agentic-filesystem-mcp
A secure, highly capable MCP server written in Rust. It exposes a comprehensive suite of filesystem operations as tools for AI agents.
Install / Use
claude mcp add KubaZ2 -- npx -y github:KubaZ2/agentic-filesystem-mcpIf the server publishes to npm under a different name, use that package instead — check the repo README.
MCP Server
Model Context Protocol server
Quality Score
Category
SecuritySupported Platforms
Our assessment of agentic-filesystem-mcp
agentic-filesystem-mcp scores 75/100 on our quality scale, 1038th of 1,116 Security skills we index.
Its MCP Server is 9.0 KB long, well organised into 17 sections with 7 code examples: a thorough specification that gives an agent plenty to work with.
It has 3 GitHub stars, so there is little community track record yet; judge it on its content.
Maintenance, license and trust
- The repository was last updated today, so agentic-filesystem-mcp is actively maintained.
- It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
- Its trust signals score 92/100, with 1 caution from licensing, adoption, age or documentation. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.
agentic-filesystem-mcp compared with similar skills
All 4 of these similar skills score higher than agentic-filesystem-mcp; compare them before choosing.
| Skill | Score | Stars | Updated | Format |
|---|---|---|---|---|
| agentic-filesystem-mcp (this skill)by KubaZ2 | 75 | 3 | today | MCP Server |
| Agent-Reachby Panniantong | 100 | 91.8k | 20d ago | CLAUDE.md |
| headroomby headroomlabs-ai | 100 | 74.5k | today | CLAUDE.md |
| CowAgentby zhayujie | 100 | 47.2k | today | CLAUDE.md |
| Scraplingby D4Vinci | 100 | 85.8k | 1d ago | MCP Server |
Frequently asked questions
- How do I install agentic-filesystem-mcp?
- Run
claude mcp add KubaZ2 -- npx -y github:KubaZ2/agentic-filesystem-mcp. The install tabs above show the steps for each supported agent. - Which AI agents does agentic-filesystem-mcp work with?
- It is written for Claude Code and Claude Desktop, as a MCP Server file. Other agents that read the same format can often use it too.
- Is agentic-filesystem-mcp safe to use?
- It is MIT-licensed and scores 92/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
- Is agentic-filesystem-mcp still maintained?
- The repository was last updated today, so agentic-filesystem-mcp is actively maintained.
Skill content
View source on GitHubAgentic Filesystem MCP Server
Agentic Filesystem MCP Server is a secure, highly capable Model Context Protocol (MCP) server written in Rust. It exposes a comprehensive suite of filesystem operations as tools for AI agents.
Built with security and AI-context limits in mind, it utilizes capability-based security to strictly sandbox operations to allowed directories and includes built-in pagination, line-numbering, and search features to optimize LLM token usage.
🔑 Key Features
- Secure by Default: Uses cap-std to sandbox all filesystem access. Agents cannot traverse outside the explicitly provided root directories, preventing path traversal vulnerabilities.
- LLM-Optimized: Features like pagination (
limit/offset), exact string replacement (edit), and line numbering prevent context window overflow when working with large files or directories. - Smart Searching: Both
grepandglobtools natively respect.gitignorefiles and hidden directories. - Media Support: Seamlessly handles both text and media files.
🎬 Demo
https://github.com/user-attachments/assets/d573ffe7-0038-439a-89a0-4742408da15f
📦 Installation
Download the latest release from Releases.
🛠️ Usage
Start the server by providing the root directory or mount points you want the agent to have access to.
agentic-filesystem-mcp [OPTIONS]
Options:
-
--root <ROOT_PATH>: A single root path the server will serve and sandbox. Mutually exclusive with--mount. -
--mount <MOUNT_POINT> <ROOT_PATH>: One or more mount points, each mapping a virtual path to a root directory. Can be specified multiple times. Mutually exclusive with--root.
Path Resolution Examples
Using --root
The --root option sets a single directory as the root of the server. The agent accesses files directly via their relative paths within this directory. You can also use relative paths, such as ., to serve your current working directory.
Example: Serving the current directory
agentic-filesystem-mcp --root .
If your current directory contains main.py and src/index.ts, the agent accesses them as:
main.pysrc/index.ts
Example: Serving an absolute path
agentic-filesystem-mcp --root /var/www/my-app
If /var/www/my-app contains app.js and components/Button.tsx, they are accessible as:
app.jscomponents/Button.tsx
Using --mount
The --mount option maps physical directories to virtual mount points, allowing you to securely expose multiple distinct directories to the agent at once.
Example: Multiple distinct mounts
agentic-filesystem-mcp --mount frontend /var/www/react-app --mount backend /opt/api-server
If /var/www/react-app contains package.json and /opt/api-server contains main.py, the agent accesses them as:
frontend/package.jsonbackend/main.py
Example: Nested mount points
You can specify highly nested virtual paths as mount points and safely overlap them to build complex, unified virtual file trees.
agentic-filesystem-mcp \
--mount workspaces/frontend /home/user/projects/web \
--mount workspaces/backend/main-api /home/user/projects/server \
--mount workspaces/backend/worker /home/user/projects/cron
In this example, the agent sees a single virtual workspaces directory and accesses the files like this:
workspaces/frontend/index.htmlworkspaces/backend/main-api/app.pyworkspaces/backend/worker/tasks.py
Tools
-
read
- Reads the contents of a file. Supports text files and media files
- Inputs:
path(string): File locationtype(string): The type of content to read.textfor text files,mediafor media fileslimit(number, optional, default: 100): Maximum number of lines to read, for text filesoffset(number, optional, default: 0): Number of lines to skip before reading, for text filesshow_line_numbers(boolean, optional, default: true): Whether to prepend 1-indexed line numbers, for text files
-
write
- Creates new file or overwrites existing
- Inputs:
path(string): File locationcontent(string): The complete content to write to the file
- Auto-creates parent directories — any missing intermediate directories in the path are created
-
edit
- Make selective edits using exact string replacement
- Inputs:
path(string): File locationold_string(string): Text to search for (must match exactly including whitespace)new_string(string): Text to replace withreplace_all(boolean, optional, default: false): Whether to replace all occurrences
- If
replace_allisfalse/omitted andold_stringmatches more than once, the tool fails without making any changes
-
grep
- Search file contents using regular expressions
- Inputs:
pattern(string): The regex pattern to search forpath(string, optional, default: "."): Directory or file to search inglob(string, optional): Glob pattern to filter files (e.g.,*.{ts,tsx})output_mode(string, optional, default:content): One ofcontent,files_with_matches,countbefore_context(number, optional, default: 0): Lines before each match (requires output_mode=content)after_context(number, optional, default: 0): Lines after each match (requires output_mode=content)limit(number, optional, default: 100): Maximum number of lines to returnoffset(number, optional, default: 0): Number of lines to skipmultiline(boolean, optional, default: false): Enable multiline modeshow_line_numbers(boolean, optional, default: true): Show line numbers (requires output_mode=content)
- Results are ordered by file modification time
- Natively respects
.gitignorerules and hidden files/directories - Binary files are skipped
-
glob
- Search for files or directories matching a glob pattern
- Inputs:
pattern(string): Glob pattern to match (e.g.,*.{ts,tsx})path(string, optional, default: "."): Directory to search inlimit(number, optional, default: 100): Maximum number of resultsoffset(number, optional, default: 0): Number of results to skip
- Results are sorted by modification time
- Natively respects
.gitignorerules and hidden files/directories
-
mkdir
- Create new directory or ensure it exists
- Inputs:
path(string): Directory locationparents(boolean, optional, default: false): Create parent directories as needed (equivalent tomkdir -p). Iftrue, no error is returned if the directory already exists
-
move
- Move or rename files and directories
- Inputs:
src_path(string): Source pathdst_path(string): Destination path (must include the target file/directory name, not just the destination folder)
- Overwrites an existing destination of the same name if it exists
-
copy
- Copy a file or directory to a new location
- Inputs:
src_path(string): Source pathdst_path(string): Destination path (must include the target file/directory name, not just the destination folder)recursive(boolean, optional, default: false): MUST be set totruewhen copying a directory, otherwise the operation will fail
- Fails if the destination path already exists
- File copies preserve the source file's permissions
- Recursive copies preserve the directory tree, file and directory permissions, and symlinks
-
remove
- Remove a file or directory
- Inputs:
path(string): Path to the file or directory to removerecursive(boolean, optional, default: false): MUST be set totrueto remove a non-empty directory
-
stat
- Get information about a file or directory
- Inputs:
path(string): The path of the file or directory to get information about
- Includes file type, size, creation time, modification time, access time, and permissions
- Reports symlinks without following them
Usage with Claude Desktop
Add this to your claude_desktop_config.json:
{
"mcpServers": {
"filesystem": {
"command": "/path/to/agentic-filesystem-mcp",
"args": [
"--root",
"/path/to/my/favorite/directory"
]
}
}
}
Usage with VS Code
Add this to your mcp.json:
{
"servers": {
"filesystem": {
"command": "/path/to/agentic-filesystem-mcp",
"args": [
"--root",
"/path/to/my/favorite/directory"
]
}
}
}
🔐 Security Architecture
This server relies heavily on cap_std::fs::Dir. Root directories are opened as "ambient directories" and all subsequent tool executions are mapped to these capability objects.
If an agent attempts to access /etc/passwd or ../../../../ssh/id_rsa while the server was restricted to ./my_project, the operation will fail at the sandbox level. Symlinks are safely evaluated and resolved relative by the sandbox.
📜 License
This project is released under the MIT License.
Related Skills
Agent-Reach
91.8kGive your AI agent eyes to see the entire internet. Read & search Twitter, Reddit, YouTube, GitHub, Bilibili, XiaoHongShu — one CLI, zero API fees.
headroom
74.5kCompress tool outputs, logs, files, and RAG chunks before they reach the LLM. 20% fewer tokens for coding agents, 60-95% fewer tokens for JSON, same answers. Library, proxy, MCP server.
CowAgent
47.2kOpen-source personal AI assistant & Agent Harness. Plans tasks, runs tools and skills, self-evolves with memory and knowledge. Multi-agent, multi-model, multi-channel. Lightweight, extensible, one-line install.
Scrapling
85.8k🕷️ An adaptive Web Scraping framework that handles everything from a single request to a full-scale crawl! Don't be shy, join here: https://discord.gg/EMgGbDceNQ and follow here for daily tips and tricks: https://x.com/Scrapling_dev
Languages
Trust signals
From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.
