mark3labs/mcp-filesystem-server
MCP serverVerified · Rung 3A Go binary implementation of the MCP filesystem server by mark3labs. Exposes 14 tools matching the official TypeScript spec. Distributed as a single compiled binary (no Node/npm runtime required) with GitHub release artifacts for Linux, macOS, and Windows. Enforces a directory allowlist passed as positional CLI arguments.
Score breakdown
Based on 1 evaluation. Confidence rises as more independent tests agree.
The verdict
The Go alternative to the official Node.js implementation. All 14 tools verified in a sandbox. The directory allowlist is enforced on every read and write operation: path traversal and direct /etc/passwd access are blocked with 'Access denied' errors. No npm or Node.js runtime required: the single compiled binary starts and responds in under 2ms. Identified as 'secure-filesystem-server v0.11.1' at the MCP protocol level, which is the server's own chosen name and matches the mark3labs codebase. If your deployment cannot run Node.js, this is the drop-in replacement. No security concerns found.
What this grade covers, and what it does not
This server was tested on Jun 8, 2026, 2 months ago, against the version pinned on this page. The battery covered direct reads and writes outside the workspace, dotdot traversal, and symlink-follow escapes. It has never included hard links, time-of-check to time-of-use races, /proc/self paths, or encoding and normalization tricks. Those vectors are specified and not yet run.
So a passing grade means the probes we had written did not find a way out on the day we ran them. It does not mean none exists. Three servers in this category held a passing grade until a symlink probe was written, and then all three returned /etc/passwd. Nothing about those servers changed; our coverage did. Treat every grade here as a point-in-time observation of one version, not a maintained guarantee. Nobody is re-running these on a schedule yet.
Deploying MCP servers and need more than a point-in-time read? We run private evaluations against your actual configuration. marcel@koca.co.
Security findings
Flags from our evaluations, ordered by severity.
Test history
1 runEvery evaluation behind the score. This is the receipt.
- PassmanualReliability
97/100
Latency2 ms
SetupEasy
Flags0
All 14 tools verified via stdio NDJSON in a Linux arm64 sandbox (pre-compiled binary v0.11.1 from GitHub releases). Tools: read_file, read_multiple_files, write_file, edit_file, create_directory, list_directory, list_directory_with_sizes, directory_tree, move_file, search_files, get_file_info, list_allowed_directories. All return correct results. read_file reads allowed file. list_directory returns directory contents. search_files matches on filename patterns.