Filesystem MCP
Official MCP reference server for controlled local file operations within allowed directories.
- Skill Road
- Filesystem MCP
Categories
Description
What Filesystem MCP is for
Filesystem MCP is an official Model Context Protocol reference server for local file operations. It is maintained in the modelcontextprotocol/servers repository, and the npm package is published as @modelcontextprotocol/server-filesystem. Its value is not a flashy niche feature; it provides one of the most important foundations for practical AI agents: controlled access to files and directories. An agent can read project files, compare multiple files, create new files, apply targeted edits, inspect directory trees, and retrieve metadata without the user manually pasting every relevant file into the chat.
Capabilities and practical use cases
According to the official README, the server supports tools including read_text_file, read_media_file, read_multiple_files, write_file, edit_file, create_directory, list_directory, directory_tree, move_file, search_files, get_file_info, and list_allowed_directories. That toolset makes Filesystem MCP useful for coding agents, technical writing, documentation maintenance, and local knowledge bases. In a software project, an assistant can inspect configuration files, update documentation, find tests, or prepare small refactors. In an editorial workflow, the same server can make local Markdown or text collections available for structured review.
The strength of the server is also its main responsibility: it operates on the local filesystem. That makes it much more powerful than a simple search tool, but also riskier. Write-oriented tools can create, overwrite, move, or modify files. For real work, this is valuable because an agent can prepare actual changes instead of only suggesting them. For experiments or directories containing sensitive information, broad access would be the wrong default.
Directory access control and Roots
Filesystem MCP restricts access to allowed directories. According to the documentation, those directories can be passed as command-line arguments at startup or supplied dynamically by the client through the MCP Roots protocol. When the client supports Roots, it can provide allowed directories during initialization and later update them through roots/list_changed notifications. Roots supplied by the client fully replace server-side directories. If the server starts without command-line arguments and the client does not provide Roots, initialization fails according to the README.
That detail matters in practice. Do not expose the whole home directory, the whole disk, or folders containing SSH keys, browser profiles, production configuration, or credentials. Narrow project folders are the safer pattern, ideally under version control. Docker deployments can add another guardrail by mounting directories read-only when write access is not required. The list_allowed_directories tool helps the user or host inspect which paths are currently available.
Installation and operation
The typical start command in the documentation uses npx, for example npx -y @modelcontextprotocol/server-filesystem /path/to/project. Docker is also supported. In MCP clients, the server is registered as a stdio server; allowed paths are either listed in args or supplied through Roots. The server itself does not require an account with an external service and does not introduce a vendor subscription. The relevant permission boundary is the local operating-system account: what that account can read or write inside the allowed directory can generally be reached through the MCP tool.
Who benefits most from Filesystem MCP?
Filesystem MCP is useful for users who want AI agents to work with local files while still placing a clear boundary around where they may operate. Common questions are important: Is it free? Yes, according to the project it is open source; only your own runtime environment may cost money. Is it safe? Only with narrow Roots, backups, and a review workflow. Can it damage files? Yes, write and move tools can make real changes. The best setup is a clearly scoped working directory where agent assistance is welcome and every change can be reviewed through version control.
Requirements
An MCP client plus Node.js with npx, or Docker as an alternative. At least one allowed directory must be passed at startup unless the client supplies MCP Roots.
Installation instructions
Start the server through npx and append every allowed directory as a separate argument. Alternatively, the client can set directories dynamically through MCP Roots; supplied roots completely replace directories passed at startup.
With Docker, allowed paths must be mounted into the container. Mark mounts with ro when only read access is required.
npx -y @modelcontextprotocol/server-filesystem /pfad/zum/verzeichnis
Authentication
No separate login. The server runs locally over stdio. Access is governed by the operating-system account and the directories allowed at startup or through MCP Roots.
Required access permissions
Read and, by default, write permissions of the executing account inside the allowed directories. Tools can read, create, overwrite, edit, and move files and create directories. Read-only Docker mounts can restrict access to reading.
Transmitted or stored data
File contents, names, paths, directory trees, and metadata from allowed directories are sent to the MCP client and potentially to its language model. Write operations modify or store data directly in the local filesystem. The server itself does not send files to an external service of its own.
Security risks
Overly broad roots can expose confidential files. Write tools can overwrite, move, or create content; the official tool annotations explicitly classify several operations as potentially destructive. Allow narrowly scoped project folders, exclude sensitive paths, enable write access only when needed, and version or back up changes.
License and costs
- License
- Apache-2.0 / MIT (transitional)
- Cost
- free
The reference server is open-source and free. Only your own runtime environment may incur costs.
Alternatives
At a glance
- Provider
- Model Context Protocol
- Status
- Official server
- Deployment
- Local
- Current version
- 2026.8.31
- Last reviewed
- 06.09.2026
Repository and documentation
Categories
Supported clients
Related guides
Guides and background related to this entry.
Set up the Box MCP Server safely
Connect Box MCP through OAuth using a test account, keep enterprise scopes narrow, and approve file changes deliberately.
18.09.2026
Setting up the OpenAI PDF Skill and reviewing PDF output
OpenAI’s PDF Skill combines ReportLab, text extraction, and rendering so PDF outputs are checked visually, not only for extracted text.
09.09.2026
Setting up Filesystem MCP securely
Configure Filesystem MCP with narrowly scoped directories, MCP Roots, or read-only Docker mounts.
03.09.2026