medium
MCP filesystem server that can write, edit and move files
The filesystem server can change every folder you pass it, not just read it.
Why it matters
If the agent reads a document or web page carrying injected instructions, it can be steered into overwriting files or planting new ones in those folders, with your permissions.
How to fix it
Pass only the project folder it needs, keep your client's approval prompt on for write tools, and prefer a read-only mount (for example a container with :ro) when the agent only needs to read.
Before
{
"mcpServers": {
"filesystem": {
"command": "npx",
"args": [
"-y",
"@modelcontextprotocol/[email protected]",
"/Users/alex/Documents"
]
}
}
}After
{
"mcpServers": {
"filesystem": {
"command": "docker",
"args": [
"run",
"-i",
"--rm",
"--mount",
"type=bind,src=/Users/alex/projects/site,dst=/projects/site,ro",
"mcp/filesystem@sha256:0123abcd",
"/projects"
]
}
}
}Illustrative configs. The checker flags the "before" version with this finding and not the "after" version.
Other checks
- MCP tools auto-approved or always allowed
- MCP server installs without asking (npx -y)
- MCP filesystem server with access to a very broad path
- Broad host folder or Docker socket mounted into an MCP container
- MCP server container shares the host network
- Remote MCP server over unencrypted http
- MCP server container runs --privileged
- Remote MCP server with no credentials configured
- Secret passed as a command-line argument
- Secret written into an MCP config
- Secret inside an MCP server URL
- MCP server launched through a shell
- MCP server that can run shell commands
- Unpinned MCP server package or image
- Hidden instructions in an MCP config description
Sources
- Model Context Protocol: Security best practices
- Checked 28 September 2026.