MCP server for secure filesystem access with caching, rate limiting, and configuration management
This filesystem MCP server demonstrates solid definition quality with 12 well-named tools, consistent descriptions, and clear parameter schemas. All tools start with action verbs (read_, write_, create_, list_, move_, search_, delete_, get_). Descriptions are present and informative (averaging 120-180 chars), explaining what each tool does. Input schemas use proper JSON Schema with types and descriptions for all parameters. However, there are gaps: (1) no documented output schemas visible in the source, the code implements handlers but doesn't declare what fields/structure responses contain; (2) no tool annotations (readOnlyHint, destructiveHint, idempotentHint) despite clear risk levels marked in the tool list; (3) error handling is basic, the code catches exceptions but doesn't return structured recovery guidance; (4) missing pagination parameters on list/search tools despite the risk of large results. The read_multiple_files and similar tools lack guidance on batch result structure. The move_file tool lacks a confirmation/dry-run pattern for destructive operations. Overall, a competent server suitable for production use with minor enhancements.
Create a new directory. If the directory already exists, this will succeed without doing anything.
Delete a file. Note that directories cannot be deleted using this tool.
Get a recursive tree view of a directory's contents with depth control. Returns a structured view of the directory hierarchy.
Edit a file by specifying a series of find-and-replace operations. Each operation replaces the first occurrence of the old text with the new text. All operations are applied sequentially.
Get detailed metadata about a file or directory including size, creation/modification times, and permissions.
List the contents of a directory. Returns an array of entries in the directory, each with basic metadata (type, size for files).
No documented output schemas. The code implements tool handlers but does not declare the structure, fields, or types of responses. LLMs cannot reason about downstream tool chains or extract specific fields without knowing the response schema.
No tool annotations (readOnlyHint, destructiveHint, idempotentHint) despite clear risk levels. The server marks tools as READ_ONLY, WRITE, or DESTRUCTIVE but does not communicate these via the MCP tool annotations feature.
List/search tools lack pagination parameters (limit, offset, page_size). Without pagination, tools like list_directory and search_files could return unbounded results, exhausting context windows and degrading LLM reasoning.
Inferred effective spec: <=2025-11-25.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | B | 79 | <=2025-11-25 | v2 |
| 2026-03-09 | F | 0 | - | v1 |
List directory contents with detailed file size information. Entries can be sorted by name or size.
Move or rename a file or directory. The destination path must not already exist.
Read the complete contents of a file. If the file does not exist, an error will be returned. Note that this can only read files, not directories.
Read multiple files at once. If any file does not exist or is not readable, an error will be returned for that file, but other files will still be read.
Search for files and directories matching a pattern within a specified path. Search is case-insensitive.
Create a new file or overwrite an existing file with the provided content. If the file already exists, it will be completely replaced.
Limited error recovery guidance. Error handling is present in the code but likely returns generic exceptions. LLMs need structured error messages that say what went wrong and what to try next (e.g., 'Path outside allowed directories. Allowed: [list]').
No dry-run or confirmation pattern for destructive operations. delete_file and move_file are marked DESTRUCTIVE but lack a dry-run or confirmation option to prevent accidental data loss.
move_file description lacks clarity on behavior when destination exists. The description says 'must not already exist' but does not explain what error is returned or how to recover.
read_multiple_files lacks per-item error reporting. When multiple files fail, the tool should return per-file success/failure, not a blanket error that forces retry of all files.