{"_id":"@alan512/localspace","_rev":"3-9ecb11c64d7d147f8fa4438881f48d77","name":"@alan512/localspace","dist-tags":{"latest":"1.0.6"},"versions":{"1.0.4":{"name":"@alan512/localspace","version":"1.0.4","keywords":["mcp","chatgpt","coding-agent","local-workspace","developer-tools"],"author":{"name":"Alan-512"},"license":"MIT","_id":"@alan512/localspace@1.0.4","maintainers":[{"name":"sam1478963","email":"alan182@163.com"}],"homepage":"https://github.com/Alan-512/localspace#readme","bugs":{"url":"https://github.com/Alan-512/localspace/issues"},"bin":{"localspace":"dist/cli.js"},"dist":{"shasum":"f2efec3cf2d783160bb140dca453859e8498ecdb","tarball":"https://registry.npmjs.org/@alan512/localspace/-/localspace-1.0.4.tgz","fileCount":367,"integrity":"sha512-VcaaBc8AwB1vhasiQrmpMQ8rrQOqlQqGqyQ7aHfaC2LwJHdzbnLr+2f2/aFVHN23Nn/XsG/eIBiuAnE3s3Z6qg==","signatures":[{"sig":"MEUCIC8MehS0pnI3kQ82yrG9rAcs2/vzg5suSO7K484AJLJcAiEAjSurC2NnoPsjZcBefPNpPRdzQRIJPFBz/py2TVN6llw=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":12408491},"main":"dist/server.js","type":"module","engines":{"node":">=22.19 <27"},"gitHead":"74f80aeba544e247b9ae695302f232b583898ed8","scripts":{"dev":"node scripts/dev-server.mjs","test":"tsx src/config.test.ts && tsx src/ui/card-types.test.ts && tsx src/ui/patch-display.test.ts && tsx src/apply-patch.test.ts && tsx src/project-map.test.ts && tsx src/symbols.test.ts && tsx src/code-navigation.test.ts && tsx src/code-map.test.ts && tsx src/entrypoints.test.ts && tsx src/diagnostics.test.ts && tsx src/server-output-schema.test.ts && tsx src/command-safety.test.ts && tsx src/command-approval.test.ts && tsx src/sensitive-paths.test.ts && tsx src/audit-log.test.ts && tsx src/workflow-tools.test.ts && tsx src/task-summary.test.ts && tsx src/final-report.test.ts && tsx src/git-changes.test.ts && tsx src/git-tools.test.ts && tsx src/process-platform.test.ts && tsx src/process-sessions.test.ts && tsx src/roots.test.ts && tsx src/skills.test.ts && tsx src/workspaces.test.ts && tsx src/review-checkpoints.test.ts && tsx src/oauth-store.test.ts && tsx src/cli.test.ts","build":"npm run clean && npm run build:app && tsc -p tsconfig.build.json","clean":"node -e \"require('node:fs').rmSync('dist', { recursive: true, force: true })\"","start":"node dist/cli.js serve","build:app":"vite build","typecheck":"tsc -p tsconfig.json --noEmit","postinstall":"node scripts/fix-node-pty-permissions.mjs"},"_npmUser":{"name":"sam1478963","email":"alan182@163.com"},"overrides":{"ws":"8.21.0","undici":"8.5.0","protobufjs":"7.6.4"},"repository":{"url":"git+https://github.com/Alan-512/localspace.git","type":"git"},"_npmVersion":"11.5.2","description":"Expose a secure local coding workspace through an MCP server.","directories":{},"_nodeVersion":"24.3.0","dependencies":{"zod":"^4.4.3","diff":"^8.0.3","react":"^19.2.6","semver":"^7.8.4","express":"^5.2.1","react-dom":"^19.2.6","drizzle-orm":"^0.45.2","@pierre/diffs":"^1.2.5","@clack/prompts":"^1.5.1","better-sqlite3":"^12.10.0","@modelcontextprotocol/sdk":"^1.29.0","@modelcontextprotocol/ext-apps":"^1.7.2","@earendil-works/pi-coding-agent":"^0.80.1"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.22.3","vite":"^8.0.14","typescript":"^6.0.3","@types/node":"^25.9.1","@types/react":"^19.2.15","@types/semver":"^7.7.1","@types/express":"^5.0.6","@types/react-dom":"^19.2.3","@vitejs/plugin-react":"^6.0.2","@types/better-sqlite3":"^7.6.13"},"optionalDependencies":{"node-pty":"^1.1.0"},"_npmOperationalInternal":{"tmp":"tmp/localspace_1.0.4_1783162690195_0.631322987041838","host":"s3://npm-registry-packages-npm-production"}},"1.0.5":{"name":"@alan512/localspace","version":"1.0.5","keywords":["mcp","chatgpt","coding-agent","local-workspace","developer-tools"],"author":{"name":"Alan-512"},"license":"MIT","_id":"@alan512/localspace@1.0.5","maintainers":[{"name":"sam1478963","email":"alan182@163.com"}],"homepage":"https://github.com/Alan-512/localspace#readme","bugs":{"url":"https://github.com/Alan-512/localspace/issues"},"bin":{"localspace":"dist/cli.js"},"dist":{"shasum":"bcb89e05448a8ae09bf5c344e8f007f20d8a234a","tarball":"https://registry.npmjs.org/@alan512/localspace/-/localspace-1.0.5.tgz","fileCount":369,"integrity":"sha512-EmrGEGdLYw4ulEpJTSnp2b5r1Hqya5YtJU2ILLBYRjpss6JvlylbnJc+uQrxGSruMpeOGTuwQOSH8zGj5PhIng==","signatures":[{"sig":"MEUCIG7B+Ng4hQEpOPOU4hv0FK0gI/sMxQTRpjSTGRXCoPhMAiEA71WbWKVTIkTvRWXDfe/qPgNcwwHZOn4//KI4TOCpAfU=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":12426859},"main":"dist/server.js","type":"module","engines":{"node":">=22.19 <27"},"gitHead":"8d63e70f509559e660095a7dcd33a846b03767a8","scripts":{"dev":"node scripts/dev-server.mjs","test":"tsx src/config.test.ts && tsx src/ui/card-types.test.ts && tsx src/ui/patch-display.test.ts && tsx src/workspace-app-resource.test.ts && tsx src/apply-patch.test.ts && tsx src/project-map.test.ts && tsx src/symbols.test.ts && tsx src/code-navigation.test.ts && tsx src/code-map.test.ts && tsx src/entrypoints.test.ts && tsx src/diagnostics.test.ts && tsx src/server-output-schema.test.ts && tsx src/command-safety.test.ts && tsx src/command-approval.test.ts && tsx src/sensitive-paths.test.ts && tsx src/audit-log.test.ts && tsx src/workflow-tools.test.ts && tsx src/task-summary.test.ts && tsx src/final-report.test.ts && tsx src/git-changes.test.ts && tsx src/git-tools.test.ts && tsx src/process-platform.test.ts && tsx src/process-sessions.test.ts && tsx src/mcp-session-registry.test.ts && tsx src/mcp-server-restart.test.ts && tsx src/roots.test.ts && tsx src/skills.test.ts && tsx src/workspaces.test.ts && tsx src/review-checkpoints.test.ts && tsx src/oauth-store.test.ts && tsx src/cli.test.ts","build":"npm run clean && npm run build:app && tsc -p tsconfig.build.json","clean":"node -e \"require('node:fs').rmSync('dist', { recursive: true, force: true })\"","start":"node dist/cli.js serve","build:app":"vite build","typecheck":"tsc -p tsconfig.json --noEmit","postinstall":"node scripts/fix-node-pty-permissions.mjs"},"_npmUser":{"name":"sam1478963","email":"alan182@163.com"},"overrides":{"ws":"8.21.0","undici":"8.5.0","protobufjs":"7.6.4"},"repository":{"url":"git+https://github.com/Alan-512/localspace.git","type":"git"},"_npmVersion":"11.5.2","description":"Expose a secure local coding workspace through an MCP server.","directories":{},"_nodeVersion":"24.3.0","dependencies":{"zod":"^4.4.3","diff":"^8.0.3","react":"^19.2.6","semver":"^7.8.4","express":"^5.2.1","react-dom":"^19.2.6","drizzle-orm":"^0.45.2","@pierre/diffs":"^1.2.5","@clack/prompts":"^1.5.1","better-sqlite3":"^12.10.0","@modelcontextprotocol/sdk":"^1.29.0","@modelcontextprotocol/ext-apps":"^1.7.2","@earendil-works/pi-coding-agent":"^0.80.1"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.22.3","vite":"^8.0.14","typescript":"^6.0.3","@types/node":"^25.9.1","@types/react":"^19.2.15","@types/semver":"^7.7.1","@types/express":"^5.0.6","@types/react-dom":"^19.2.3","@vitejs/plugin-react":"^6.0.2","@types/better-sqlite3":"^7.6.13"},"optionalDependencies":{"node-pty":"^1.1.0"},"_npmOperationalInternal":{"tmp":"tmp/localspace_1.0.5_1784345341539_0.16000531591071643","host":"s3://npm-registry-packages-npm-production"}},"1.0.6":{"name":"@alan512/localspace","version":"1.0.6","description":"Expose a secure local coding workspace through an MCP server.","homepage":"https://github.com/Alan-512/localspace#readme","bugs":{"url":"https://github.com/Alan-512/localspace/issues"},"repository":{"type":"git","url":"git+https://github.com/Alan-512/localspace.git"},"type":"module","main":"dist/server.js","engines":{"node":">=22.19 <27"},"bin":{"localspace":"dist/cli.js"},"publishConfig":{"access":"public"},"scripts":{"clean":"node -e \"require('node:fs').rmSync('dist', { recursive: true, force: true })\"","build":"npm run clean && npm run build:app && tsc -p tsconfig.build.json","build:app":"vite build","dev":"node scripts/dev-server.mjs","postinstall":"node scripts/fix-node-pty-permissions.mjs","start":"node dist/cli.js serve","test":"tsx src/config.test.ts && tsx src/ui/card-types.test.ts && tsx src/ui/patch-display.test.ts && tsx src/workspace-app-resource.test.ts && tsx src/apply-patch.test.ts && tsx src/project-map.test.ts && tsx src/symbols.test.ts && tsx src/code-navigation.test.ts && tsx src/code-map.test.ts && tsx src/entrypoints.test.ts && tsx src/diagnostics.test.ts && tsx src/server-output-schema.test.ts && tsx src/command-safety.test.ts && tsx src/command-approval.test.ts && tsx src/sensitive-paths.test.ts && tsx src/audit-log.test.ts && tsx src/workflow-tools.test.ts && tsx src/task-summary.test.ts && tsx src/final-report.test.ts && tsx src/git-changes.test.ts && tsx src/git-tools.test.ts && tsx src/process-platform.test.ts && tsx src/process-sessions.test.ts && tsx src/mcp-session-registry.test.ts && tsx src/server-shutdown.test.ts && tsx src/mcp-server-restart.test.ts && tsx src/roots.test.ts && tsx src/skills.test.ts && tsx src/workspaces.test.ts && tsx src/review-checkpoints.test.ts && tsx src/oauth-store.test.ts && tsx src/cli.test.ts","typecheck":"tsc -p tsconfig.json --noEmit"},"keywords":["mcp","chatgpt","coding-agent","local-workspace","developer-tools"],"author":{"name":"Alan-512"},"license":"MIT","dependencies":{"@clack/prompts":"^1.5.1","@earendil-works/pi-coding-agent":"^0.80.1","@modelcontextprotocol/ext-apps":"^1.7.2","@modelcontextprotocol/sdk":"^1.29.0","@pierre/diffs":"^1.2.5","better-sqlite3":"^12.10.0","diff":"^8.0.3","drizzle-orm":"^0.45.2","express":"^5.2.1","react":"^19.2.6","react-dom":"^19.2.6","semver":"^7.8.4","zod":"^4.4.3"},"devDependencies":{"@types/better-sqlite3":"^7.6.13","@types/express":"^5.0.6","@types/node":"^25.9.1","@types/react":"^19.2.15","@types/react-dom":"^19.2.3","@types/semver":"^7.7.1","@vitejs/plugin-react":"^6.0.2","tsx":"^4.22.3","typescript":"^6.0.3","vite":"^8.0.14"},"overrides":{"protobufjs":"7.6.4","ws":"8.21.0","undici":"8.5.0"},"optionalDependencies":{"node-pty":"^1.1.0"},"_id":"@alan512/localspace@1.0.6","gitHead":"1a4b0c2ca25cae9f8eb7088ecb53df0919fac8a5","_nodeVersion":"24.3.0","_npmVersion":"11.5.2","dist":{"integrity":"sha512-KPAkvCapCpFXI0b/C2EV+fGC8NJBneGfu/srjmbC/kziHQ6lfdZcocVVFPv5HkVQan0F9edOMdYhCgzm5zIXEg==","shasum":"82848f128b1fe4c8aa738b5d4aa07cedb54c2d60","tarball":"https://registry.npmjs.org/@alan512/localspace/-/localspace-1.0.6.tgz","fileCount":370,"unpackedSize":12429308,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIAjdad+WuSSJzGUWnXybWlrIfxaWjvwsOOMPyYSm2meWAiBsoqqH6o5T/lq845TBvoCVuE4HOek5V87PRPwW15V/2g=="}]},"_npmUser":{"name":"sam1478963","email":"alan182@163.com"},"directories":{},"maintainers":[{"name":"sam1478963","email":"alan182@163.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/localspace_1.0.6_1784552183341_0.7194045158162679"},"_hasShrinkwrap":false}},"time":{"created":"2026-07-04T10:58:10.000Z","modified":"2026-07-20T12:56:23.721Z","1.0.4":"2026-07-04T10:58:10.478Z","1.0.5":"2026-07-18T03:29:01.837Z","1.0.6":"2026-07-20T12:56:23.559Z"},"bugs":{"url":"https://github.com/Alan-512/localspace/issues"},"author":{"name":"Alan-512"},"license":"MIT","homepage":"https://github.com/Alan-512/localspace#readme","keywords":["mcp","chatgpt","coding-agent","local-workspace","developer-tools"],"repository":{"type":"git","url":"git+https://github.com/Alan-512/localspace.git"},"description":"Expose a secure local coding workspace through an MCP server.","maintainers":[{"name":"sam1478963","email":"alan182@163.com"}],"readme":"<p align=\"center\">\r\n  <picture>\r\n    <img src=\"docs/assets/localspace-logo-light.svg\" alt=\"LocalSpace logo\" width=\"140\">\r\n  </picture>\r\n</p>\r\n\r\n<h1 align=\"center\">LocalSpace</h1>\r\n\r\n<p align=\"center\">A secure local coding workspace for ChatGPT and other MCP hosts.</p>\r\n\r\n<p align=\"center\">\r\n  <a href=\"https://www.npmjs.com/package/@alan512/localspace\"><img alt=\"npm\" src=\"https://img.shields.io/npm/v/@alan512/localspace?style=flat-square\" /></a>\r\n  <a href=\"https://github.com/Alan-512/localspace/actions/workflows/ci.yml\"><img alt=\"CI\" src=\"https://img.shields.io/github/actions/workflow/status/Alan-512/localspace/ci.yml?style=flat-square&branch=main\" /></a>\r\n  <a href=\"https://github.com/Alan-512/localspace/blob/main/LICENSE\"><img alt=\"License\" src=\"https://img.shields.io/badge/license-MIT-blue?style=flat-square\" /></a>\r\n  <a href=\"https://github.com/Alan-512/localspace\"><img alt=\"MCP\" src=\"https://img.shields.io/badge/MCP-local%20coding%20workspace-7c3aed?style=flat-square\" /></a>\r\n</p>\r\n\r\nLocalSpace lets ChatGPT, Claude, or another MCP-capable client work directly in\r\nselected folders on your own machine. It exposes file inspection, scoped edits,\r\ncode search, Git review, command execution, validation summaries, and handoff\r\ntools through a self-hosted MCP server.\r\n\r\nUse it when you want a Codex-style loop in ChatGPT: inspect the repository, read\r\nproject instructions, make focused changes, run local tests, review diffs, and\r\ncontinue long tasks across chat windows.\r\n\r\n<p align=\"center\">\r\n  <img src=\"docs/assets/localspace-feature-showcase.png\" alt=\"LocalSpace feature showcase\" width=\"860\">\r\n</p>\r\n\r\n> **Security note**\r\n>\r\n> LocalSpace is remote access to selected local folders. Your files stay on your\r\n> machine unless a connected MCP client explicitly asks LocalSpace to read or\r\n> modify them through tool calls. Only connect clients you trust, keep the Owner\r\n> password private, and keep your allowed roots narrow.\r\n\r\n---\r\n\r\n## Why LocalSpace?\r\n\r\nLocalSpace is designed for hybrid human + AI coding sessions where the model is\r\ninside your real development environment, but every capability remains explicit\r\nand inspectable.\r\n\r\n- **Local-first coding**: work with your actual projects, package manager, Git\r\n  repository, scripts, and terminal.\r\n- **Workspace-based access**: open one approved folder or managed worktree, then\r\n  reuse the returned `workspaceId` for all later operations.\r\n- **Codex-style editing**: use `read`, `apply_patch`, `exec_command`,\r\n  `write_stdin`, `changes`, and dedicated `git_*` tools.\r\n- **Fast code orientation**: use `project_map`, `entrypoints`, `symbols`,\r\n  `imports`, `references`, and `code_map` before changing unfamiliar code.\r\n- **Workflow guidance**: use `doctor`, `workspace_info`, `next_steps`,\r\n  `validate_plan`, `review_checklist`, `validation_summary`, `task_summary`,\r\n  `final_report`, and `handoff_summary` to keep long sessions grounded.\r\n- **Safety rails**: use filesystem allowlists, OAuth owner approval, Host header\r\n  checks, sensitive-path protection, command risk warnings, danger-command\r\n  approval tokens, and audit logs.\r\n\r\nLocalSpace does **not** replace your judgment. Shell access is intentionally\r\npowerful, so treat a connected MCP client like a trusted coding partner with\r\naccess to your machine.\r\n\r\n---\r\n\r\n## Quick Start\r\n\r\n### 1. Install requirements\r\n\r\nLocalSpace requires:\r\n\r\n- Node `>=22.19 <27`\r\n- npm\r\n- Git\r\n- a public HTTPS URL that forwards to the local LocalSpace server\r\n\r\nOn Windows, portable commands such as `node`, `npm`, and `git` work directly.\r\nBash-specific commands still require Git Bash, WSL, MSYS2, Cygwin Bash, or an\r\nexplicit shell configured with `LOCALSPACE_SHELL`.\r\n\r\n### 2. Install LocalSpace\r\n\r\nInstall the published package:\r\n\r\n```bash\r\nnpm install -g @alan512/localspace\r\n```\r\n\r\nOr, if you are developing LocalSpace from this checkout:\r\n\r\n```bash\r\nnpm install\r\nnpm run build\r\n```\r\n\r\n### 3. Initialize LocalSpace\r\n\r\n```bash\r\nlocalspace init\r\n```\r\n\r\nFrom a local checkout, use `node dist/cli.js init` instead.\r\n\r\nDuring setup, choose:\r\n\r\n- the local folders that MCP clients may open as workspaces\r\n- the local port, usually `7676` or `7680`\r\n- the public HTTPS base URL for your tunnel or reverse proxy\r\n\r\nEnter the public base URL as an origin only, without `/mcp`:\r\n\r\n```text\r\nhttps://your-tunnel-host.example.com\r\n```\r\n\r\nThe Owner password is printed during setup and stored in:\r\n\r\n```text\r\n~/.localspace/auth.json\r\n```\r\n\r\nKeep this password private. LocalSpace also keeps a backward-compatible fallback\r\nfor legacy auth files from earlier installs.\r\n\r\n### 4. Start your tunnel\r\n\r\nLocalSpace does not create the public tunnel for you. Use Cloudflare Tunnel,\r\nngrok, Pinggy, Tailscale Funnel, or another HTTPS reverse proxy.\r\n\r\nPoint the tunnel to your local server, for example:\r\n\r\n```text\r\nhttp://127.0.0.1:7680\r\n```\r\n\r\nThen configure your MCP client with:\r\n\r\n```text\r\nhttps://your-tunnel-host.example.com/mcp\r\n```\r\n\r\n### 5. Start LocalSpace\r\n\r\n```bash\r\nlocalspace serve\r\n```\r\n\r\nFrom a local checkout, use `node dist/cli.js serve` instead.\r\n\r\nWhen the MCP client connects, LocalSpace shows an Owner approval page. Enter the\r\nOwner password only when you intentionally want that client to access this\r\nserver.\r\n\r\n### 6. Open a project from ChatGPT\r\n\r\nAsk your MCP client to open one of the approved folders:\r\n\r\n```text\r\n@localspace Open ~/work/my-project and inspect the current git status.\r\n```\r\n\r\nFor long or risky changes, prefer an isolated managed worktree:\r\n\r\n```text\r\n@localspace Open ~/work/my-project in worktree mode and implement the next task.\r\n```\r\n\r\n---\r\n\r\n## Common Commands\r\n\r\n```bash\r\n# Check local runtime, config, Git, shell, and dependency health\r\nlocalspace doctor\r\n\r\n# Start the MCP server\r\nlocalspace serve\r\n\r\n# Start with a temporary public URL override\r\nLOCALSPACE_PUBLIC_BASE_URL=\"https://new-tunnel.example.com\" localspace serve\r\n\r\n# Persist a stable public URL\r\nlocalspace config set publicBaseUrl https://localspace.example.com\r\n```\r\n\r\nIf you are running from a local checkout, replace `localspace` with\r\n`node dist/cli.js` after running `npm run build`.\r\n\r\n---\r\n\r\n## Tool Surface\r\n\r\nLocalSpace is designed around the default `hybrid` tool surface. It combines\r\nsafe workspace inspection, Codex-style patching, process tools, code navigation,\r\nGit helpers, and workflow summaries for ChatGPT coding sessions.\r\n\r\n`LOCALSPACE_TOOL_MODE` still exists for compatibility and advanced experiments,\r\nbut normal users should keep the default `hybrid` mode.\r\n\r\n| Mode | Status | Best for |\r\n| --- | --- | --- |\r\n| `hybrid` | Default and recommended | ChatGPT coding sessions with Codex-style edits, process tools, code navigation, Git helpers, and workflow summaries. |\r\n| `codex` | Experimental compatibility | A smaller Codex-like surface: workspace, read, patch, command, process, changes, and Git tools. |\r\n| `full` | Legacy compatibility | Broader dedicated inspection/search/edit tools plus Git and workflow helpers. |\r\n| `minimal` | Legacy compatibility | A small compatibility surface for hosts that prefer simple read/write/bash-style tools. |\r\n\r\nExample:\r\n\r\n```bash\r\nLOCALSPACE_TOOL_MODE=\"hybrid\" node dist/cli.js serve\r\n```\r\n\r\nSee [`docs/configuration.md`](docs/configuration.md) for the complete reference.\r\n\r\nLocalSpace also ships built-in workflow skills. `open_workspace` advertises only\r\ntheir names, descriptions, and `SKILL.md` paths; the model should read the\r\nmatching skill only when the current task needs that workflow. This keeps\r\nworkflow guidance progressively loaded while the `hybrid` tool surface remains\r\nthe single recommended default.\r\n\r\n---\r\n\r\n## What ChatGPT Can Do\r\n\r\n\r\nIn the default `hybrid` mode, ChatGPT can:\r\n\r\n- open an approved checkout or managed worktree with `open_workspace`\r\n- inspect project state with `doctor`, `workspace_info`, and `entrypoints`\r\n- read files directly with `read`\r\n- map unfamiliar projects with `project_map` and `code_map`\r\n- search code with `grep`, `glob`, `ls`, `symbols`, `imports`, and `references`\r\n- edit files with `apply_patch`\r\n- run commands with `exec_command` and interact with running processes through\r\n  `write_stdin`\r\n- review changes with `changes`, `git_status`, `git_diff`, and `git_log`\r\n- stage and commit explicit files with `git_add` and `git_commit` when the user\r\n  asks for it\r\n- summarize progress with `session_summary`, `validation_summary`,\r\n  `task_summary`, `final_report`, and `handoff_summary`\r\n\r\nThe workflow tools are intentionally read-only unless their names clearly imply\r\nmutation, such as `apply_patch`, `exec_command`, `git_add`, or `git_commit`.\r\n\r\n---\r\n\r\n## Security Model\r\n\r\nLocalSpace has multiple safety layers, but it is still a tool for trusted local\r\ndevelopment access.\r\n\r\n| Layer | Purpose |\r\n| --- | --- |\r\n| Filesystem allowlist | Only configured roots can be opened as workspaces. |\r\n| OAuth owner approval | A connecting MCP client must be approved with your Owner password. |\r\n| Host allowlist | LocalSpace derives allowed hosts from local and public configuration. |\r\n| Sensitive path protection | Write-like tools block `.env`, Git config/hooks, secret-like files, LocalSpace state paths, home roots, and system directories. |\r\n| Command warnings | Risky shell patterns are surfaced before or with command execution. |\r\n| Danger-command approval | High-risk commands require an explicit one-time approval token. |\r\n| Audit log | Important coding actions are recorded for review and session summaries. |\r\n\r\nGood allowed roots are narrow project folders such as:\r\n\r\n```text\r\n~/work\r\n~/personal/open-source\r\nC:\\Users\\alice\\dev\r\n```\r\n\r\nAvoid broad roots such as `~`, `/`, or `C:\\`.\r\n\r\nRead more in [`docs/security.md`](docs/security.md).\r\n\r\n---\r\n\r\n## ChatGPT Workflow\r\n\r\nA strong LocalSpace session usually follows this loop:\r\n\r\n1. Open the target folder once with `open_workspace`.\r\n2. Read returned `AGENTS.md` or equivalent project instructions.\r\n3. Inspect the repo with `workspace_info`, `entrypoints`, `project_map`, or\r\n   `code_map`.\r\n4. Make small, scoped edits with `apply_patch`.\r\n5. Run the most relevant validation commands.\r\n6. Review `changes` or `git_diff` before summarizing.\r\n7. Use `final_report` or `handoff_summary` at natural stopping points.\r\n\r\nFor detailed model-facing guidance, see\r\n[`docs/chatgpt-coding-workflow.md`](docs/chatgpt-coding-workflow.md).\r\n\r\n---\r\n\r\n## Documentation\r\n\r\n- [`docs/setup.md`](docs/setup.md): setup walkthrough\r\n- [`docs/configuration.md`](docs/configuration.md): commands, environment\r\n  variables, tool modes, widgets, skills, and logging\r\n- [`docs/security.md`](docs/security.md): security model and operational cautions\r\n- [`docs/chatgpt-coding-workflow.md`](docs/chatgpt-coding-workflow.md): how an\r\n  MCP host should use LocalSpace during coding tasks\r\n- [`docs/structured-content.md`](docs/structured-content.md): structured output\r\n  returned by navigation, Git, diagnostics, and workflow tools\r\n- [`docs/gotchas.md`](docs/gotchas.md): common setup and workflow pitfalls\r\n\r\n---\r\n\r\n## Local Development\r\n\r\nFor working on LocalSpace itself:\r\n\r\n```bash\r\nnpm install --include=dev\r\nnpm run dev\r\nnpm run typecheck\r\nnpm test\r\nnpm run build\r\nnpm run start\r\n```\r\n\r\nBefore finalizing changes, run at least:\r\n\r\n```bash\r\nnpm run typecheck\r\nnpm test\r\n```\r\n\r\n---\r\n\r\n## Credits\r\n\r\nLocalSpace started as a fork of\r\n[DevSpace](https://github.com/Waishnav/devspace) by\r\n[Waishnav](https://x.com/wshxnv). The original project demonstrated a practical\r\nway to bring local coding workflows to MCP hosts.\r\n\r\nLocalSpace builds on that foundation with its own branding, CLI/config paths,\r\nhybrid tool modes, structured output, code navigation, Git helpers, command\r\nsafety, audit logs, workflow summaries, and long-session handoff support.\r\n\r\n## License\r\n\r\nMIT. See [`LICENSE`](LICENSE).\r\n","readmeFilename":"README.md"}