Skip to main content
AgentsUse

MCP server, by Model Context Protocol

Filesystem MCP Server

Node.js MCP server for reading, writing, searching and managing files inside explicitly allowed directories.

stdio (local process)Checked 2026-10-07Config checked

Quick facts

Transport
stdio (local process)
Runs as
npx (@modelcontextprotocol/server-filesystem)
Review state
Config checked against the official source. Facts checked 2026-10-07. Not locally tested by AgentsUse.

What it does

The filesystem server gives an MCP client controlled access to local directories. You pass allowed paths as command line arguments, or a client that supports Roots can supply and update them at runtime. If neither source provides a directory, the server fails during initialization rather than running unrestricted.

Tool annotations mark read only operations separately from writes, flag idempotent calls, and mark destructive operations such as overwrites and moves. Every tool reports openWorldHint false because access stays inside the allowed local directories.

It is published as an npm package and can also run in Docker with directories mounted under /projects, including read only mounts.

Configuration

Run with npx and pass one or more allowed directory paths as arguments, or run the Docker image with bind mounts under /projects.

MCP config (placeholders)
{
  "mcpServers": {
    "filesystem": {
      "command": "npx",
      "args": ["-y", "@modelcontextprotocol/server-filesystem", "/path/to/allowed/dir"]
    }
  }
}

Source: https://github.com/modelcontextprotocol/servers/tree/main/src/filesystem. Placeholders only. Replace them in your own environment, and never commit real keys to a repository.

No environment variables are required per the official documentation.

Verified tools and features

  • read_text_file Config checked

    Reads a file as UTF-8 text, with optional head or tail line limits.

  • write_file and edit_file Config checked

    Creates or overwrites files, and applies selective text edits with dry run diff previews.

  • search_files and directory_tree Config checked

    Recursively searches with glob patterns and returns a JSON tree of directory contents.

  • list_allowed_directories Config checked

    Lists the directories the server is currently permitted to access.

Security notes

Security notes
  • Access is restricted to directories passed as arguments or supplied through MCP Roots. At least one allowed directory is required.
  • Write tools can overwrite and move files. Use the smallest directory scope possible and prefer read only Docker mounts where writes are not needed.
  • No network access is claimed by the tools. openWorldHint is false for all filesystem tools.

An MCP server runs with the permissions of the process you start it from. Scope credentials to the narrowest access the job needs, and review what the client will send before connecting anything sensitive.

Stacks featuring this server

Sources and freshness

Last checked 2026-10-07. Verification label: config checked, which means the configuration and feature list trace to the official source above. It does not mean AgentsUse ran the server. Spotted an error? Send a correction. Back to the MCP server index.