The Filesystem server gives your AI agent tools to read, write and search files, but only inside the folders you list when it starts. It is one of the reference servers the MCP project maintains to show how the protocol works, which makes it a good first server: it runs on your machine, needs no account, and its folder limit is easy to see and test.
Prompts to try
- "List the allowed folders, then show me the tree of the first one."
- "Find every Markdown file under docs and give me a one-line summary of each."
- "Read package.json and list the scripts it defines, with what each one runs."
- "Rename draft.md to 2026-09-notes.md." (a write: your tool should ask first)
Gotchas
- The folder is the whole security model. Name the smallest folder that does
the job: a project folder, not your home folder, where your SSH keys and
.envfiles live. - Your tool can override the folder. If your AI tool sends MCP roots (its own list of workspace folders), those replace the ones in the config. Ask the agent to list its allowed folders to see what it really has.
- Writes overwrite without warning. The write tool replaces a file whole. Keep the folder under version control so a bad write is one undo away.
- It is a reference implementation. The MCP project says these servers are "educational examples" rather than production-ready. For a personal project folder that is fine; for anything shared, it is your threat model to check.
- On Windows, npx needs cmd /c. The README wraps the command as
cmd /c npx -y …in the config there.
When not to use it
If your AI tool already edits files in your project, as Claude Code, Cursor and Codex do, this adds a second way to do the same thing. Use it where there is no built-in file access, or to fence an agent into one folder.