✨ Winx - MCP Server for Shell & Coding Agents ✨
🦀 Native Rust implementation inspired by WCGW, built for local code-agent workflows
A local MCP server you can hand to a coding agent and stop worrying about the shell.
Winx is the MCP server I wanted while running Claude, Codex, and friends against real repos: one process that handles the shell, file IO, and PTY-backed interactive sessions, written in Rust so it doesn't fight you on stdio.
It started as a Rust port of WCGW but isn't a Python wrapper. Everything runs on a
real PTY (via portable-pty), cd actually sticks, Ctrl+C actually interrupts, and background shells survive
long-running TUIs without leaking output buffers into your token budget.
What you get
- A stateful bash session per thread with proper PTY semantics - foreground, background, status checks, text input,
Enter/Ctrl-C/Ctrl-D, raw ASCII. Multiline scripts and top-level
commandshorthand both work; NUL bytes are rejected before they reach the shell. - Workspaces with three modes:
wcgw(full access),architect(read-only),code_writer(allowlist of commands and write globs). The command allowlist is parsed with tree-sitter, so it checks every command on the line - pipelines,&&/||/;, command substitution, subshells - not just the first word, and can't be bypassed withls && curl … | shorls $(rm …). - A resilient PTY: a shell that won't return to a prompt (even after Ctrl-C) is auto-reset at the same cwd/mode, child
processes are reaped on drop, and prompt detection is robust to a custom
PS1. Opt intozshwithWINX_SHELL=zsh. - File reads with WCGW-style line ranges (
file.rs:10-40,file.rs:10-,file.rs:-40). Active files are tracked and prioritized in the repository context across calls. - File writes and SEARCH/REPLACE edits that survive ambiguous matches, indentation drift, and the usual unicode
quote-mismatches from LLMs. Writes are blocked when the file hasn't been read or the cached content is stale, the
success message shows a compact diff of what changed, and recent edits are reversible with
UndoEdit.MultiFileEditapplies a change across several files all-or-nothing (validated in memory first, so a failure on the last file leaves the earlier ones untouched). - Tree-sitter code navigation via
CodeMap: a token-budgeted symbol map of a file or the whole repo, or a definition/reference lookup for a symbol name - the semantic view that plaingrepcan't give you, across 11 languages. ContextSavefor handing a task summary plus its files to the next session - including workspace context, active files, git status/diff, and terminal sharing for proper resumption. Resuming reopens the saved project root and token-caps the restored memory so it never overflows the context window.ReadImageso multimodal clients can pull screenshots, mockups, error PNGs, etc.- Clean, token-aware shell output: cursor/ANSI noise from interactive programs (REPLs, progress
bars) is rendered away through a terminal emulator, and mechanical repetition is collapsed
losslessly (
line [winx: ×N]) so build/install logs don't blow your context budget. Toggle the collapsing withWINX_NO_COMPRESS. When output still overflows the cap, the dropped head is streamed to a scratch file under.winx/scratch/the agent can re-read, instead of being lost. - Secret redaction on by default: provider API keys, JWTs, PEM private-key blocks and
user:pass@URLs are scrubbed from all tool output and saved memory before they reach the model (disable withWINX_NO_REDACT=1). An opt-in Landlock sandbox (WINX_SANDBOX=1, Linux) adds a kernel-enforced second layer that confines writes to the workspace and hides the home directory. - Two transports: stdio for local clients, plus an optional token-gated Streamable HTTP server
(
winx serve --http) for remote MCP clients like ChatGPT - see Remote access.






