High-performance MCP server for filesystem operations with caching, parallel execution, and advanced features
This server has 26 tools with inconsistent quality. Most tool names are appropriately verb-prefixed (efs_read, efs_write, etc.), but descriptions are often superficial (10-50 chars), parameter documentation is minimal or absent for many tools, and schemas lack proper structure. The server explicitly registers tools via setupFileTools() and similar functions in src/index.ts, confirming definitions are visible. However, critical tools like efs_python, efs_exec, and windows_tool expose dangerous parameters (shell choice, arbitrary environment vars) without proper validation or security guidance. Many utility tools (ollama_tool, process_tool, json_tool, windows_tool, model_tool) have minimal input schema, the code shows operation strings like {'operation': {'type': 'string'}} with no enums or validation, forcing LLMs to guess valid operation names. Output schemas are completely undocumented across all 26 tools. Error handling is basic wrap() functions that return plain text, offering no recovery guidance or categorization. Per-tool analysis reveals ~8 tools with reasonable schemas (efs_read, efs_write, efs_list, efs_edit, http_tool, archive_tool, download_tool), while 18 others are severely underdefined.
Analyze TypeScript/JavaScript code for symbols, functions, classes, and structure
Create, extract, and manage zip archives with compression and content listing
Read from and write to system clipboard with text and file support
Compare files and directories with unified diff format and binary detection
Download files from URLs with progress tracking, resume, and auto-placement for models
Execute multiple file operations atomically with rollback support
Delete a file or directory recursively
Edit file by replacing oldText with newText with optional dry-run and count limits
Generic operation-string parameters with no enum constraints or validation guidance. Tools like ollama_tool, process_tool, windows_tool, model_tool accept operation:string with no defined valid values. LLMs must guess operation names (e.g., 'status'? 'info'? 'get_status'?), leading to silent failures.
Dangerous tools (efs_exec, efs_python, ssh_tool) expose shell/environment parameters without security warnings or input validation guidance. efs_exec accepts arbitrary 'shell' choice (cmd, bash, sh, powershell) and efs_python accepts arbitrary install arrays with no sanitization mention. ssh_tool accepts plaintext passwords as parameters.
No output schemas documented. All 26 tools lack documented return types and response structures. LLMs cannot plan downstream tool calls or extract required fields without knowing what data a tool returns. This violates the pattern:tool baseline (100% of A+ tools have documented return types).
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | F | 45 | 2026-07-28+ | v2 |
| 2026-03-09 | F | 0 | - | v1 |
Execute shell commands with working directory, timeout, and environment variables
Execute git operations including commit, pull, push, and status
Get file or directory information including stats, encoding, and git status
List directory contents with optional depth, pattern filtering, and sorting
Move or rename a file or directory
Execute Python code with session management, libraries, and output capture
Read file contents with optional offset, length, and encoding parameters
Search for files and content with regex, case sensitivity, and limit options
Write content to a file with optional mode (overwrite/append) and encoding
Calculate file and text hashes using MD5, SHA1, SHA256, SHA512
Make HTTP/HTTPS requests with headers, body, authentication, and response parsing
Parse, query, and manipulate JSON with deep path support and transformation
Manage AI model files including metadata, conversion, and optimization
Execute Ollama operations for local LLM inference
Execute and manage system processes with PID tracking and signal handling
Execute commands over SSH with file transfer and tunneling capabilities
Windows-specific operations including Registry, PowerShell, and system tasks
Parse, query, and manipulate YAML files with deep path support
Minimal descriptions for many tools. 11 tools have descriptions under 40 characters (ollama_tool: 'Execute Ollama operations for local LLM inference', process_tool: 'Execute and manage system processes with PID tracking and signal handling', windows_tool: 'Windows-specific operations including Registry, PowerShell, and system tasks', model_tool: 'Manage AI model files including metadata, conversion, and optimization', analysis_tool: 'Analyze TypeScript/JavaScript code for symbols, functions, classes, and structure'). These are too generic to guide LLM selection or explain when each tool is appropriate.
Parameter descriptions missing or trivial for many tools. efs_delete and efs_move lack descriptions beyond the path field. windows_tool's 'operation' parameter has only 'Windows operation' as description. ollama_tool's 'operation' is just 'Ollama operation'. This forces LLMs to infer valid values.
Error handling is rudimentary. wrap() function catches all errors and returns plain text messages like 'Git failed: ...' with no recovery guidance, no error classification (retryable vs fatal), and no actionable next steps. LLMs receive no signal about what to do after a failure.
Destructive tools (efs_delete, efs_move, efs_exec, efs_python) lack confirmation or dry-run patterns. No tool description warns that efs_delete is recursive and irreversible. LLMs could accidentally delete entire directory trees without a confirm_before_execute pattern.
No pagination support in list-returning tools. efs_list, efs_search, and efs_batch return potentially hundreds of results with no documented limit, no offset/page parameters, and no total_count in response. Large directory traversals could overwhelm context windows.
Inconsistent parameter naming conventions. Some tools use snake_case (session_id, case_sensitive), others use camelCase internally. Field mappings between tools are not documented, it's unclear if efs_list returns 'path' or 'filepath' or 'file_path', making it hard for LLMs to chain tool calls.
No security scopes declared. Pattern:scope-declaration requires each tool to declare what permissions it requires (e.g., 'read:filesystem', 'write:filesystem', 'exec:shell'). This server has none, making it impossible to configure least-privilege agent policies or generate audit trails.