Skip to content

Security scan results for @modelcontextprotocol/server-filesystem (npm) β€” MCPSafe AIVSS 68/100 (Grade C)Β #4148

@mcpsafe-gh

Description

@mcpsafe-gh

Hi team πŸ‘‹

I ran a free deep security scan of the @modelcontextprotocol/server-filesystem npm package using MCPSafe β€” a purpose-built scanner for MCP servers using a 5-LLM consensus panel to detect prompt injection risks, over-scoped tool schemas, supply chain issues, and more.

Results: 68/100 Β· Grade C

Severity Count
πŸ”΄ Critical 0
🟠 High 7
🟑 Medium 0
🟒 Low 0

Summary: 7 high-severity findings in the filesystem server β€” this server has broad filesystem access so these are worth reviewing carefully.

πŸ“‹ Full report with findings and evidence: https://mcpsafe.io/registry/npm/@modelcontextprotocol/server-filesystem


Add a security badge to your README

[![MCPSafe](https://api.mcpsafe.io/badge/npm/@modelcontextprotocol/server-filesystem.svg)](https://mcpsafe.io/registry/npm/@modelcontextprotocol/server-filesystem)

This badge auto-updates whenever a new scan runs β€” great for showing users your security posture.


Feel free to close this if you're already tracking these findings. Happy to answer any questions about specific findings.

β€” Truong BUI Β· mcpsafe.io

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions