Back to Browse

PLwC MCP Server

Developer ToolsUse Caution4.2MCP RegistryLocal
Free

Server data from the Official MCP Registry

Governed local MCP gateway for workspace, sandbox, document and profile operations.

About

Governed local MCP gateway for workspace, sandbox, document and profile operations.

Security Report

4.2
Use Caution4.2High Risk

PLwC is a policy-controlled MCP gateway with thoughtfully designed security architecture, including path traversal protections, sandboxing, and governance controls. However, the codebase is extremely large and complex, making comprehensive analysis challenging. Several moderate concerns exist: file operations accept user-controlled paths that must be validated by the adapter layer (defense-in-depth risk if validation fails), environment variable access is present without clear scoping documentation, and the audit system relies on external logging which could fail silently. The sandboxed execution design is sound, but dependencies like fastembed and qdrant-client are not pinned in pyproject.toml, creating supply chain risk. Despite these concerns, the overall architecture demonstrates good security practices appropriate for a governance-focused tool. Supply chain analysis found 3 known vulnerabilities in dependencies (0 critical, 3 high severity).

4 files analyzed · 11 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

File System Read

Reads files on your machine. Normal for tools that analyze or process local data.

File System Write

Writes or modifies files on your machine. Check that this is expected for the tool.

HTTP Network Access

Connects to external APIs or services over the internet.

env_vars

Check that this permission is expected for this type of plugin.

Shell Command Execution

Runs commands on your machine. Be cautious — only use if you trust this plugin.

process_spawn

Check that this permission is expected for this type of plugin.

system_info

Check that this permission is expected for this type of plugin.

How to Install

Add this to your MCP configuration file:

{
  "mcpServers": {
    "io-github-mhoedt-ai-plwc-gateway": {
      "args": [
        "plwc-gateway"
      ],
      "command": "uvx"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

PLwC — Personality Layer with Conscience

PLwC is a local, model-independent governance gateway for AI tool access, persistent context and controlled memory. It is not the agent and it is not the language model. It is the independent control layer between the AI host, the model and local tools.

AI host / model
       |
       v
PLwC governance gateway
       |
       v
tools, files, profiles, memory and sandbox

PLwC exposes one visible MCP server, routes all capabilities through policy and governance checks, and provides workspace, document, sandbox, profile, reflection and audit-oriented controls. The gateway is designed for MCP-capable hosts in general. Claude Desktop is the current primary packaged and smoke-tested Open Beta route, but the boundary remains useful when a host, such as ChatGPT Work, Claude or another MCP client, also offers its own file access or agent features.

Status

  • Current status: Open Beta, based on v0.2.0-rc18.dev9.
  • This repository is the privacy-filtered public Open Beta snapshot. Private development history, local evidence, real profiles and workspace data are intentionally not included.
  • v0.2.0-rc18.dev9 combines PR-005 privacy-filtered packaging with RC18-ALIAS-001: reflection marker/trust inputs are English-first while preserving PBA2 canonical storage.
  • Readiness audit result: RC_READY_WITH_NOTES.
  • This is not a final public release.
  • The latest package-, Desktop- and Odysseus-smoked open beta package is v0.2.0-rc18.dev9 with verdict PASS.
  • The packaged MCPB is not signed.

PLwC is not production-certified. It is local infrastructure under active development.

What PLwC is - and what it is not

PLwC is:

  • an MCP gateway, not its own agent;
  • a local governance boundary between model requests and tool execution;
  • model- and host-independent policy for MCP-capable hosts;
  • controlled memory, profile and persona management through explicit profile, reflection and Governor flows;
  • a single public MCP boundary named plwc-gateway.

PLwC is not:

  • a standalone AI platform;
  • a desktop agent;
  • the language model or a replacement for the user's chosen AI host;
  • a full proxy for all model traffic;
  • protection for data that a user or host sends directly to a cloud model outside PLwC;
  • permission to expose raw PLfC/PBA or Desktop Commander MCP servers beside the gateway.

What PLwC does

  • Exposes exactly one visible MCP server: plwc-gateway.
  • Provides exactly eight public facade tools (see below).
  • Controls workspace operations (read / write / search / move / rename / exact replace / batch read).
  • Creates and reads DOCX, XLSX, PPTX and PDF artifacts.
  • Inspects, extracts, merges, splits and rotates PDFs.
  • Inspects, extracts and creates ZIP archives with bounded safety limits.
  • Reads workspace raster images and returns them as MCP image content blocks (PNG, JPEG, WEBP, first-frame GIF).
  • Runs sandboxed Python and Shell snippets through Docker, with no silent fallback to a host shell.
  • Manages profiles, reflection writes, memory and persona governance, and Governor plan / apply flows including reflection_condensation with plan_id apply.
  • Blocks protected profile and governance paths from direct workspace writes.
  • Emits structured local audit events for high-risk operations.

Public tools

PLwC v0.2 exposes exactly these eight public facade tools:

ToolWhat it does
plwc_statusReports gateway, sandbox, and profile runtime state; generates a ready-to-paste Claude Desktop config snippet.
plwc_describeReturns a self-description of all supported tools, operations, plan types, and capability boundaries — the single source of truth for what PLwC can do in the current session.
plwc_profileLoads, inspects, and activates profiles; compiles the configured profile into the active session context.
plwc_reflectionWrites governed reflection entries to reflection.md with semantic validation — rejects pure technical logs and requires a reusable user, collaboration, or system insight.
plwc_governorTwo-stage plan / apply flow for promoting insights to memory.md or PERSONA.md, condensing stale reflection candidates, and creating new profiles — all requiring explicit confirmation before any write.
plwc_sandbox_runExecutes Python or Shell snippets in an isolated Docker container with no network access and no silent fallback to a host shell.
plwc_workspace_operationReads, writes, lists, searches, copies, moves, and renames files within configured workspace roots; includes binary and base64 paths and an exact-replace mode. Delete is not public.
plwc_document_operationCreates and manipulates DOCX, XLSX, PPTX, and PDF files; inspects, merges, splits, rotates, and extracts text from PDFs; handles ZIP archives; reads workspace images as MCP image content blocks.

The 19 individual public tool names from earlier scaffolds (plwc_compile_profile, plwc_write_workspace_file, plwc_governor_plan, plwc_write_reflection, ...) are no longer public in v0.2. Their behavior is reachable through the eight facade tools above via operation / scope / lang dispatch parameters.

Document capabilities

  • DOCX Creation V2 (layouts, styles, runs, lists, tables, images, page breaks).
  • XLSX Creation V2 (multi-sheet, formatting, formulas-as-written (not executed), freeze panes, boolean auto_filter, merges).
  • PPTX Creation V2 (five slide layouts, content elements, tables, images, slide sizes, plain-text speaker notes).
  • PDF Creation V2 (layout-PDF builder with A4/A5/landscape/custom page sizes, headings, paragraph runs, bullet/numbered lists, tables, images, explicit page breaks).
  • read_image (governed workspace image reads).
  • ZIP create / inspect / extract.
  • PDF inspect / extract / merge / split / rotate / extract_pdf_text.

Security model

  • One visible gateway server. No bypass MCP servers are exposed.
  • Protected profile and governance files (PERSONA.md, memory.md, reflection.md, governance/config.yaml, ...) cannot be edited through workspace operations.
  • Workspace operations are scoped to configured roots; parent traversal, absolute host paths, UNC paths and protected segments are rejected.
  • Docker-backed Python and Shell sandbox; no silent host-shell fallback.
  • Fail-closed behavior on missing engines, missing Docker image, or policy denial.
  • No external URL fetching for document assets (PDF V2, PPTX V2 and DOCX V2 image paths must be workspace-relative).

Known limitations

The following are intentionally not implemented in v0.2:

  • No OCR.
  • No PDF redaction.
  • No digital signing.
  • No form filling or form creation.
  • No PDF/A claim.
  • No LibreOffice or Pandoc conversion.
  • No macro execution (no .docm / .xlsm / .pptm generation).
  • No external URL fetching, no network access at runtime.
  • No JavaScript in PDFs.
  • No HTML/CSS rendering pipeline.
  • No final-release claim yet.

Installation

For step-by-step installation, see docs/QUICKSTART_CLAUDE_DESKTOP.md.

For full installation context, prerequisites and configuration options, including local GPT and Odysseus stdio setup plus hosted ChatGPT web/custom-app status, see docs/INSTALLATION.md.

Documentation

Project Website and Contact

Use GitHub Issues for reproducible bugs and feature requests. For security-sensitive reports, contact info@plwc.de privately. Do not include secrets, real profile content, private paths or other sensitive details in public issues.

Support

If PLwC helps you, you can support development via Ko-fi:

https://ko-fi.com/mhoedtai

Ko-fi support is voluntary and not required to use PLwC.

License

PLwC is licensed under the Apache License 2.0. See LICENSE.

Reviews

No reviews yet

Be the first to review this server!