THRONE
See report Verify server

registry / record

@modelcontextprotocol/server-filesystem

npm / sealed 2026-06-14 / No. f67c8910

> throne registry @modelcontextprotocol/server-filesystem sealed
receiptsealed evidence
scan id
f67c89104e4141de9e8a241832687bfc
target
@modelcontextprotocol/server-filesystem
sealed at
2026-06-14 17:06:12Z
evidence hash
sha256:38c3aec25622d869a84b862dc08bc27d711fd866e0cfc1431e5d91fc0d39086e
01connectPASS1.0s

initialize ok: server secure-filesystem-server 0.2.0, negotiated protocolVersion 2025-11-25, capabilities ['tools']

02discoverPASS16ms

supported: tools/list (14 tools); method not found (tolerated): resources/list, prompts/list

03validate_schemasPASS5ms

all 14 tool inputSchemas are valid JSON Schema

04smoke_test_toolsPASS23ms

called 10 of 10 tools (cap 10): 1 ok, 9 returned tool-level errors (expected for synthesized args)

05error_handlingPASS4.1s

structured error responses, connection survived — wrong_type_args: accepted (returned result); unknown_method: error(-32601); invalid_id: no response (silent), connection alive

06streamingPASS0ms

no streaming-capable tool declared by this server; not applicable (pass-na)

07resource_lifecyclePASS1ms

resources capability not declared; not applicable (pass-na)

08concurrent_callsPASS15ms

ladder 1/2/4/8 overlapping list_allowed_directories calls: max_observed_stable_concurrency=8; all ids answered exactly once at every level

09reconnectPASS957ms

transport closed and relaunched; re-handshake ok (protocolVersion 2025-11-25, first session was 2025-11-25)

01connectPASS961ms

initialize ok: server secure-filesystem-server 0.2.0, negotiated protocolVersion 2025-11-25, capabilities ['tools']

02discoverPASS12ms

supported: tools/list (14 tools); method not found (tolerated): resources/list, prompts/list

03validate_schemasPASS5ms

all 14 tool inputSchemas are valid JSON Schema

04smoke_test_toolsPASS21ms

called 10 of 10 tools (cap 10): 1 ok, 9 returned tool-level errors (expected for synthesized args)

05error_handlingPASS4.0s

structured error responses, connection survived — wrong_type_args: accepted (returned result); unknown_method: error(-32601); invalid_id: no response (silent), connection alive

06streamingPASS0ms

no streaming-capable tool declared by this server; not applicable (pass-na)

07resource_lifecyclePASS2ms

resources capability not declared; not applicable (pass-na)

08concurrent_callsPASS15ms

ladder 1/2/4/8 overlapping list_allowed_directories calls: max_observed_stable_concurrency=8; all ids answered exactly once at every level

09reconnectPASS1.0s

transport closed and relaunched; re-handshake ok (protocolVersion 2025-11-25, first session was 2025-11-25)

chatgpt desktopemulation profile pending real-traffic captureCOMING SOON
SECURITY: REVIEW / 1 finding(s) / review material, not a verdict
LOWTHR-INSTALL-03 / Install-time script execution (npm lifecycle)

"prepare" runs on git-dependency installs and local dev (not registry installs): 'npm run build'

package/package.json
VERDICT: FIT TO SHIPSANDBOXED RUN — submitted server executed in a disposable microVM — compatibility: 0 fail / 0 warn across 2 clients / security: review — 1 finding(s), 0 highsealed by THRONE / No. f67c8910 / 2026-06-14
THRONE: FIT TO SHIPwear the crown

paste this in your README. it renders the live verdict and links back to this record. if a release ever breaks the verdict, the badge says so on its own.

[![THRONE: FIT TO SHIP](https://api.usethrone.dev/api/badge/%40modelcontextprotocol%2Fserver-filesystem)](https://usethrone.dev/server/modelcontextprotocol-server-filesystem)
executed in a disposable microVM, created for this scan and destroyed after it. nothing outlives a run.

maintainer of this server? challenge this record: hello@usethrone.dev. tell us what we got wrong and we re-run it in the open.

this page renders the stored record of a real run. nothing on it is asserted without the execution that proved it.