Official BridgeMCP reference server — safe filesystem access
Project description
bridgemcp-server-filesystem
Official BridgeMCP reference server — safe filesystem access for AI clients.
Overview
bridgemcp-server-filesystem exposes ten filesystem tools to any MCP-compatible AI client (Claude Desktop, Cursor, etc.). It is the second official server in the BridgeMCP ecosystem and serves as the canonical reference implementation for filesystem access.
Key safety features:
- Root confinement — set
--root /workspaceto restrict all operations to that directory. Path traversal attacks (../../etc/passwd) and symlink escapes are blocked at thePath.resolve()level before any filesystem operation occurs. - Read-only mode — set
--read-onlyto expose a directory for inspection without permitting any writes. - File size limit — set
--max-file-size-mb 10to prevent accidentally reading large files. - Binary detection —
read_filedetects binary files before decoding and returns a structuredis_binary=Trueresponse instead of aUnicodeDecodeError. - Explicit delete confirmation —
delete_pathrequiresconfirm=Truein every call. The configured root can never be deleted.
Installation
pip install bridgemcp-server-filesystem
pip install 'bridgemcp-server-filesystem[mcp]' # for running as an MCP server
Quick start
Programmatic use:
from bridgemcp_filesystem import create_app
app = create_app(root="/workspace", read_only=False, max_file_size_mb=10.0)
app.run()
CLI use:
# Stdio transport (default) — for Claude Desktop / Cursor
bridgemcp-filesystem --root /workspace
# Read-only with a size limit
bridgemcp-filesystem --root /data --read-only --max-file-size-mb 5
# HTTP/SSE transport
bridgemcp-filesystem --root /app --http --port 8080
Claude Desktop config (claude_desktop_config.json):
{
"mcpServers": {
"filesystem": {
"command": "bridgemcp-filesystem",
"args": ["--root", "/workspace"]
}
}
}
Tools
| Tool | Description |
|---|---|
read_file |
Read file content. Returns is_binary=true, content=null for binary files. |
write_file |
Write text to a file. Optionally creates missing parent directories. |
list_directory |
List directory contents with type, size, and timestamps. |
search_files |
Glob search within a directory, optionally recursive. |
get_info |
Metadata for a file or directory: type, size, timestamps, permissions. |
create_directory |
Create a directory, optionally including parents. |
copy_path |
Copy a file or directory tree. |
move_path |
Move a file or directory. Supports cross-filesystem moves. |
rename_path |
Atomic rename within the same filesystem. |
delete_path |
Delete a file or directory. Requires confirm=True. |
Safety model
Root confinement
Set root to restrict all operations to a single directory tree:
app = create_app(root="/workspace")
Any path that resolves outside /workspace — including ../../etc/passwd and symlinks pointing out — raises an error before any IO occurs. The check uses Path.resolve() which follows all symlinks, so there is no way to escape the root through link indirection.
When root is not set, the server operates in unrestricted mode: any path on the filesystem is accessible. This is appropriate for trusted local tools but should not be used in multi-user or production environments.
Read-only mode
app = create_app(root="/data", read_only=True)
All mutating tools (write_file, create_directory, copy_path, move_path, rename_path, delete_path) raise an error immediately without touching the filesystem.
Delete safeguard
delete_path always requires confirm=True:
# This always raises an error:
app.call("delete_path", path="/workspace/file.txt")
# This proceeds with deletion:
app.call("delete_path", path="/workspace/file.txt", confirm=True)
The configured root directory can never be deleted, even with confirm=True.
Development
git clone https://github.com/Arsie-codes/bridgemcp-server-filesystem
cd bridgemcp-server-filesystem
pip install -e '.[dev]'
ruff check bridgemcp_filesystem tests
black --check bridgemcp_filesystem tests
pyright bridgemcp_filesystem
pytest tests/ -v
License
MIT — see LICENSE.
Links
Project details
Release history Release notifications | RSS feed
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file bridgemcp_server_filesystem-0.1.1.tar.gz.
File metadata
- Download URL: bridgemcp_server_filesystem-0.1.1.tar.gz
- Upload date:
- Size: 26.6 kB
- Tags: Source
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/6.2.0 CPython/3.14.6
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
c947263332dba526e7f27c1335c27007b360cb4d7fb33999eeddbd53a9caf5d7
|
|
| MD5 |
de2102b1d890c9c87c79b860aff61167
|
|
| BLAKE2b-256 |
03c74330f14d2046899ecc723226dc863d3caa06051eaaf3f360f6196b09fd6d
|
File details
Details for the file bridgemcp_server_filesystem-0.1.1-py3-none-any.whl.
File metadata
- Download URL: bridgemcp_server_filesystem-0.1.1-py3-none-any.whl
- Upload date:
- Size: 17.6 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/6.2.0 CPython/3.14.6
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
3ac6ebcaac3b3cbc9279aec10490f0f2bdbb73ee1f3090ddf467215554a5f116
|
|
| MD5 |
32185fc6912c95293a3fc84f45f589d8
|
|
| BLAKE2b-256 |
a3acdba371f6bd3263d1626755ec329e43f4da90ac25b9327d44ab28639f9f31
|