Enrich contact and company data via B4 integration
Official MCP reference server for filesystem operations - read, write, edit, and search files within an allowlist.
Maintainer of this project? Claim this page to edit the listing.
1.0.0Add to Favorites
Why it matters
Automatically enhance lead and customer records by pulling enriched contact and company information from B4's data platform to improve targeting, personalization, and sales intelligence.
Outcomes
What it gets done
Query B4 API to retrieve enriched contact profiles with verified email and phone data
Fetch detailed company information including firmographics and technographics
Sync enriched data back to CRM or data warehouse systems
Validate and update existing records with fresh B4 intelligence
Install
Add it to your toolbox
Run in your project directory:
curl -fsSL https://spark.entire.vc/get/mcp-server-filesystem | bash Overview
Filesystem MCP Server
The official MCP reference server for filesystem operations, exposing 13 tools to read, write, edit, search, and manage files and directories. Access is scoped to an explicit directory allowlist, configurable via command-line arguments or the dynamic MCP Roots protocol. Use when an AI agent needs real, scoped filesystem access - reading, editing, or reorganizing files - restricted to specific directories you control.
What it does
This is the official Model Context Protocol reference server for filesystem operations - a Node.js server (published on npm as @modelcontextprotocol/server-filesystem) that gives Claude and other MCP clients the ability to read, write, edit, search, and manage files and directories, all scoped to an explicit allowlist of directories.
When to use - and when NOT to
Use it when an AI agent needs real filesystem access - reading or editing project files, listing and searching directories, moving files, or inspecting file metadata - restricted to specific directories you control. Directory access is set either via command-line arguments at startup, or dynamically via the MCP Roots protocol (recommended): a Roots-supporting client sends its roots on connect and can update them at runtime via notifications/roots/list_changed, and each update completely replaces the server's allowed-directory list rather than adding to it. If the server starts with no command-line directories AND the connecting client doesn't support Roots (or sends an empty roots list), the server throws an error during initialization - it always requires at least one allowed directory to operate, and every operation outside the allowlist is rejected.
Capabilities
Thirteen tools, split by MCP tool-annotation hints (readOnlyHint/idempotentHint/destructiveHint; every tool also sets openWorldHint: false since it never reaches outside the local filesystem). Nine are pure reads: read_text_file (UTF-8 text, with optional head/tail line limits, not both at once), read_media_file (base64-encoded content with MIME type - images and audio as media content, everything else as an embedded resource), read_multiple_files (failed reads don't abort the batch), list_directory and list_directory_with_sizes (the latter sortable by name or size, with summary stats), directory_tree (a recursive JSON tree with glob-pattern exclusions), search_files (glob-style recursive search), get_file_info (size, creation/modified/access time, type, permissions), and list_allowed_directories. Four are write-capable: create_directory (idempotent, non-destructive - a no-op if it already exists), write_file (idempotent but destructive - overwrites existing files), edit_file (non-idempotent, destructive - pattern-based multi-edit with indentation preservation, git-style diff output, and a dryRun mode that should always be used first to preview changes), and move_file (non-idempotent, destructive - fails if the destination already exists, deletes the source).
How to install
Via NPX in claude_desktop_config.json, passing the allowed directories as trailing args:
{
"mcpServers": {
"filesystem": {
"command": "npx",
"args": [
"-y",
"@modelcontextprotocol/server-filesystem",
"/Users/username/Desktop",
"/path/to/other/allowed/dir"
]
}
}
}
On Windows, wrap the command in cmd /c. Alternatively, run it via Docker, mounting each allowed directory to /projects (add the ro flag to mount a directory read-only). VS Code supports the same NPX or Docker configurations through one-click install buttons, the Command Palette's "MCP: Open User Configuration," or a shared .vscode/mcp.json workspace file, typically pointing at ${workspaceFolder} instead of a hardcoded path. To build the Docker image from source: docker build -t mcp/filesystem -f src/filesystem/Dockerfile .. The server is MIT-licensed.
Who it's for
Developers who want an AI agent to work directly with real files and directories - reading, writing, editing, searching, or reorganizing a codebase or document set - under an explicit, revocable directory allowlist rather than unrestricted filesystem access.
Source README
Filesystem MCP Server
Node.js server implementing Model Context Protocol (MCP) for filesystem operations.
Published on npm as @modelcontextprotocol/server-filesystem.
Features
- Read/write files
- Create/list/delete directories
- Move files/directories
- Search files
- Get file metadata
- Dynamic directory access control via Roots
Directory Access Control
The server uses a flexible directory access control system. Directories can be specified via command-line arguments or dynamically via Roots.
Method 1: Command-line Arguments
Specify Allowed directories when starting the server:
mcp-server-filesystem /path/to/dir1 /path/to/dir2
Method 2: MCP Roots (Recommended)
MCP clients that support Roots can dynamically update the Allowed directories.
Roots notified by Client to Server, completely replace any server-side Allowed directories when provided.
Important: If server starts without command-line arguments AND client doesn't support roots protocol (or provides empty roots), the server will throw an error during initialization.
This is the recommended method, as this enables runtime directory updates via roots/list_changed notifications without server restart, providing a more flexible and modern integration experience.
How It Works
The server's directory access control follows this flow:
Server Startup
- Server starts with directories from command-line arguments (if provided)
- If no arguments provided, server starts with empty allowed directories
Client Connection & Initialization
- Client connects and sends
initializerequest with capabilities - Server checks if client supports roots protocol (
capabilities.roots)
- Client connects and sends
Roots Protocol Handling (if client supports roots)
- On initialization: Server requests roots from client via
roots/list - Client responds with its configured roots
- Server replaces ALL allowed directories with client's roots
- On runtime updates: Client can send
notifications/roots/list_changed - Server requests updated roots and replaces allowed directories again
- On initialization: Server requests roots from client via
Fallback Behavior (if client doesn't support roots)
- Server continues using command-line directories only
- No dynamic updates possible
Access Control
- All filesystem operations are restricted to allowed directories
- Use
list_allowed_directoriestool to see current directories - Server requires at least ONE allowed directory to operate
Note: The server will only allow operations within directories specified either via args or via Roots.
API
Tools
read_text_file
- Read complete contents of a file as text
- Inputs:
path(string)head(number, optional): First N linestail(number, optional): Last N lines
- Always treats the file as UTF-8 text regardless of extension
- Cannot specify both
headandtailsimultaneously
read_media_file
- Read a file and return it as a base64-encoded content block with its MIME type
- Inputs:
path(string)
- Streams the file and returns base64 data with the corresponding MIME type. Image and
audio files are returned asimage/audiocontent; any other file type is returned as
an embeddedresource(a valid MCP content block for arbitrary binary data)
read_multiple_files
- Read multiple files simultaneously
- Input:
paths(string[]) - Failed reads won't stop the entire operation
write_file
- Create new file or overwrite existing (exercise caution with this)
- Inputs:
path(string): File locationcontent(string): File content
edit_file
- Make selective edits using advanced pattern matching and formatting
- Features:
- Line-based and multi-line content matching
- Whitespace normalization with indentation preservation
- Multiple simultaneous edits with correct positioning
- Indentation style detection and preservation
- Git-style diff output with context
- Preview changes with dry run mode
- Inputs:
path(string): File to editedits(array): List of edit operationsoldText(string): Text to search for (can be substring)newText(string): Text to replace with
dryRun(boolean): Preview changes without applying (default: false)
- Returns detailed diff and match information for dry runs, otherwise applies changes
- Best Practice: Always use dryRun first to preview changes before applying them
create_directory
- Create new directory or ensure it exists
- Input:
path(string) - Creates parent directories if needed
- Succeeds silently if directory exists
list_directory
- List directory contents with [FILE] or [DIR] prefixes
- Input:
path(string)
list_directory_with_sizes
- List directory contents with [FILE] or [DIR] prefixes, including file sizes
- Inputs:
path(string): Directory path to listsortBy(string, optional): Sort entries by "name" or "size" (default: "name")
- Returns detailed listing with file sizes and summary statistics
- Shows total files, directories, and combined size
move_file
- Move or rename files and directories
- Inputs:
source(string)destination(string)
- Fails if destination exists
search_files
- Recursively search for files/directories that match or do not match patterns
- Inputs:
path(string): Starting directorypattern(string): Search patternexcludePatterns(string[]): Exclude any patterns.
- Glob-style pattern matching
- Returns full paths to matches
directory_tree
- Get recursive JSON tree structure of directory contents
- Inputs:
path(string): Starting directoryexcludePatterns(string[]): Exclude any patterns. Glob formats are supported.
- Returns:
- JSON array where each entry contains:
name(string): File/directory nametype('file'|'directory'): Entry typechildren(array): Present only for directories- Empty array for empty directories
- Omitted for files
- JSON array where each entry contains:
- Output is formatted with 2-space indentation for readability
get_file_info
- Get detailed file/directory metadata
- Input:
path(string) - Returns:
- Size
- Creation time
- Modified time
- Access time
- Type (file/directory)
- Permissions
list_allowed_directories
- List all directories the server is allowed to access
- No input required
- Returns:
- Directories that this server can read/write from
Tool annotations (MCP hints)
This server sets MCP ToolAnnotations
on each tool so clients can:
- Distinguish read‑only tools from write‑capable tools.
- Understand which write operations are idempotent (safe to retry with the same arguments).
- Highlight operations that may be destructive (overwriting or heavily mutating data).
- Signal that a tool does not reach an open or external world (every filesystem tool sets
openWorldHint: false).
The mapping for filesystem tools is:
| Tool | readOnlyHint | idempotentHint | destructiveHint | Notes |
|---|---|---|---|---|
read_text_file |
true |
- | - | Pure read |
read_media_file |
true |
- | - | Pure read |
read_multiple_files |
true |
- | - | Pure read |
list_directory |
true |
- | - | Pure read |
list_directory_with_sizes |
true |
- | - | Pure read |
directory_tree |
true |
- | - | Pure read |
search_files |
true |
- | - | Pure read |
get_file_info |
true |
- | - | Pure read |
list_allowed_directories |
true |
- | - | Pure read |
create_directory |
false |
true |
false |
Re‑creating the same dir is a no‑op |
write_file |
false |
true |
true |
Overwrites existing files |
edit_file |
false |
false |
true |
Re‑applying edits can fail or double‑apply |
move_file |
false |
false |
true |
Deletes source file |
Note:
idempotentHintanddestructiveHintare meaningful only whenreadOnlyHintisfalse, as defined by the MCP spec. Every tool also setsopenWorldHint: false- this server only accesses the local filesystem within its allowed directories, never an open or external world.
Usage with Claude Desktop
Add this to your claude_desktop_config.json:
Note: you can provide sandboxed directories to the server by mounting them to /projects. Adding the ro flag will make the directory readonly by the server.
Docker
Note: all directories must be mounted to /projects by default.
{
"mcpServers": {
"filesystem": {
"command": "docker",
"args": [
"run",
"-i",
"--rm",
"--mount", "type=bind,src=/Users/username/Desktop,dst=/projects/Desktop",
"--mount", "type=bind,src=/path/to/other/allowed/dir,dst=/projects/other/allowed/dir,ro",
"--mount", "type=bind,src=/path/to/file.txt,dst=/projects/path/to/file.txt",
"mcp/filesystem",
"/projects"
]
}
}
}
NPX
{
"mcpServers": {
"filesystem": {
"command": "npx",
"args": [
"-y",
"@modelcontextprotocol/server-filesystem",
"/Users/username/Desktop",
"/path/to/other/allowed/dir"
]
}
}
}
On Windows, use cmd /c to launch npx:
{
"mcpServers": {
"filesystem": {
"command": "cmd",
"args": [
"/c",
"npx",
"-y",
"@modelcontextprotocol/server-filesystem",
"/Users/username/Desktop",
"/path/to/other/allowed/dir"
]
}
}
}
Usage with VS Code
For quick installation, click the installation buttons below...
For manual installation, you can configure the MCP server using one of these methods:
Method 1: User Configuration (Recommended)
Add the configuration to your user-level MCP configuration file. Open the Command Palette (Ctrl + Shift + P) and run MCP: Open User Configuration. This will open your user mcp.json file where you can add the server configuration.
Method 2: Workspace Configuration
Alternatively, you can add the configuration to a file called .vscode/mcp.json in your workspace. This will allow you to share the configuration with others.
For more details about MCP configuration in VS Code, see the official VS Code MCP documentation.
You can provide sandboxed directories to the server by mounting them to /projects. Adding the ro flag will make the directory readonly by the server.
Docker
Note: all directories must be mounted to /projects by default.
{
"servers": {
"filesystem": {
"command": "docker",
"args": [
"run",
"-i",
"--rm",
"--mount", "type=bind,src=${workspaceFolder},dst=/projects/workspace",
"mcp/filesystem",
"/projects"
]
}
}
}
NPX
{
"servers": {
"filesystem": {
"command": "npx",
"args": [
"-y",
"@modelcontextprotocol/server-filesystem",
"${workspaceFolder}"
]
}
}
}
On Windows, use:
{
"servers": {
"filesystem": {
"command": "cmd",
"args": [
"/c",
"npx",
"-y",
"@modelcontextprotocol/server-filesystem",
"${workspaceFolder}"
]
}
}
}
Build
Docker build:
docker build -t mcp/filesystem -f src/filesystem/Dockerfile .
FAQ
Common questions
Discussion
Questions & comments · 0
Sign In Sign in to leave a comment.