MCP Security Kit

medium

MCP filesystem server that can write, edit and move files

The filesystem server can change every folder you pass it, not just read it.

Why it matters

If the agent reads a document or web page carrying injected instructions, it can be steered into overwriting files or planting new ones in those folders, with your permissions.

How to fix it

Pass only the project folder it needs, keep your client's approval prompt on for write tools, and prefer a read-only mount (for example a container with :ro) when the agent only needs to read.

Before

{
  "mcpServers": {
    "filesystem": {
      "command": "npx",
      "args": [
        "-y",
        "@modelcontextprotocol/[email protected]",
        "/Users/alex/Documents"
      ]
    }
  }
}

After

{
  "mcpServers": {
    "filesystem": {
      "command": "docker",
      "args": [
        "run",
        "-i",
        "--rm",
        "--mount",
        "type=bind,src=/Users/alex/projects/site,dst=/projects/site,ro",
        "mcp/filesystem@sha256:0123abcd",
        "/projects"
      ]
    }
  }
}

Illustrative configs. The checker flags the "before" version with this finding and not the "after" version.

Check your own config

Other checks

Sources