx",
      "args": [
        "-y",
        "@wonderwhy-er/desktop-commander@latest"
      ]
    }
  }
}

Start the connection and inspect its available tools first. A running process does not establish that a file was read successfully. If the editor cannot find npx, use the troubleshooting navigator and inspect the exact error and execution environment. The client directory explains configuration formats for other programs. Keep the process command and arguments separate rather than pasting a whole shell command into one field.

Separate directory settings from terminal permissions

The project describes allowedDirectories and its command blocklist as safeguards against accidental actions. They are not a sandbox: terminal commands can access files outside allowed directories. If the rest of the machine must be inaccessible, use an appropriately isolated environment such as a container or virtual machine. The folders mounted into it and their permissions still determine which data the process can reach.

A small first file check 1. Folder Choose test copies 2. File Read known text 3. Check Match path and text
Suggested checks for your environment; no account test was performed.
  1. Create an unimportant text file in the test folder and note a distinctive sentence. Keep credentials out of this test data.

  2. Inspect the active configuration and execution location. Request only this specific file, without a broad cleanup or editing task.

  3. Compare the returned path and text with your note. Check whether the response was truncated before treating missing text as a file problem.

  4. Try later edits on a copy only. Open it independently and compare the change. Test terminal operations as a separate step with their own expected result.

Expand from a checked result

For recurring work, define which files may be read, which may be changed and which processes may be started. A request to “clean up the project” leaves those boundaries open. Specify a folder, an expected output and a result you can inspect. Use the permissions planner to separate these decisions. Find other implementations through the registry search, or return to the app guides for a different task.

Is Desktop Commander only a file reader?
No. The project also exposes file editing, terminal and process functions.
Does allowedDirectories constrain every terminal command?
No. Its security documentation explicitly says directory settings do not sandbox terminal execution.
Does this local setup require a remote endpoint?
The stdio example launches a local process. An additional HTTP URL does not belong in this entry.
Why record the version after checking it?
The @latest tag may resolve to another release later. A recorded version makes changes easier to investigate.

Provider sources checked on 2 October 2026. Test procedures are editorial suggestions.

  1. Desktop Commander: Installation and configuration
    Show retrieval commandcurl -s https://github.com/wonderwhy-er/DesktopCommanderMCP
  2. Desktop Commander: Security model
    Show retrieval commandcurl -s https://github.com/wonderwhy-er/DesktopCommanderMCP/blob/main/SECURITY.md

Put it into practice

All posts

tracevero · https://tracevero.com/blog/desktop-commander-mcp-setup