Mac MCP creator bulutarkan claims the open-source local server lets ordinary ChatGPT conversations operate macOS shell, files, UI, browsers, and memory without Codex, potentially making ChatGPT a system-wide automation interface with optional delegated coding workers.
state: corroboratedheat: lowuncertainty: mediumconvergesscott: mediummacos-agents mcp agent-harnessesbulutarkanMac MCP
What is this?
Mac MCP is an open-source (MIT) local macOS control server by Arkan Bulut (GitHub: bulutarkan) that exposes a Mac to AI agents through both a native MCP endpoint and a REST/OpenAPI interface — shell commands, transactional file management, and AppleScript-driven Safari/Chrome automation — so that an ordinary ChatGPT conversation (not a dedicated coding agent like Codex) can act as the orchestrator for a local agent layer with shell, files, UI, and memory tools. A community-run wiki entry (ai.miraheze.org, 'reflects developments through September 2026') now provides the first third-party corroboration of the project's existence, authorship, license, and dual-interface architecture, though it is user-editable and its 'Released September 2024' date conflicts with the case's ~105-day repo-age telemetry; the repo itself still has not been directly inspected, so capability and safety claims remain first-party testimony. The surrounding territory is corroborated and moving fast: independent implementations of the same ChatGPT-web-as-local-agent pattern exist (CursorTouch/MacOS-MCP, logxroot's dotlink), while OpenAI now ships native ChatGPT Computer Use on macOS with per-app approvals and Accessibility/Screen-Recording permissions, developer-mode MCP hosting (with independently reported lifecycle bugs where tools silently drop out of long-running conversations), and WebMCP support in the ChatGPT desktop browser — the platform absorbing much of the capability space third-party local-agent servers claim.
Why it matters to Scott
OpenAI now natively ships the tool-belt-with-approval-perimeter architecture Scott codified in his hands-and-eyes ebook (native ChatGPT computer use with per-app approvals, developer-mode MCP hosting, WebMCP), and the independently reported dev-mode bug — tools silently dropping out of long-running conversations — is a dated receipt for his doorway-not-memory thesis and an operational hazard for his own ChatGPT-facing MCP builds (ebook-mcp's Apps SDK pattern). Mac MCP's local receipts/undo design is a convergent but still-unvalidated minor-party instance of his reversibility canon: the local-execution-vs-provider-native counterpoint is worth watching, not yet acting on, until the repo or a reproducible integration path is inspected.
ip:source.mcp-as-the-tool-belt-standard-giving-ai-agents-hands-and-eyes-ebookip:source.retail-mcp-is-the-doorway-not-the-memory-ebookip:source.why-code-execution-beats-mcpdev:project.ebook-mcpradar:concept.mcpradar:concept.agent-harnessesradar:concept.computer-useradar:concept.openairadar:openai-webmcp-browser-supportradar:overlord-transactional-agent-executionradar:pomeroy-v1-cross-assistant-macos
queries asked of Scott's wikis
- MCP as tool belt standard: giving AI agents hands and eyes
- code execution beats MCP tool calling — reliability and harness arguments
- ChatGPT developer mode / connectors: local MCP server hosting and platform absorption
- local-first agent execution with undo, receipts, audit trail, reversible side effects
- ebook-mcp project — agent-maintained wiki over MCP
- computer use / GUI automation on macOS: Accessibility permissions, per-app approvals, safety boundaries
Measured heat
now 0 pts/hpeak 1 pts/hcomments 0/hpeers p14momentum: steady3 platformsage 2745h
points/hour across evidence · reading as of 2026-10-12 02:59:37.977291+11:00 · deterministic, not a model opinion
How the heat travelled
Evidence (4) — ⭐ canonical anchor
Interpretation history
2026-10-02T05:30:55Z
grounded: converges/medium — OpenAI now natively ships the tool-belt-with-approval-perimeter architecture Scott codified in his hands-and-eyes ebook (native ChatGPT computer use with per-ap
2026-10-02T05:22:45Z
The first third-party implementation of the case's pattern (dotlink: ChatGPT web driving local shell/files over MCP) supplies the independent line the case previously lacked, corroborating the ChatGPT-as-local-control-plane territory — not Mac MCP itself, whose control path, memory, delegated workers and safety behavior remain single-voice claims. The case now tracks a corroborated-but-cold pattern with a live platform-absorption counterpoint (native ChatGPT computer use + dev-mode MCP hosting vs. local-execution-with-receipts), not a one-off project claim.
2026-10-02T04:27:22Z
evidence attached: hn.story.49929101 — Another implementation of ChatGPT-web-as-local-agent over MCP with sandboxed shell/file access — independent support that this pattern is real rather than one-off.
2026-09-28T17:08:04Z
grounded: converges/medium — The center of gravity moved from the project to its territory: the grounding (snippet-level on the ChatGPT docs) has OpenAI shipping native ChatGPT computer use
2026-09-28T16:57:26Z
The maintainer's follow-up replaces a bare capability list with a coherent design story — remote reasoning, local execution, reversible side effects via receipts, undo and gated foreground execution — making Mac MCP a live, self-consistent small project worth monitoring rather than a one-off claim. But the step to watching rests on accumulated first-party consistency alone: every artifact is the creator's own testimony with negligible traction (the follow-up sits at 2 points, 1 comment) and no independent validation, so the case advances no further and stays cold.
2026-09-28T15:45:04Z
evidence attached: reddit.post.1wseyjt — Mac MCP maintainer's own follow-up on receipts, undo, and gated foreground execution is design substance the open case's re-judgement should weigh.
2026-09-15T13:44:58Z
The discussion adds analogy, not validation: a commenter describes a similar Claude Desktop setup without demonstrating Mac MCP's integration or trust-boundary behavior. The speculative TOS warning establishes no contradiction, leaving this a thinly evidenced implementation of a familiar pattern.
2026-09-13T14:26:36Z
grounded: known/low — The supported capabilities repeat Scott’s position in “MCP as the Tool Belt Standard: Giving AI Agents Hands and Eyes” and overlap with shell/file execution alr
2026-09-13T14:23:48Z
origin walked (codex/luna, conf 0.97): anchor reddit.post.1wf7o6p -> echo.github.6e66abcbc5 by Tarkan Bulut
2026-09-13T14:22:10Z
case created — The creator describes a concrete, distinct local automation project, but the available excerpt provides neither a repository link nor support for the scout's stronger safety claims.
Decision trace
- 10-02 15:30repriceThe first third-party implementation of the case's pattern (dotlink: ChatGPT web driving local shell/files over MCP) supplies the independent line the case previously lacked, corroborating the Ch
- 10-02 15:30groundOpenAI now natively ships the tool-belt-with-approval-perimeter architecture Scott codified in his hands-and-eyes ebook (native ChatGPT computer use with per-app approvals, developer-mode MCP hosting,
- 10-02 14:27attachAnother implementation of ChatGPT-web-as-local-agent over MCP with sandboxed shell/file access — independent support that this pattern is real rather than one-off.
- 10-02 14:23propose_attachAnother implementation of ChatGPT-web-as-local-agent over MCP with sandboxed shell/file access — independent support that this pattern is real rather than one-off.
- 09-29 03:08repriceThe maintainer's follow-up replaces a bare capability list with a coherent design story — remote reasoning, local execution, reversible side effects via receipts, undo and gated foreground execut
- 09-29 03:08groundThe center of gravity moved from the project to its territory: the grounding (snippet-level on the ChatGPT docs) has OpenAI shipping native ChatGPT computer use with per-app approval gates plus dev-mo
- 09-29 01:45attachMac MCP maintainer's own follow-up on receipts, undo, and gated foreground execution is design substance the open case's re-judgement should weigh.
- 09-29 01:37propose_attachMac MCP maintainer's own follow-up on receipts, undo, and gated foreground execution is design substance the open case's re-judgement should weigh.
- 09-22 19:28review_screenjev screen: no material development (noul=0.06)
- 09-15 23:44repriceThe discussion adds analogy, not validation: a commenter describes a similar Claude Desktop setup without demonstrating Mac MCP's integration or trust-boundary behavior. The speculative TOS warni
- 09-15 23:44review_screenA commenter claims firsthand use of a similar setup and references trust-boundary handling, but the excerpt is incomplete and does not establish the project's capabilities or materially validate
- 09-14 00:26groundThe supported capabilities repeat Scott’s position in “MCP as the Tool Belt Standard: Giving AI Agents Hands and Eyes” and overlap with shell/file execution already implemented in “Ask terminal agent”
- 09-14 00:23promote_anchororigin walk conf 0.97
- 09-14 00:22createThe creator describes a concrete, distinct local automation project, but the available excerpt provides neither a repository link nor support for the scout's stronger safety claims.