AGPL-3.0-or-later · forever.

mcp · anthropic

Filesystem

Read and write local files with path-based access control.

Vendored from the released binary · supernovae-st/nika@5d61b7e13f1f (v0.107.0) · digest-verified, re-derived at build, gated in CI

Call it from a workflow

tasks:
  work:
    invoke: "mcp:filesystem.<tool>"
permits:
  mcp: ["filesystem"]

The permit names the server · absent means the empty boundary, and the run refuses before a call leaves.

Packages · 1

  • npm · @modelcontextprotocol/server-filesystem

Env vars · 1

  • FILESYSTEM_ALLOWED_PATHS

Names only · secrets ride the environment, never a file.