Atlas / MCP servers / cyanheads / Filesystem

FilesystemSAFE

mcp/cyanheads/filesystem-16

A Model Context Protocol (MCP) server for platform-agnostic file capabilities, including advanced search/replace and directory tree traversal

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
10 3r · 5w · 2d
Transport
stdio · streamable-http
License
Apache-2.0
Stars
53
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://www.typescriptlang.org/) [](https://modelcontextprotocol.io/) []() [](https://opensource.org/licenses/Apache-2.0) []() [](https://github.com/cyanheads/filesystem-mcp-server)

Empower your AI agents with robust, platform-agnostic file system capabilities, now with STDIO & Streamable HTTP transport options.

This Model Context Protocol (MCP) server provides a secure and reliable interface for AI agents to interact with the local filesystem. It enables reading, writing, updating, and managing files and directories, backed by a production-ready TypeScript foundation featuring comprehensive logging, error handling, security measures, and now supporting both STDIO and HTTP transports.

Table of Contents

  • Overview
  • Features
  • Installation
  • Configuration
  • Usage with MCP Clients
  • Available Tools
  • Project Structure
  • Development
  • License

Overview

The Model Context Protocol (MCP) is a standard framework allowing AI models to securely interact with external tools and data sources (resources). This server implements the MCP standard to expose essential filesystem operations as tools, enabling AI agents to:

  • Read and analyze file contents.
  • Create, modify, or overwrite files.
  • Manage directories and file paths.
  • Perform targeted updates within files.

Built with TypeScript, the server emphasizes type

Read from source at commit eb9b262c6f07OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add filesystem-mcp-server -- npx -y @cyanheads/[email protected]
claude-desktop
{
  "mcpServers": {
    "filesystem-mcp-server": {
      "command": "npx",
      "args": [
        "-y",
        "@cyanheads/[email protected]"
      ]
    }
  }
}
03

Exposed tools (10)

3 read · 5 write · 2 destructive. Blast radius: 2 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
copy_pathread
create_directorywrite
delete_directorydestructive
delete_filedestructive
list_filesread
move_pathwrite
read_fileread
set_filesystem_defaultwrite
update_filewrite
write_filewrite
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (8 observation(s))
Network
declared (2 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (8)

MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete_directory, delete_file
Why it matters. 2 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.clinerules
.clinerules
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/mcp-server/tools/copyPath/copyPathLogic.ts:4
import { BaseErrorCode, McpError } from '../../../types-global/errors.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/mcp-server/tools/copyPath/copyPathLogic.ts:5
import { logger } from '../../../utils/internal/logger.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/mcp-server/tools/copyPath/copyPathLogic.ts:6
import { RequestContext } from '../../../utils/internal/requestContext.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/mcp-server/tools/copyPath/copyPathLogic.ts:7
import { serverState } from '../../state.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/mcp-server/tools/copyPath/registration.ts:2
import { BaseErrorCode, McpError } from '../../../types-global/errors.js';
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@google/genai, @modelcontextprotocol/sdk, @types/jsonwebtoken, @types/node, @types/sanitize-html, chalk, chrono-node, cli-table3
Why it matters. 28 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha eb9b262c6f07full audit observations/trust-audit/mcp-server/cyanheads__filesystem-16.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08eb9b262c6f07SAFEB89first audit
06

Questions

What is the Filesystem MCP server?

A Model Context Protocol (MCP) server for platform-agnostic file capabilities, including advanced search/replace and directory tree traversal

What tools does Filesystem expose?

10 in total: 3 read-only, 5 that write, and 2 that can delete or overwrite (delete_directory, delete_file). Every one is listed on this page with its risk.

Is Filesystem safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 2 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Filesystem need?

No credential environment variables were found in its source, so it appears to need none.

How does Filesystem run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @cyanheads/filesystem-mcp-server at 1.0.4.

How current is this page?

The grade is for one exact copy of the source (eb9b262c6f07), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement