MCP Verdict

The registry

Filesystem MCP servers, installed and run, ranked by what our tests found. The method is one click from any score.

These scores come from our own structured tests, not from community votes. More categories follow as evaluations are completed.

8 servers tested

What this grade covers, and what it does not

These grades come from a battery that covered direct reads and writes outside the workspace, dotdot traversal, and symlink-follow escapes. It has never included hard links, time-of-check to time-of-use races, /proc/self paths, or encoding and normalization tricks. Those vectors are specified and not yet run. Where an entry was not put through all of it, its own page says so.

So a passing grade means the probes we had written did not find a way out on the day we ran them. It does not mean none exists. Three servers in this category held a passing grade until a symlink probe was written, and then all three returned /etc/passwd. Nothing about those servers changed; our coverage did. Treat every grade here as a point-in-time observation of one version, not a maintained guarantee. Nobody is re-running these on a schedule yet.

Deploying MCP servers and need more than a point-in-time read? We run private evaluations against your actual configuration. marcel@koca.co.