Skip to content
anavem.com

MCP server

Filesystem MCP Server

Reference MCP server from the Model Context Protocol organization. It lets an MCP client read, search, create and edit files and directories inside folders you allow when you start it.

Maintainer
Model Context Protocol organization (reference server in the modelcontextprotocol/servers repository)
Licence
Repository LICENSE: MIT to Apache-2.0 transition (see limitations)
Last release
2026.8.31, released 2026-08-31 (repository-wide release shown on the modelcontextprotocol/servers releases page; the package.json in src/filesystem shows version 0.6.3)
Last verified Jump to what it can access ↓

What it can access

An MCP server gives an AI application a set of capabilities, and it can do only what its code and the credentials you give it allow. This is what the listing states, based on the sources below. Anavem does not rate it safe or unsafe: check it against what you plan to use it for.

Permissions it asks for

  • Read tools (per README): read_text_file, read_media_file, read_multiple_files, list_directory, list_directory_with_sizes, directory_tree, search_files, get_file_info, list_allowed_directories
  • Write tools (per README): write_file, edit_file, create_directory, move_file
  • Operations are limited to directories passed as command-line arguments or set by the client through the MCP Roots protocol

Data it can reach

README states the server only allows operations within the directories you specify via args or Roots. Per the MCP architecture page (modelcontextprotocol.io, 2026-10-03), when Claude Desktop launches the filesystem server it runs locally on the same machine because it uses the STDIO transport; it is a local process, not a hosted service. File contents that the tools return are passed to the AI application you connect it to.

How it is installed or connected

Steps copied from the official README (https://github.com/modelcontextprotocol/servers/tree/main/src/filesystem, read 2026-10-03). The README gives these as claude_desktop_config.json entries; allowed directories are passed as arguments.

  1. NPX, as shown in the README:
{
  "mcpServers": {
    "filesystem": {
      "command": "npx",
      "args": [
        "-y",
        "@modelcontextprotocol/server-filesystem",
        "/Users/username/Desktop",
        "/path/to/other/allowed/dir"
      ]
    }
  }
}
  1. Docker, as shown in the README:
{
  "mcpServers": {
    "filesystem": {
      "command": "docker",
      "args": [
        "run",
        "-i",
        "--rm",
        "--mount", "type=bind,src=/Users/username/Desktop,dst=/projects/Desktop",
        "--mount", "type=bind,src=/path/to/other/allowed/dir,dst=/projects/other/allowed/dir,ro",
        "--mount", "type=bind,src=/path/to/file.txt,dst=/projects/path/to/file.txt",
        "mcp/filesystem",
        "/projects"
      ]
    }
  }
}

The README notes that directories are mounted to /projects and that the ro flag makes a directory read-only for the server, that on Windows npx is launched with cmd /c, and that roots sent by the client completely replace any server-side allowed directories.

Limitations

  • Licence detail: Repository LICENSE: the project is "undergoing a licensing transition from the MIT License to the Apache License, Version 2.0"; new code is Apache-2.0, contributions without relicensing consent remain MIT, and documentation contributions (excluding specifications) are CC-BY-4.0. The src/filesystem README License section states MIT. The package.json license field reads "SEE LICENSE IN LICENSE".
  • The repository README describes the servers as reference implementations meant as educational examples, not production-ready solutions.
  • Includes write-capable tools (write_file, edit_file, create_directory, move_file); the README states operations are restricted to the allowed directories. Its tool table marks write_file, edit_file and move_file as destructive (overwrite or heavily mutate data).
  • Which directories are allowed is set by whoever starts the server or by the client through Roots; the README says the server throws an error at initialization if it has no command-line directories and the client provides no roots.
  • Anavem has not audited this software.

Not sure what to look for? Read what to check before installing.

Quick answers

Who maintains this MCP server?
Model Context Protocol organization (reference server in the modelcontextprotocol/servers repository).
What can it access?
It asks for: Read tools (per README): read_text_file, read_media_file, read_multiple_files, list_directory, list_directory_with_sizes, directory_tree, search_files, get_file_info, list_allowed_directories, Write tools (per README): write_file, edit_file, create_directory, move_file, Operations are limited to directories passed as command-line arguments or set by the client through the MCP Roots protocol. README states the server only allows operations within the directories you specify via args or Roots. Per the MCP architecture page (modelcontextprotocol.io, 2026-10-03), when Claude Desktop launches the filesystem server it runs locally on the same machine because it uses the STDIO transport; it is a local process, not a hosted service. File contents that the tools return are passed to the AI application you connect it to. We do not label anything safe or unsafe; read the official sources before you install.
What licence does it use?
Repository LICENSE: MIT to Apache-2.0 transition (see limitations). Check the terms if you plan to use it commercially.
What are its limitations?
Licence detail: Repository LICENSE: the project is "undergoing a licensing transition from the MIT License to the Apache License, Version 2.0"; new code is Apache-2.0, contributions without relicensing consent remain MIT, and documentation contributions (excluding specifications) are CC-BY-4.0. The src/filesystem README License section states MIT. The package.json license field reads "SEE LICENSE IN LICENSE". The repository README describes the servers as reference implementations meant as educational examples, not production-ready solutions. Includes write-capable tools (write_file, edit_file, create_directory, move_file); the README states operations are restricted to the allowed directories. Its tool table marks write_file, edit_file and move_file as destructive (overwrite or heavily mutate data). Which directories are allowed is set by whoever starts the server or by the client through Roots; the README says the server throws an error at initialization if it has no command-line directories and the client provides no roots. Anavem has not audited this software.
When was it last released?
2026.8.31, released 2026-08-31 (repository-wide release shown on the modelcontextprotocol/servers releases page; the package.json in src/filesystem shows version 0.6.3). Verified Oct 3, 2026.

Sources

Other listings in the same category.

All MCP servers →