Filesystem
90,704 starsOfficial MCP reference server: secure file operations (read, write, create, move, delete, search) strictly inside the directories you explicitly allow, configured via command-line arguments or MCP Roots.
- First published:2024-11-20
- data as of:
- 2026-09-30
- Licence:
- MIT / Apache-2.0(repo 正在授權轉移,見 repo LICENSE)
- Transport:
- stdio
- Primitives exposed:
- tools
What it can touch
Full read/write over every file in the directories you allow, including delete, move and directory creation. No network, no databases. The allowed scope is set by launch arguments or MCP Roots, and the server process runs with your own user privileges.
Risk
Granting a too-wide directory (e.g. your whole home) hands your disk to the agent: an injected agent can delete or rewrite files inside the scope and exfiltrate their content through other tools. The official README warns these reference servers are educational examples, not production-grade; keep the allowed directories minimal.
Install prompt
從官方參考 server 倉庫取得 Filesystem server 的說明,把 README 提供的客戶端設定片段(以 npx 啟動 @modelcontextprotocol/server-filesystem,並把允許的目錄作為參數傳入)加進你的 MCP 客戶端設定檔,然後重啟客戶端。Paste this to your agent. It deliberately contains no tool subcommands — check the tool's official docs for commands.