MCP Reference Filesystem
Reference server for controlled filesystem read/write access within an approved root.
Automated danger grade: this page reports detected or inferred risk from a scan. It is not an endorsement, certification, or claim that the server is malicious.
Grade history
14 scans on record between 2026-06-20 and 2026-07-04. The grade has not changed across them.
| Scanned (UTC) | Grade | Engine | Attributed cause |
|---|---|---|---|
| 2026-06-20 06:52 | D | mcpaudit 2.1.0 | First scan on record |
| 2026-06-20 07:10 | D | mcpaudit 2.1.0 | No change |
| 2026-07-03 02:50 | D | mcpaudit 2.1.0 | No change |
| 2026-07-03 09:44 | D | mcpaudit 2.3.0 | No change |
| 2026-07-03 10:00 | D | mcpaudit 2.3.0 | No change |
| 2026-07-03 10:02 | D | mcpaudit 2.3.0 | No change |
| 2026-07-03 10:12 | D | mcpaudit 2.3.0 | No change |
| 2026-07-03 10:16 | D | mcpaudit 2.3.0 | No change |
| 2026-07-03 12:42 | D | mcpaudit 2.3.0 | No change |
| 2026-07-03 13:21 | D | mcpaudit 2.4.0 | No change |
| 2026-07-03 14:13 | D | mcpaudit 2.4.0 | No change |
| 2026-07-04 08:13 | D | mcpaudit 2.4.0 | No change |
| 2026-07-04 08:16 | D | mcpaudit 2.4.0 | No change |
| 2026-07-04 08:18 | D | mcpaudit 2.4.0 | No change |
History as recorded by this registry's own scans. The cause is an attribution from the inputs the registry records — the scanner engine identity and the declared tool surface — not proof of what changed on the server. Generated 2026-08-02.
How to read this grade
- What was scanned: @modelcontextprotocol/server-filesystem, as distributed.
- When: 2026-07-04 08:18:09.
- By what: mcpaudit 2.4.0, applied to the published danger rubric (weights, bands, and the critical cap are all public).
- What the grade means: this registry's opinion, computed by the disclosed automated methodology against the artifact version above, on the scan date above. It measures conformance to the rubric at scan time.
- What it does not claim: it is not a statement that the product is malicious, insecure in your deployment, or unfit for use, and it is not an endorsement or certification.
- Disagree? Grades are re-checkable against the same package version, and corrections are welcome: open a dispute — see the dispute & correction policy.
Spec-shift exposure
BREAKS against MCP 2026-07-28-rc · confidence medium · ruled 2026-07-18
| Dimension | Area | Verdict |
|---|---|---|
| D1 | Stateless-core compatibility | BREAKS |
| D2 | Deprecated-capability reliance | READY |
| D3 | Authorization posture | N_A |
| D4 | Schema and wire conformance | READY |
| D5 | Extensions readiness | NOTE |
What to change
- D1 [small] Drop the server.server.oninitialized assignment at dist/index.js:600 and establish roots without depending on handshake-time state - fetch them on first use, or accept them as tool parameters or server configuration. The surviving roots/list_changed handler at :587 already proves the non-handshake path works; it just needs an establishment entry point as well as a change entry point.
This is a point-in-time ruling against a release candidate, not the published specification, and it is independent of the danger grade above. Neither figure constrains the other.
Provenance & dispute
- Listing basis: operator-listed from a public catalog. This entry was not submitted by its vendor.
- Scan target: the published npm artifact
@modelcontextprotocol/server-filesystem, installed and scanned locally using sandbox imagemcp-trust-scan:corpus-2026-07-03. The public record stores the sandbox image, but not the network mode, so this page does not claim network isolation for that run. - Credentials: none declared, none used.
- Dispute: vendor or maintainer of this server? Dispute this grade — first response within 14 days.
Add this badge to your README
Copy the Markdown below only if you want to link readers to the latest danger grade and scan caveats:
[](https://mcp-trust.vercel.app/ui/servers/mcp-reference-filesystem)
Findings
| Severity | Rule | Title | Category | Detail |
|---|---|---|---|---|
| low | MCP001 | File read capability | file_read | readOnlyHint=true |
| low | MCP003 | Network access capability | network | openWorldHint=null (spec default: true) |
| low | MCP001 | File read capability | file_read | readOnlyHint=true |
| low | MCP003 | Network access capability | network | openWorldHint=null (spec default: true) |
| low | MCP001 | File read capability | file_read | readOnlyHint=true |
| low | MCP003 | Network access capability | network | openWorldHint=null (spec default: true) |
| low | MCP001 | File read capability | file_read | readOnlyHint=true |
| low | MCP003 | Network access capability | network | openWorldHint=null (spec default: true) |
| low | MCP005 | Destructive operation capability | destructive | destructiveHint=true |
| low | MCP003 | Network access capability | network | openWorldHint=null (spec default: true) |
| medium | MCP001 | File read capability | file_read | path |
| high | MCP002 | File write capability | file_write | write_file; write; overwrite; create |
| low | MCP005 | Destructive operation capability | destructive | destructiveHint=true |
| low | MCP003 | Network access capability | network | openWorldHint=null (spec default: true) |
| medium | MCP001 | File read capability | file_read | path |
| high | MCP002 | File write capability | file_write | edit_file |
| low | MCP004 | Shell execution capability | shell_execution | run |
| low | MCP003 | Network access capability | network | openWorldHint=null (spec default: true) |
| high | MCP001 | File read capability | file_read | path; directory |
| medium | MCP002 | File write capability | file_write | create |
| low | MCP001 | File read capability | file_read | readOnlyHint=true |
| low | MCP003 | Network access capability | network | openWorldHint=null (spec default: true) |
| low | MCP001 | File read capability | file_read | readOnlyHint=true |
| low | MCP003 | Network access capability | network | openWorldHint=null (spec default: true) |
| low | MCP001 | File read capability | file_read | readOnlyHint=true |
| low | MCP003 | Network access capability | network | openWorldHint=null (spec default: true) |
| medium | MCP006 | Data exfiltration capability | exfiltration | output |
| low | MCP003 | Network access capability | network | openWorldHint=null (spec default: true) |
| high | MCP001 | File read capability | file_read | directory; source |
| high | MCP002 | File write capability | file_write | move_file; destination |
| low | MCP001 | File read capability | file_read | readOnlyHint=true |
| low | MCP003 | Network access capability | network | openWorldHint=null (spec default: true) |
| low | MCP001 | File read capability | file_read | readOnlyHint=true |
| low | MCP003 | Network access capability | network | openWorldHint=null (spec default: true) |
| low | MCP001 | File read capability | file_read | readOnlyHint=true |
| low | MCP003 | Network access capability | network | openWorldHint=null (spec default: true) |
Score breakdown
| Dimension | Raw (0–10) | Weight | Weighted |
|---|---|---|---|
| File access | 1.8 | ×1.2 | 2.16 |
| Network access | 1.5 | ×1.0 | 1.50 |
| Shell execution | 0.9 | ×2.0 | 1.80 |
| Destructive | 2.0 | ×0.3 | 0.60 |
| Exfiltration | 1.5 | ×0.4 | 0.60 |