Desktop Commander MCP setup: files and terminal access
Work with files or run programs as well? Choose the scope you need and check the first connection against a dedicated test folder.
Desktop Commander combines file operations with terminal and process tools. Start with one small task: read a prepared text file and independently compare its contents. Create a separate folder containing copies of unimportant data. Record its absolute path and a short passage before connecting. This gives you an expectation that was not produced by the connection you are trying to check.
Filesystem or Desktop Commander?
| Your task | Starting point | Check first |
|---|---|---|
| Read files in an allowed directory | Filesystem guide | Allowed paths and file permissions |
| Edit files and operate processes | Desktop Commander | Operating-system permissions and execution environment |
| Click pages and inspect forms | Playwright guide | Browser profile and signed-in accounts |
The Filesystem guide covers scoped file access. For websites, follow the Playwright guide. Desktop Commander suits tasks that also need terminal processes. Extra functions bring additional decisions about permissions and execution context; they do not replace an explicit task. Decide which result you intend to inspect before choosing the connection.
Local setup in VS Code
Put this example in the workspace .vscode/mcp.json. If that file already contains connections, add the entry inside servers without replacing the others. Node.js and npx must be reachable from the environment that launches the editor process. Starting the server downloads the published package. The @latest tag can change; record the version you tested before relying on a repeatable workflow.
{
"servers": {
"desktop-commander": {
"type": "stdio",
"command": "npx",
"args": [
"-y",
"@wonderwhy-er/desktop-commander@latest"
]
}
}
}
Start the connection and inspect its available tools first. A running process does not establish that a file was read successfully. If the editor cannot find npx, use the troubleshooting navigator and inspect the exact error and execution environment. The client directory explains configuration formats for other programs. Keep the process command and arguments separate rather than pasting a whole shell command into one field.
Separate directory settings from terminal permissions
The project describes allowedDirectories and its command blocklist as safeguards against accidental actions. They are not a sandbox: terminal commands can access files outside allowed directories. If the rest of the machine must be inaccessible, use an appropriately isolated environment such as a container or virtual machine. The folders mounted into it and their permissions still determine which data the process can reach.
Create an unimportant text file in the test folder and note a distinctive sentence. Keep credentials out of this test data.
Inspect the active configuration and execution location. Request only this specific file, without a broad cleanup or editing task.
Compare the returned path and text with your note. Check whether the response was truncated before treating missing text as a file problem.
Try later edits on a copy only. Open it independently and compare the change. Test terminal operations as a separate step with their own expected result.
Expand from a checked result
For recurring work, define which files may be read, which may be changed and which processes may be started. A request to “clean up the project” leaves those boundaries open. Specify a folder, an expected output and a result you can inspect. Use the permissions planner to separate these decisions. Find other implementations through the registry search, or return to the app guides for a different task.
- Is Desktop Commander only a file reader?
- No. The project also exposes file editing, terminal and process functions.
- Does allowedDirectories constrain every terminal command?
- No. Its security documentation explicitly says directory settings do not sandbox terminal execution.
- Does this local setup require a remote endpoint?
- The stdio example launches a local process. An additional HTTP URL does not belong in this entry.
- Why record the version after checking it?
- The @latest tag may resolve to another release later. A recorded version makes changes easier to investigate.
Provider sources checked on 2 October 2026. Test procedures are editorial suggestions.
- Desktop Commander: Installation and configuration
Show retrieval command
curl -s https://github.com/wonderwhy-er/DesktopCommanderMCP - Desktop Commander: Security model
Show retrieval command
curl -s https://github.com/wonderwhy-er/DesktopCommanderMCP/blob/main/SECURITY.md