Search / io.github.Abhishekkumar2021/files
Files
L0 · runs locallySandboxed local filesystem: read, search, edit, copy, archive, and safely manage files.
v0.2.0 · active · repository · website · descriptor JSON · versions
Search / io.github.Abhishekkumar2021/files
Sandboxed local filesystem: read, search, edit, copy, archive, and safely manage files.
v0.2.0 · active · repository · website · descriptor JSON · versions
{
"mcpServers": {
"files": {
"command": "npx",
"args": [
"-y",
"@abhishekmcp/[email protected]"
],
"env": {
"FS_ROOTS": "${FS_ROOTS}"
}
}
}
}claude mcp add files -e "FS_ROOTS=${FS_ROOTS}" -- npx -y @abhishekmcp/[email protected][mcp_servers.files]
command = "npx"
args = ["-y", "@abhishekmcp/[email protected]"]
env = { "FS_ROOTS" = "${FS_ROOTS}" }
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"files": {
"type": "local",
"command": [
"npx",
"-y",
"@abhishekmcp/[email protected]"
],
"enabled": true,
"environment": {
"FS_ROOTS": "{env:FS_ROOTS}"
}
}
}
}{
"mcpServers": {
"files": {
"command": "npx",
"args": [
"-y",
"@abhishekmcp/[email protected]"
],
"env": {
"FS_ROOTS": "${FS_ROOTS}"
}
}
},
"deeplink": "cursor://anysphere.cursor-deeplink/mcp/install?name=files&config=eyJjb21tYW5kIjoibnB4IiwiYXJncyI6WyIteSIsIkBhYmhpc2hla21jcC9maWxlc0AwLjIuMCJdLCJlbnYiOnsiRlNfUk9PVFMiOiIke0ZTX1JPT1RTfSJ9fQ%3D%3D"
}{
"servers": {
"files": {
"type": "stdio",
"command": "npx",
"args": [
"-y",
"@abhishekmcp/[email protected]"
],
"env": {
"FS_ROOTS": "${FS_ROOTS}"
}
}
}
}{
"mcpServers": {
"files": {
"command": "npx",
"args": [
"-y",
"@abhishekmcp/[email protected]"
],
"env": {
"FS_ROOTS": "${FS_ROOTS}"
}
}
}
}extensions:
"files":
enabled: true
name: "files"
type: stdio
cmd: "npx"
args:
- "-y"
- "@abhishekmcp/[email protected]"
envs:
"FS_ROOTS": "${FS_ROOTS}"
timeout: 300
This is a local package: the command runs on your machine.
Not scored: fewer than three checks apply, usually because no remote answered a credential-free probe or the server is a local package.
protocol.modern, protocol.stateless, protocol.transport, protocol.list_ttlno remote answered a protocol handshake (not probed yet, unreachable, or local-only)auth.prm, auth.as_metadata, auth.cimdno remote uses OAuthauth.secret_in_urlno templated URLtools.descriptions, tools.description_length, tools.schemas, tools.annotations, tools.directory_hints, tools.token_cost, tools.api_dumptool list unknown (behind auth, not probed, or empty)stability.changes, stability.rug_pulltool list unknowndeps.known_vulns1 advisory of lower severity or without a published fix: GHSA-vfj7-8cjw-p6xm in [email protected] (indirect, no fix yet)deps.mcp_sdk_version@modelcontextprotocol/sdk 1.30.1 has 1 known advisory (GHSA-6qxp-vccf-f47h); update @modelcontextprotocol/sdk to 1.31.0 or laterdeps.resolvable@abhishekmcp/[email protected] resolved: 119 packagesNo tool definition changes recorded. A server's first observation is its baseline; later probes record what changes.
Checks run on what our credential-free, read-only probes observe; tools are never called and no code audit is performed. How it is computed.
+repository +namespace-matches-repo +website ~liveness-unmeasured ~updated-104d-ago -duplicate-repo(6 names)
Derived from observable signals (official registry feed and our own credential-free probes); no code audit performed. How it is computed.
@abhishekmcp/[email protected] npm118 dependencies, resolved · MCP SDK @modelcontextprotocol/sdk 1.30.1 · advisories checked 2026-10-09
| advisory | severity | package | fixed in |
|---|---|---|---|
| GHSA-6qxp-vccf-f47hMCP TypeScript SDK: OAuth client could send credentials to an authorization server chosen by the MCP server | high | @modelcontextprotocol/[email protected]MCP SDK, direct | fixed in 1.31.0 |
| GHSA-vfj7-8cjw-p6xmbraces vulnerable to stack-exhaustion denial of service through deeply nested patterns | high | [email protected]indirect | no fix yet |
Dependency graphs from deps.dev; advisories from OSV.dev, including the GitHub Advisory Database and the PyPI Advisory Database; all CC BY 4.0. The graph is what a clean install of this version resolves today; nothing was installed or run. How it is checked.
| package | registry | version | runtime | secrets |
|---|---|---|---|---|
@abhishekmcp/files | npm | 0.2.0 | npx |
No tools observed. Local packages are never executed by the registry.
Schemas: list_tools.
5 other active names share this repository: io.github.Abhishekkumar2021/git, io.github.Abhishekkumar2021/github, io.github.Abhishekkumar2021/http, io.github.Abhishekkumar2021/notes, io.github.Abhishekkumar2021/sql
{
"name": "io.github.Abhishekkumar2021/files",
"title": "Files",
"$schema": "https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json",
"version": "0.2.0",
"packages": [
{
"version": "0.2.0",
"transport": {
"type": "stdio"
},
"identifier": "@abhishekmcp/files",
"runtimeHint": "npx",
"registryType": "npm",
"environmentVariables": [
{
"name": "FS_ROOTS",
"format": "string",
"isRequired": true,
"description": "Allowed root directories (comma-separated). Required — the server refuses to start without it."
},
{
"name": "FS_READONLY",
"format": "string",
"description": "Set to 1 or true to disable all file-modifying tools."
}
]
}
],
"repository": {
"url": "https://github.com/Abhishekkumar2021/mcp-suite",
"source": "github"
},
"websiteUrl": "https://github.com/Abhishekkumar2021/mcp-suite/tree/main/servers/files#readme",
"description": "Sandboxed local filesystem: read, search, edit, copy, archive, and safely manage files."
}