modelcontextprotocol · MCP server
MCP server for filesystem access
Not claimed by its maker. Is this yours? Prove it and answer the findings
Published because it was found. A finding is information about where the limits are, not a verdict that the software is unsafe.
Receipt history: every signed receipt for every version of this listing, and what changed between them.
MCP server for filesystem access
Static scanned
Paste this into your client's MCP configuration.
{
"mcpServers": {
"mcp-server-filesystem": {
"command": "npx",
"args": [
"-y",
"@modelcontextprotocol/server-filesystem@2026.8.31"
]
}
}
}Or run it directly.
npx -y @modelcontextprotocol/server-filesystem@2026.8.31Pinned to 2026.8.31, which is the version the findings above were found in. Drop the version to take whatever is newest, and the report on this page stops describing what you installed.
2,748,976 installs last month (via ecosyste.ms) · build provenance signed · no published advisories · version current · checked 2026-10-04
Built from source, attested
npm publishes a signed statement that this exact package was built from the repository below, at this commit. It is verifiable without taking our word for it.
It renders the current rung (static scanned) and links back here, where what that does and does not establish is one click away. It updates itself as the evidence deepens.
[](https://ooruby.com/market/modelcontextprotocol-server-filesystem)Verification records what our published tests found on a specific version at a specific date. It is not a warranty, and it does not certify that software is free of defects.
MCP server for loading and extracting text from PDF files with chunked pagination and interactive viewer
MCP server for sequential thinking and problem solving
MCP server that exercises all the features of the MCP protocol
Maintenance
MaintainedA release on 31 Aug 2026 (2026.8.31), 23 days before this check on 23 Sep 2026. Anything later would only be more recent.
Read from the npm registry, read by the weekly version refresh.
Release activity only: it says nothing about quality or safety, and a finished small package can be fine without releases. How it is measured