MCP Security Kit by Agent Trust Cloud

high

MCP filesystem server with access to a very broad path

A filesystem server is allowed to read and write /, a whole home folder, a drive root or a system folder.

Why it matters

The agent can read and write everything under that path, including SSH keys, cloud credentials and browser profiles. A prompt injection in any document it reads can ask for them.

How to fix it

Allow only the project folders the agent needs.

Before

{
  "mcpServers": {
    "filesystem": {
      "command": "npx",
      "args": [
        "@modelcontextprotocol/[email protected]",
        "/Users/alex"
      ]
    }
  }
}

After

{
  "mcpServers": {
    "filesystem": {
      "command": "npx",
      "args": [
        "@modelcontextprotocol/[email protected]",
        "/Users/alex/projects/site"
      ]
    }
  }
}

Illustrative configs. The checker flags the “before” version with this finding and not the “after” version.

Check your own config

Other checks