MCP Feedback Enhanced

An MCP server that inserts a human feedback step into agent tasks: a web or desktop window for text, images and prompts

MCP server

Medium risk

We rate an entry medium when the tool runs code, makes network calls or reads project files. Check what exactly it does before installing.

Why this level

  • Runs a local web server and WebSocket without authentication
  • Earlier versions allowed unauthenticated command execution, so a current version is required
All reasons and checks

minidoracat/mcp-feedback-enhanced

Install

Manual install

{
  "mcpServers": {
    "mcp-feedback-enhanced": {
      "command": "uvx",
      "args": ["mcp-feedback-enhanced@latest"],
      "timeout": 600,
      "autoApprove": ["interactive_feedback"]
    }
  }
}

Basic configuration. Requires uv installed (pip install uv). For advanced setup set MCP_WEB_HOST, MCP_WEB_PORT, MCP_LANGUAGE, MCP_DESKTOP_MODE in the env block.

This is third-party code. Review the repository files before installing.

What it does

The server adds a human checkpoint to the agent's workflow. When the agent calls the tool, a web interface or desktop window opens where the user writes a comment, picks a saved prompt or attaches images. The answer returns to the agent over WebSocket, and the agent adjusts its behavior or ends the task. The server detects the environment (local, SSH Remote, WSL) and opens the right interface, and it keeps session history with statistics and export. It has prompt management, an auto-submit timer, notifications and a multilingual interface.

Who it is for. For developers with coding agents who want a human confirmation and clarification step during long tasks.

Good fit when

  • You want a confirmation before the agent finishes a task or takes a big action
  • You need to pass screenshots or images to the agent
  • You want to gather clarifications in one interactive step rather than back-and-forth

Not a fit when

  • Your MCP client already supports native Elicitation and MCP Apps and that is enough
  • You cannot run a local web interface or open a browser

Example request

Before finishing the task, ask me for confirmation through the feedback window

Limitations

Requires uv or uvx and Python. The web interface and WebSocket run without authentication, so keep the binding on 127.0.0.1 and use SSH port forwarding for remote access. Desktop mode is maintenance-only and scheduled for removal in version 3. Versions 2.6.0 and earlier had an unauthenticated command-execution vulnerability, fixed in 2.6.1, so install a current version. The old point of saving Cursor quota no longer applies.

How to disable. Remove the mcp-feedback-enhanced entry from your agent's MCP configuration.

MCP

Transport
stdio
Authentication
not required
Environment variables
Environment variables
MCP_WEB_HOST
Web interface bind address, default 127.0.0.1. Setting 0.0.0.0 exposes it to the network and is not recommended.
MCP_WEB_PORT
Web interface port, default 8765.
MCP_DESKTOP_MODE
Enables the Tauri desktop mode. It is maintenance-only and will be removed in version 3.
MCP_LANGUAGE
Forces the interface language: zh-TW, zh-CN or en.
MCP_DEBUG
Debug mode, true or false, default false.

Security check

  • Runs a local web server and WebSocket without authentication
  • Earlier versions allowed unauthenticated command execution, so a current version is required

README in short

The README describes an enhanced fork of an interactive-feedback MCP server with two interfaces, a web one and a Tauri desktop one, that offer the same features. The server detects local, SSH Remote and WSL environments and opens the right interface, and supports prompt management, an auto-submit timer, session history with export, image upload and multiple languages. It installs via uvx with an MCP config fragment, and Cursor, Cline, Windsurf, Augment and Trae are named among the clients. A security section notes that 2.6.1 removed command execution and closed cross-site WebSocket hijacking. Desktop mode is now maintenance-only and will be removed in version 3.

FAQ

Is authentication needed?

The web interface and WebSocket run without it, so keep the binding on 127.0.0.1. For remote access use SSH port forwarding rather than binding to 0.0.0.0.

Which version should I install?

A current one (2.6.1 or newer). Versions 2.6.0 and earlier had an unauthenticated command-execution vulnerability that has been removed.

Editors’ pick

Open-source personal AI assistant on your own machine: answers in Telegram, Slack, Discord and WhatsApp, extended with skills and plugins

CLIHigh risk390.7KRepository stars
Editors’ pick

A self-improving agent from Nous Research with a TUI, messaging gateway, cron jobs and skills it writes itself

CLIHigh risk249.8KRepository stars
Editors’ pick

An open source coding agent for the terminal and desktop with build and plan modes

CLIHigh risk210.6KRepository stars
Editors’ pick

Open prompt library with a Claude Code plugin, MCP server and CLI: search, fetch and improve prompts and skills from an agent

PluginMedium risk171.5KRepository stars
Foxx AIMCP Feedback Enhanced

I am Foxx AI and I have already vetted this tool. Ask about install, setup or anything else, and I will keep it simple.