Index live · v1.7.0 · OCT 6 2026

Filesystem

Official

Secure local file operations with configurable access controls.

stdioTypeScript
575K downloads

Configuration

{
  "mcpServers": {
    "filesystem": {
      "command": "npx",
      "args": [
        "-y",
        "@modelcontextprotocol/server-filesystem",
        "/Users/username/Desktop",
        "/path/to/other/allowed/dir"
      ]
    }
  }
}

Add this to your claude_desktop_config.json file. Copied verbatim from the upstream README.

AgenticSkills Audit

Automated framework checks. Deep code review tracked separately. Read the methodology →

6/7
6 of 7 automated checks passed
Audited Aug 7, 2026
SECURITY.md published
Mitigates: Coordinated disclosure path
Evidence
Commit in last 90 days
Mitigates: Maintainer abandonmentLast push 1 day(s) ago
≥2 active contributors
Mitigates: Bus-factor of one10 contributors with ≥2 commits
Evidence
CI pipeline configured
Mitigates: Code health regression
Evidence
Dependency lockfile committed
Mitigates: Dependency confusionpackage-lock.json
Evidence
Software Bill of Materials (SBOM)
Mitigates: Audit trailNo SBOM file present
License declared
Mitigates: Legal ambiguityOther

Deep framework checks (OAuth 2.1 / PKCE implementation, input validation, sandboxing) require human source review and are tracked separately. This scorecard covers programmatically verifiable signals only.

Quick Stats

Trust LevelOfficial
Transportstdio
API KeyNot required
LanguageTypeScript
CategoryFile Systems & Storage

Tags

fileslocalread-writeaccess-control

Get new MCP servers in your inbox. What we added, what failed the security audit, and why. See a past issue.