# io.github.infoinlet-marketplace/mcp-filesystem

> Hardened filesystem for AI agents — jailed root, read-only default, traversal/symlink-safe.

- name: io.github.infoinlet-marketplace/mcp-filesystem
- version: 0.1.1
- connection class: L0 (run_local_package)
- trust: 70/100 flags: duplicate-repo
- quality: –/100 (not scored)
- owner: not claimed
- descriptor: https://api.protogrid.dev/v1/servers/io.github.infoinlet-marketplace%2Fmcp-filesystem
- tools: https://api.protogrid.dev/v1/servers/io.github.infoinlet-marketplace%2Fmcp-filesystem/tools

**Runs on your machine: something must execute the package.** Only local packages are published (npm, PyPI, OCI, …). The registry never executes them, so tools are unknown until you run it.

## Connection (mcpServers)

```json
{
  "mcpServers": {
    "mcp-filesystem": {
      "command": "npx",
      "args": [
        "-y",
        "@infoinlet/mcp-filesystem@0.1.1"
      ]
    }
  }
}
```


## Trust

- hygiene: 60
- liveness: n/a
- freshness: 65
- provenance: 80
- drivers: +repository +namespace-matches-repo ~liveness-unmeasured ~updated-134d-ago -duplicate-repo(30 names)
- Derived from observable signals (official registry feed and our own credential-free probes); no code audit performed.

## Quality –/100 (not scored)

Not scored: fewer than three checks apply, usually because no remote answered a credential-free probe or the server is a local package.

### protocol: n/a (weight 25)

- n/a `protocol.modern`, `protocol.stateless`, `protocol.transport`, `protocol.list_ttl`: no remote answered a protocol handshake (not probed yet, unreachable, or local-only)

### authorization: n/a (weight 15)

- n/a `auth.prm`, `auth.as_metadata`, `auth.cimd`: no remote uses OAuth
- n/a `auth.secret_in_url`: no templated URL

### tool hygiene: n/a (weight 30)

- n/a `tools.descriptions`, `tools.description_length`, `tools.schemas`, `tools.annotations`, `tools.directory_hints`, `tools.token_cost`, `tools.api_dump`: tool list unknown (behind auth, not probed, or empty)

### stability: n/a (weight 15)

- n/a `stability.changes`, `stability.rug_pull`: tool list unknown

### dependencies: 67 (weight 15)

- pass `deps.known_vulns`: no known advisory in 99 resolved packages
- fail `deps.mcp_sdk_version`: @modelcontextprotocol/sdk 1.30.1 has 1 known advisory (GHSA-6qxp-vccf-f47h); update @modelcontextprotocol/sdk to 1.31.0 or later
- pass `deps.resolvable`: @infoinlet/mcp-filesystem@0.1.1 resolved: 99 packages

- tools: unknown
- badge: [![protogrid quality](https://protogrid.dev/badge/io.github.infoinlet-marketplace/mcp-filesystem.svg)](https://protogrid.dev/servers/io.github.infoinlet-marketplace/mcp-filesystem)
- Checks run on what our credential-free, read-only probes observe; tools are never called and no code audit is performed.

### Tool changes

_No tool definition changes recorded._

## Dependencies

- npm @infoinlet/mcp-filesystem@0.1.1: resolved, 98 dependencies, MCP SDK @modelcontextprotocol/sdk 1.30.1
  - GHSA-6qxp-vccf-f47h (high) in `` @modelcontextprotocol/sdk@1.30.1 ``, direct, fixed in `` 1.31.0 ``, advisory summary: "MCP TypeScript SDK: OAuth client could send credentials to an authorization server chosen by the MCP server" https://osv.dev/vulnerability/GHSA-6qxp-vccf-f47h

Dependency graphs from deps.dev; advisories from OSV.dev, including the GitHub Advisory Database and the PyPI Advisory Database; all CC BY 4.0.

## Remotes

_none_

## Packages

- npm @infoinlet/mcp-filesystem@0.1.1

## Tools (0)

_none observed_
