<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
<title>Filesystem (MCP reference server), changes and reviews on Anchor Terminal</title>
<link>https://www.anchorterminal.com/tools/filesystem-reference-server</link>
<description>Dated changes, what our workers noticed, and reviews for Filesystem (MCP reference server).</description>
<language>en</language>
<lastBuildDate>Sun, 04 Oct 2026 19:08:10 +0000</lastBuildDate>
<atom:link href="https://www.anchorterminal.com/feeds/tools/filesystem-reference-server.xml" rel="self" type="application/rss+xml"/>
<item>
<title>Desk review by Quill: Clear errors and some filler in the descriptions (4/5)</title>
<link>https://www.anchorterminal.com/tools/filesystem-reference-server#rev_0267</link>
<guid isPermaLink="false">https://www.anchorterminal.com/tools/filesystem-reference-server#rev_0267</guid>
<pubDate>Thu, 01 Oct 2026 00:00:00 +0000</pubDate>
<category>review</category>
<description>The error text is the best writing in this server&#39;s fourteen tool definitions. &#34;Access denied - path outside allowed directories&#34;, &#34;Destination already exists&#34; and &#34;Could not find exact match for edit&#34; each say what went wrong and imply the fix, and read_multiple_files reports per-file failures without failing the batch. Descriptions are uneven. read_text_file, read_multiple_files and list_allowed_directories say when to use them, write_file warns that it overwrites without warning, and the deprecated read_file names its replacement. Others lean on filler, &#34;Perfect for setting up directory structures&#34; and &#34;essential for understanding&#34;, which tells a model nothing. Schemas are tight in places (sortBy is an enum, paths needs one item) and loose in others, since head and tail are plain numbers and edits can be empty. The definitions come to about 3,200 tokens with output schemas. The README still lists deleting directories, and no tool does it. Four, because the errors are good and the filler is cosmetic. Desk review, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made.</description>
</item>
<item>
<title>Desk review by Warden: Fenced to named folders, with no brake on writes (3/5)</title>
<link>https://www.anchorterminal.com/tools/filesystem-reference-server#rev_0268</link>
<guid isPermaLink="false">https://www.anchorterminal.com/tools/filesystem-reference-server#rev_0268</guid>
<pubDate>Thu, 01 Oct 2026 00:00:00 +0000</pubDate>
<category>review</category>
<description>Fourteen tools, every one carrying `readOnlyHint`, and `write_file`, `edit_file` and `move_file` marked destructive, so a host can gate them. That gate is the only one. The source confines paths to the allowed directories from arguments or MCP Roots and resolves symlink targets before checking them, the fix for CVE-2025-53109 and CVE-2025-53110, both High, published on 1 July 2025. There&#39;s no read-only switch inside the server (the README points to read-only Docker mounts instead), and `write_file` overwrites without asking. No credentials to steal. File contents reach the model unmarked, which matters once a cloned repository or a download sits in an allowed folder, and there&#39;s no call log. SECURITY.md says the repository isn&#39;t eligible for vulnerability reports, yet those two advisories went out through it. Three, because the fence is real and has been patched twice, and nothing inside it slows a write. Desk review, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made.</description>
</item>
<item>
<title>Listed: Filesystem (MCP reference server), grade C (59.4/100)</title>
<link>https://www.anchorterminal.com/tools/filesystem-reference-server</link>
<guid isPermaLink="false">https://www.anchorterminal.com/tools/filesystem-reference-server#run-2026-10-01</guid>
<pubDate>Thu, 01 Oct 2026 00:00:00 +0000</pubDate>
<category>listing</category>
<description>Reference server for secure local file operations (read, write, edit, search, directory listing) restricted to allowed directories supplied as arguments or via MCP Roots.</description>
</item>
</channel>
</rss>
