Atlas / MCP servers / efforthye / Fast Filesystem

Fast FilesystemCAUTION

mcp/efforthye/fast-filesystem

A high-performance Model Context Protocol (MCP) server that provides secure filesystem access for Claude and other AI assistants.

Verdict
CAUTION
Grade
B
Trust score
86 /100
Exposed tools
25 15r · 9w · 1d
Transport
stdio · streamable-http
License
Apache-2.0
Stars
63
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Advanced filesystem operations for Claude Desktop with large file handling capabilities and Claude-optimized features.

Quick Start

Add to your Claude Desktop config.

  • Basic setup
{
"mcpServers": {
"fast-filesystem": {
"command": "npx",
"args": ["-y", "fast-filesystem-mcp"]
}
}
}
  • With backup files enabled
{
"mcpServers": {
"fast-filesystem": {
"command": "npx",
"args": ["-y", "fast-filesystem-mcp"],
"env": {
"CREATE_BACKUP_FILES": "true"
}
}
}
}

Backup Configuration

Control backup file creation behavior.

  • CREATE_BACKUP_FILES=false (default): Disables backup file creation to reduce clutter
  • CREATE_BACKUP_FILES=true: Creates backup files before modifications

Note: Backup files are created with timestamps (e.g., file.txt.backup.1755485284402) to prevent data loss during edits.

Debug and Logging Configuration

The MCP server uses a safe logging system that prevents JSON-RPC communication errors.

  • DEBUG_MCP=true or MCP_DEBUG=true: Enable debug logging to stderr
  • MCP_LOG_FILE=/path/to/log.txt: Write logs to file instead of stderr
  • MCP_SILENT_ERRORS=true or SILENT_ERRORS=true: Suppress error messages in responses

Note: Debug output is automatically suppressed by default to prevent JSON parsing errors in Claude Desktop.

New Version Update

To update to the latest version, follow these steps.

  1. Uninstall previous version
npm uninstall -g fast-filesystem-mcp
  1. Clean cache and dependencies
npm cache clean --force
pnpm store prune
  1. Install latest version
npm i
Read from source at commit b15349fbd3e0OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add fast-filesystem-mcp -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "fast-filesystem-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ]
    }
  }
}
03

Exposed tools (25)

15 read · 9 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
fast_batch_file_operationsreadPerforms batch operations on multiple files
fast_compress_filesreadCompresses files or directories
fast_copy_filereadCopies a file or directory
fast_create_directorywrite디렉토리를 생성합니다
fast_delete_filedestructiveDeletes a file or directory
fast_edit_blockwritePrecise block editing: safely replace exact matches (desktop-commander style)
fast_edit_blockswriteProcesses multiple precise block edits at once (array of fast_edit_block)
fast_edit_multiple_blockswriteEdits multiple parts of a file at once
fast_extract_archivereadExtracts an archive file
fast_extract_linesreadExtracts specific lines from a file
fast_find_large_filesread큰 파일들을 찾습니다
fast_get_directory_treeread디렉토리 트리 구조를 가져옵니다
fast_get_disk_usageread디스크 사용량을 조회합니다
fast_get_file_inforead파일/디렉토리 상세 정보를 조회합니다
fast_large_write_filewriteReliably writes large files (with streaming, retry, backup, and verification features)
fast_list_allowed_directoriesread허용된 디렉토리 목록을 조회합니다
fast_list_directoryread디렉토리 목록을 조회합니다 (페이징 지원)
fast_move_filewriteMoves or renames a file or directory
fast_read_fileread파일을 읽습니다 (청킹 지원)
fast_read_multiple_filesreadReads the content of multiple files simultaneously (supports sequential reading)
fast_safe_editwriteSafe smart editing: Detects risks and provides interactive confirmation
fast_search_codereadSearches for code (ripgrep-style) - provides auto-chunking, line numbers, and context
fast_search_filesread파일을 검색합니다 (이름/내용)
fast_sync_directorieswriteSynchronizes two directories
fast_write_filewrite파일을 쓰거나 수정합니다
04

Trust audit

CAUTIONgrade B · trust 86/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (4 observation(s))
Network
declared (4 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (9)

MEDIUMInventory / provenance · inv.binary · CWE-1104
.DS_Store
.DS_Store
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
scripts/benchmark-logger.mjs:182
console.log(`   Console.log:           ${timePerOp(consoleTime)}μs`);
MEDIUMObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
scripts/benchmark-logger.mjs:183
console.log(`   Logger (DEBUG=false):  ${timePerOp(loggerOffTime)}μs`);
MEDIUMObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
scripts/benchmark-logger.mjs:184
console.log(`   Logger (DEBUG=true):   ${timePerOp(loggerOnTime)}μs`);
MEDIUMObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
scripts/benchmark-logger.mjs:185
console.log(`   Logger (File):         ${timePerOp(loggerFileTime)}μs\n`);
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
fast_delete_file
Why it matters. 1 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.DS_Store
.DS_Store
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.vercelignore
.vercelignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, @vscode/ripgrep, @types/node, tsx, typescript
Why it matters. 5 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha b15349fbd3e0full audit observations/trust-audit/mcp-server/efforthye__fast-filesystem.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07b15349fbd3e0CAUTIONB86first audit
06

Questions

What is the Fast Filesystem MCP server?

A high-performance Model Context Protocol (MCP) server that provides secure filesystem access for Claude and other AI assistants.

What tools does Fast Filesystem expose?

25 in total: 15 read-only, 9 that write, and 1 that can delete or overwrite (fast_delete_file). Every one is listed on this page with its risk.

Is Fast Filesystem safe to connect to an agent?

With care. The audit graded it B (86/100) and found 9 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Fast Filesystem need?

No credential environment variables were found in its source, so it appears to need none.

How does Fast Filesystem run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as fast-filesystem-mcp at 3.5.2.

How current is this page?

The grade is for one exact copy of the source (b15349fbd3e0), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement