Private, local-first Agent OS for desktop. Indexes local files and provides hybrid semantic + keyword search. Exposes tools to external MCP clients via Streamable HTTP protocol.
Ghost exposes 8 tools with reasonably clear descriptions and mostly complete schemas. Naming is mostly consistent with verb_noun patterns (ghost_search, ghost_read_file, ghost_write_file, ghost_run_command). All tools have non-empty descriptions in the 80 - 300 character range, well within the productive 10 - 1024 band. Input schemas are fully visible with type definitions for all parameters. However, several concerns prevent a higher score: (1) output schemas are NOT documented, we can see what goes IN but not what comes OUT; (2) ghost_index_status is duplicated (appears twice with identical input/output); (3) error handling guidance is minimal, no recovery instructions or actionable error messages shown in schema; (4) sensitive operations (ghost_write_file, ghost_run_command) lack confirmation/dry-run patterns despite being destructive; (5) tool descriptions occasionally include implementation details ('up to 100KB') rather than user intent; (6) parameter descriptions, while present, are sometimes sparse (e.g., ghost_recent_files limit parameter lacks a default or range). The server demonstrates solid foundational quality but falls short of 'excellent' (80+) due to missing output schemas and incomplete error-recovery patterns.
Get Ghost's current indexing status including document count, chunk count, vector search availability, and watched directories.
Get the current indexing statistics: total documents, text chunks, and semantic embeddings in the user's vault. Use when the user asks about what has been indexed or how much content is searchable.
List files and subdirectories in a directory. Returns names, sizes, and types (file/dir). Use to explore the filesystem before reading specific files. Hidden files (starting with .) are excluded.
Read the text content of a file. Use after ghost_search finds a relevant file, or when the user provides a specific file path. Returns up to 100KB of text. Do NOT guess file paths — use ghost_search or ghost_list_directory first to discover them.
List recently indexed files ordered by indexing time. Returns file paths, names, sizes, and timestamps.
Execute a shell command on the user's system. DANGEROUS: always requires explicit user approval. ONLY use when the user explicitly asks to run a command or perform a system operation. NEVER use proactively or to gather information that other tools can provide. Commands time out after 30 seconds. Explain what the command does before executing.
Output schemas not documented. While input schemas are complete with types and descriptions, no return/response schemas are visible in the code. LLMs cannot plan downstream tool calls or extract chained IDs without knowing what fields to expect.
Duplicate tool: ghost_index_status appears twice (lines indicate both src-tauri/src/agent/tools.rs and src-tauri/src/protocols/mcp_server.rs) with identical schemas. Reduces clarity and wastes LLM decision-making on which variant to call.
Destructive operations lack confirmation or dry-run pattern. ghost_write_file and ghost_run_command both modify/execute system state but include no dry-run, confirmation step, or compensation tools. Agents may accidentally delete files or run dangerous commands.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | B | 71 | 2026-07-28+ | v2 |
| 2026-03-09 | D | 54 | 2024-11-05+ | v1 |
Search across locally indexed files using hybrid keyword + semantic search. Returns matching documents with relevant text snippets and scores.
Write text content to a file. Creates the file if it doesn't exist, overwrites if it does. Creates parent directories automatically. Only use when the user explicitly asks to create or modify a file. Requires approval for sensitive paths.
Error handling guidance missing. No visible schema or description text explains how to recover from failures (e.g., 'If path not found, use ghost_list_directory to discover valid paths'). LLMs will stall on errors without actionable next steps.
Parameter constraints underdocumented. ghost_recent_files and ghost_search accept 'limit' but lack explicit min/max ranges. ghost_search's 'query' parameter has no documented minimum length or format guidance. LLMs may pass unreasonable values (limit=999999, empty query strings).
Implementation details leak into descriptions. ghost_read_file states 'Returns up to 100KB of text', a token-cost optimization detail relevant to backend, not user intent. Similarly, ghost_run_command mentions '30 second timeout', a system detail better handled silently or in error messages.
Tool chaining references incomplete. ghost_read_file's description says 'Use after ghost_search finds a relevant file' but does not clarify what field ghost_search returns to pass to ghost_read_file. If ghost_search returns 'filepath' but ghost_read_file expects 'path', agents must infer the mapping.