MCP/Risk

Directory / server

@modelcontextprotocol/server-filesystem

registry.modelcontextprotocol.io, scanned 2026-09-09, tool surface via package-source

This directory entry reports an automated security scan of @modelcontextprotocol/server-filesystem, scanned 2026-09-09. Trust grade B rates provenance, transport, known vulnerabilities and instruction integrity; capability risk is reported separately, not folded into the grade.

Automated checks

StatusCheckPolicyResult
WARN Listed on the official MCP registry §1.1

Not found on the official MCP registry. Not disqualifying, but listed servers carry namespace-verified provenance.

PASS Source repository is public and maintained §1.2
Active repository with a license. 5 findings
  • Repository
  • Last push: 6 days ago
  • Stars: 90186
  • License: NOASSERTION
  • Security policy (SECURITY.md): absent
PASS Published package is consistent and attested §1.3
Package is consistent with its source and carries provenance attestation. 6 findings
  • Package: @modelcontextprotocol/server-filesystem@2026.8.31
  • Ecosystem: npm
  • Age: 656 days
  • Weekly downloads: 954129
  • Repo field matches source repo: true
  • Build-provenance attestation: present
PASS Tool surface is inspectable and proportionate §2.1–§2.4
Package source scanned. Capabilities detected: filesystem. Reported as capability risk (§2.4); whether each is essential to the server's stated purpose is §2.3 and remains a manual judgement. 5 findings
  • filesystem (filesystem write/delete): dist/index.js
  • filesystem (fs module import): dist/index.js
  • filesystem (filesystem write/delete): dist/roots-utils.js
  • filesystem (fs module import): dist/roots-utils.js
  • Detected capabilities: filesystem
INFO Transport & authentication §3

Local (stdio) server: runs with host-process privileges by design. Transport checks apply to remote servers; scrutiny shifts to §1/§2.

FAIL No known vulnerabilities (OSV.dev) §4.1
2 advisory(ies) on record for @modelcontextprotocol/server-filesystem @2026.8.31 (npm) - review whether the evaluated version is affected. 2 findings
  • GHSA-hc55-p739-j48w: @modelcontextprotocol/server-filesystem vulnerability allows for path validation bypass via colliding path prefix
  • GHSA-q66q-fx2p-7w4m: @modelcontextprotocol/server-filesystem allows for path validation bypass via prefix matching and symlink handling
PASS Server-supplied instructions free of poisoning indicators §5.1–§5.4

No poisoning indicators found across 14 server-supplied text item(s).

Score history

DateGradeScore
2026-09-09B81/100
2026-07-26B81/100
2026-07-25D59/100
2026-07-12D59/100
What this grade covers
  • Provenance & supply-chain integrity (§1)
  • Tool surface & capability risk (§2)
  • Transport & authentication (§3)
  • Known CVEs via OSV.dev (§4)
  • Instruction/tool poisoning patterns (§5)

Limitations: pattern-based only (no semantic injection detection), static npm analysis (live server instructions not retrieved for package-only scans), single-server scope (no cross-server toxic flow analysis). See the full policy.

Methodology: MCP Server Security Policy. Unfamiliar term? See the glossary.