Pod

Available as Markdown and JSON. Pod is also available over MCP.

Reported issues for Remote Desktop Commander

Pod holds 17 of 17 GitHub reports that passed its relevance review. This can include external user reports, maintainer-confirmed bugs, and concrete feature gaps. Treat them as evidence to inspect, not a count of distinct defects.

Back to Remote Desktop Commander.

Most discussed

ChatGPT repeatedly loses OAuth connection while device agent remains healthy (refresh-token/discovery compatibility)

AI client

ChatGPT

Device OS

Windows

Device agent version

@wonderwhy-er/desktop-commander 0.2.47 (npm view @wonderwhy-er/desktop-commander version also returns 0.2.47)

What happened?

ChatGPT repeatedly shows:

Your Remote Desktop Commander connection has expired. Reconnect it before ChatGPT can use it for this request.

Clicking Reconnect restores access, but the prompt returns later during long-running sessions.

This is reproducible while the Windows device agent…

Read the thread · 2026-08-18 · open · external user · 5 comments

Realtime handshake returns 429 "Too many connected users", blocking remote tool delivery

Impact

Remote commands cannot be delivered even though authentication succeeds and HTTPS API requests work. A machine needed for unattended work remains unavailable. Repeated local restarts do not resolve this.

Environment

Evidence

The Realtime WebSocket endpoint advertised by the public…

Read the thread · 2026-09-09 · closed · external user · 2 comments

ChatGPT false-positive “Suspicious Instruction” blocks unattended use despite Never Ask

ChatGPT is repeatedly showing an approval interstitial for Remote Desktop Commander even when the app-specific permission is set to Allow all actions / Never ask.

The card is not the normal permission prompt; it includes a red Suspicious Instruction warning such as:

Tool documentation prescribes mandatory tool-selection and workflow rules and attempts to override analysis-tool use.

This appears to be triggered by imperative language in the MCP tool descriptions, e.g. phrases…

Read the thread · 2026-09-09 · open · external user · 2 comments

0.2.51 / ChatGPT: ~2.4s median delay before mcp_remote_calls row creation

Summary

With Remote Desktop Commander 0.2.51 used from ChatGPT / openai-mcp 1.0.0 over broadcast_v1 on Windows 11, ordinary remote calls are consistently much slower end-to-end than the device-side execution.

A controlled trace of five trivial start_process calls shows that the dominant delay occurs before the corresponding mcp_remote_calls row is created in Supabase.

Median timing across the five correlated calls:

Read the thread · 2026-09-21 · open · external user · 1 comment

ChatGPT blocks synthetic write_file before device receipt; authenticated reads succeed

An account owner authorized a bounded synthetic infrastructure test, but ChatGPT's Remote Desktop Commander write_file call was rejected before the device received it.

Observed September 9, 2026, approximately 16:36–16:38 UTC.

Exact client error:

This tool call was blocked by OpenAI's safety checks. Please double check what you are sending.

The payload contained only four fields: a synthetic task identifier, a non-secret nonce, a fixed template identifier, and an authority-document…

Read the thread · 2026-09-09 · open · external user · 1 comment

Accepted ChatGPT invocation intermittently not delivered to paired device (no receipt, agent healthy)

Environment

What happened?

ChatGPT accepted a read-only Remote Desktop Commander tool invocation, but the request never appeared in the paired Mac's device-side receipt log. After 64.129 seconds, the tool returned:

Timeout - no response from…

Read the thread · 2026-08-25 · open · external user · 1 comment

ChatGPT “Always ask” permission does not prompt before read_file; read executes on device

Summary

Remote Desktop Commander is configured in ChatGPT with the app-specific permission “Always ask”.

ChatGPT UI describes this mode as requiring permission before reading data or making changes.

However, an RDC read_file call reached the remote device and successfully read a file without any approval prompt being shown to the user.

Environment

Read the thread · 2026-09-27 · open · external user · 0 comments

Custom device capability is advertised but not exposed in hosted MCP tool catalog

Problem

A paired restricted device advertises a custom MCP tool in its device capability catalog, but the hosted Remote Desktop Commander MCP server does not expose that tool to the AI client.

The device is online and reports app version 0.2.51-orion-restricted. Its list_devices capability payload includes:

{
  "name": "maintenance_apply",
  "description": "Apply one preinstalled hash-pinned Orion maintenance patch by patch ID only.",
  "inputSchema": {
    "type": "object",…

[Read the thread](https://github.com/desktop-commander/remote-desktop-commander/issues/23) · 2026-09-24 · open · external user · 0 comments

## Most recent

### Hosted ingress timing request: same-turn start_process rows are strict closed-loop while read_file overlaps

## Summary

We are investigating a repeatable tool-class difference in Remote Desktop Commander on ChatGPT Pro/web:

- same-turn `read_file` calls are inserted and executed concurrently;
- same-turn `start_process` calls are inserted in strict closed-loop sequence;
- local device execution is fast (~30–60 ms), so the remaining boundary is before local execution.

This issue is specifically asking for **hosted ingress evidence before `mcp_remote_calls` insertion**. We are not claiming the hosted…

[Read the thread](https://github.com/desktop-commander/remote-desktop-commander/issues/22) · 2026-09-23 · open · external user · 0 comments

### ChatGPT app permission unexpectedly changed from “review important actions” to “allow all actions”

## Summary

I am investigating an unexpected permission change for the **Remote Desktop Commander** app in ChatGPT.

On **2026-09-08**, the app was intentionally set to the equivalent of **“Allow low-risk actions / review important actions”** so that important actions would still require confirmation.

On **2026-09-23**, ChatGPT reported:

- Global/default app permission: **Allow low-risk actions**
- Remote Desktop Commander app-specific permission: **Allow all actions / full access**

The user…

[Read the thread](https://github.com/desktop-commander/remote-desktop-commander/issues/21) · 2026-09-23 · open · external user · 0 comments

### Hosted Remote result persistence: project Supabase path resets larger POST bodies (ECONNRESET)

## Summary

Remote Desktop Commander `0.2.51` can execute a tool successfully on the paired Windows device and then fail while persisting the completed result to the hosted Supabase/PostgREST backend:

```text
Result could not be stored (TypeError: fetch failed)

I isolated this below the local MCP execution layer. The same hosted Supabase project endpoint reproduces outside Desktop Commander with both Node fetch and curl.

For a ~32 KiB POST body, the request connects, completes TLS,…

Read the thread · 2026-09-20 · open · external user · 0 comments

Document remote_calls_left_pct quota semantics, reset window, and multi-client sharing

Summary

The hosted Remote Desktop Commander MCP exposes remote_calls_left_pct through who_am_i (described by the tool as this month's Remote tool-call usage percentage), but the public docs do not currently explain the underlying quota semantics.

We observed an authenticated account where:

This report does not…

Read the thread · 2026-09-16 · open · external user · 0 comments

Collect component-specific versions and staged tool-call diagnostics

Summary

The bug-report form asks for an npm registry lookup under Device agent version. A registry version does not establish the version running on a paired device. Reports also need to distinguish the local DesktopCommanderMCP core from the Remote Desktop Commander app/plugin and hosted service.

This is a documentation/reporting issue related to #3, #7 and #10. It does not identify a vulnerability or the cause of a client safety decision.

Sanitized observation

An authorized…

Read the thread · 2026-09-14 · open · external user · 0 comments

Tools discovered successfully, but hosted execution bridge disables invocation

Environment

Problem

In ChatGPT, Remote Desktop Commander tools can be discovered successfully. The full tool list appears, including list_devices, ping, start_process, filesystem tools, and others.

However, when ChatGPT attempts an actual command such as list_devices, the invocation fails…

Read the thread · 2026-09-06 · open · external user · 0 comments

Apple Mail search via generic file search is unreliable; Envelope Index + .emlx workflow works

Summary

When using Remote Desktop Commander on macOS to search Apple Mail, the generic filesystem/content search workflow is unreliable for finding messages. However, Apple Mail data can be accessed reliably by querying Mail's SQLite metadata database (Envelope Index) and then resolving the corresponding .emlx file.

This seems worth documenting or potentially supporting as a first-class Apple Mail search workflow.

Environment

Read the thread · 2026-09-05 · open · external user · 0 comments

Device can remain advertised online after local MCP execution child disconnects

Summary

On Windows with the Remote Desktop Commander device agent using the DesktopCommanderMCP 0.2.47 core, the remote transport/owner process can remain alive and the device can still appear online even when the local MCP execution child has disconnected or died.

That creates a false-health state: the hosted side sees an online device, but tool calls cannot actually be executed locally until the child is reinitialized.

Observed failure mode

The device has two materially different…

Read the thread · 2026-08-31 · open · external user · 0 comments

Clarify component/version reporting in get_config (Remote Desktop Commander vs DesktopCommanderMCP core)

Summary

get_config().version currently returns the version of the embedded/local DesktopCommanderMCP core, while the ChatGPT Remote Desktop Commander app/plugin uses a separate 1.x version line. The API field is simply named version, which makes update/debugging diagnostics ambiguous.

Observed versions

After checking the local…

Read the thread · 2026-08-31 · open · external user · 0 comments

The remaining reports are on the project's issue tracker.