What it can do: Desktop Commander
MCP server · wonderwhy-er
What Desktop Commander declares, asks for and runs, according to the marketplaces we read. Runs on your machine: the AI tool starts this npm package locally: @wonderwhy-er/desktop-commander. Tools it declares: 26. As of our marketplace pass on 2026-10-11.
This is not a security audit. We list what the marketplaces publish about this plugin: what it declares, what it asks for and what it runs. We do not run or inspect its code, and a verified mark is the marketplace's statement, not ours.
Where it runs
- Runs on your machine: the AI tool starts this npm package locally:
@wonderwhy-er/desktop-commander - Runs on your machine, in a container started from this image:
mcp/desktop-commander
What it declares
Tools it declares: 26. As declared on: Docker MCP Catalog.
create_directoryedit_blockforce_terminateget_configget_file_infoget_more_search_resultsget_promptsget_recent_tool_callsget_usage_statsgive_feedback_to_desktop_commanderinteract_with_processkill_process
Show the remaining 14
list_directorylist_processeslist_searcheslist_sessionsmove_fileread_fileread_multiple_filesread_process_outputset_config_valuestart_processstart_searchstop_searchwrite_filewrite_pdf
Prompts and resources: the marketplaces we read do not publish them.
What it asks for
None of the marketplaces we read lists environment variables for it.
Names only: we keep no values, examples or descriptions of these variables. OAuth scopes and install-time settings are not published by the marketplaces we read.
What it runs besides MCP
Skills: 6 As declared on: Claude Code: claude-plugins-official.
ai-tools-setupcomputer-health-checkdesktop-commander-overviewknowledge-baseobsidian-vaultterminal
Who answers for it
wonderwhy-er
- No marketplace we read marks it or its publisher as verified.
- License: MIT.
- The repository github.com/wonderwhy-er/desktopcommandermcp belongs to the account the publisher is listed under on Official MCP Registry.
How it has changed
Its tools, settings, hooks and composition have not changed since we started watching it.
In context
- Median number of secrets an MCP server asks for on the marketplaces we read: 0.0. This one asks for: 0.
- Share of MCP servers that run on a remote server: 63%.
Where it is published and how its figures have moved
Data comes from the Official MCP Registry (registry.modelcontextprotocol.io), CC0 1.0. Data comes from the public marketplace file https://github.com/anthropics/claude-plugins-official/blob/HEAD/.claude-plugin/marketplace.json. Data comes from the Docker MCP Catalog (desktop.docker.com/mcp/catalog) and Docker Hub. Data comes from the public marketplace file https://github.com/anthropics/knowledge-work-plugins/blob/HEAD/.claude-plugin/marketplace.json. Figures come from our own regular passes over the marketplaces, last read on . We publish no contact details for plugin publishers.