Many MCP servers work with files: reading project code, searching documents, writing output. The protocol and good practice help keep this access bounded.
Roots
Clients can tell servers which roots — typically directories — are relevant to the current session, such as the project the user has open. Servers should confine their work to these locations.
Roots are a coordination mechanism, not an enforcement mechanism: a local server with file system access could still read elsewhere. Enforcement comes from sandboxing and operating-system permissions.
Safe File Access
- Resolve paths and reject ones outside allowed directories, including via
..segments and symbolic links. - Separate read and write tools; make write tools clearly labelled.
- Avoid exposing sensitive locations: home directory secrets, SSH keys, credential files.
- Limit file sizes returned.
For Users
Grant file servers access only to the directories they need, and run untrusted servers in isolated environments.
Remote Servers
Remote servers don't see local files at all unless the host sends content; they work on their own storage with user-specific permissions.