A secure Windows and macOS workstation MCP gateway for ChatGPT over OpenAI Secure MCP Tunnel.
WorkForge MCP demonstrates solid definition quality with consistent naming, descriptions, and schemas across 13 tools. All tools follow verb_noun naming convention (workstation_context, project_resume, list_directory, search_files, read_text_file, read_image_file, write_text_file, replace_text, shell_start, shell_output, shell_status, shell_cancel, wait_for_shell_settled). All tools have descriptions (range 100-200 chars, well within the 10-1024 baseline). Input schemas are present and typed for all tools. However, output schemas are not documented in the source code, parameter descriptions lack some context-sensitivity guidance, and error handling guidance is minimal. The contextRevision pattern for mutation operations shows thoughtful design, but recovery guidance is sparse.
List a bounded directory tree. Absolute paths are allowed; relative paths start at the profile default directory.
Read a bounded Git branch, status, recent-commit, diff-stat, and resume-document snapshot without modifying the repository.
Read an image file and return base64-encoded data. Only PNG, JPEG, GIF, WebP, SVG, and BMP are supported.
Read a text file with optional line range. Paths outside the profile boundary are rejected.
Replace text in a file by search pattern or line range. Must pass the current contextRevision.
Search paths or file content with ripgrep without modifying files.
Cancel a running shell job. Safe to call on already-completed jobs.
Output schemas not documented in source code. LLMs cannot plan downstream tool calls or extract required fields without knowing what each tool returns.
Error handling guidance is minimal. Tools do not return recovery suggestions (e.g., 'if path out of bounds, try listing parent directory') or error classifications (retryable vs. user-fixable vs. fatal). LLMs cannot self-correct failures effectively.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-23 | C | 61 | 2025-06-18+ | v2 |
Read output from a running or completed shell job with optional server-side wait.
Start an asynchronous shell job (PowerShell on Windows, zsh on macOS). Jobs run as the current OS user within registered-profile path boundaries.
Query the status of a shell job without retrieving output.
Server-side blocking wait for a shell job to complete. Returns when job exits or timeout expires.
Read the profile identity, complete bootstrap guidance, current context revision, platform, and actual access boundary before a mutation or shell command.
Create or overwrite a text file. Must pass the current contextRevision from workstation_context or project_resume.
Parameter descriptions lack actionable constraint details. For example, replace_text 'pattern' param describes itself as '1-1M chars' but does not explain the consequences of a pattern not matching, or whether partial replacements are possible. Descriptions should answer: what happens on edge cases?
write_text_file and replace_text require contextRevision parameter to prevent concurrent edits, but the tool descriptions do not explain what an agent should do if contextRevision is stale. Should the agent retry? Fetch fresh context? This guidance is missing.
shell_* tools (shell_start, shell_output, shell_status, shell_cancel, wait_for_shell_settled) return IDs in format 'shell_<hex>' but do not document that LLMs must preserve and pass back this exact format. If an LLM reformats or truncates the ID, downstream calls fail silently.