filesystem_sandbox
README.md
# MCP Filesystem Sandbox
A simple, safe, Python MCP server that exposes filesystem operations
(list files, move files, create directories, delete files)
inside a single sandboxed directory.
The server is designed for learning and personal use with
Claude Desktop via the Model Context Protocol (MCP).
---
## Features
- Relative-path sandboxing (no access outside the allowed directory)
- No shell execution (pure Python filesystem APIs)
- Safe file-only deletion (directories cannot be deleted)
- Minimal, explicit tool surface
- Designed for use with Claude Desktop via MCP
---
## Sandbox directory
This server operates inside **one sandbox directory**.
You must provide the sandbox path as the first argument when
starting the server:
```bash
uv run server.py /absolute/path/to/sandbox
````
All filesystem operations are restricted to this directory.
Paths passed to tools are always **relative to the sandbox root**.
Use `"."` to refer to the sandbox root itself.
---
## Running the server
From the project directory:
```bash
uv run server.py /absolute/path/to/sandbox
```
The server will start and wait for MCP tool calls over stdio.
No output is expected while it is running.
---
## Using with Claude Desktop (MCP)
Example MCP configuration:
```json
{
"mcpServers": {
"filesystem_sandbox": {
"command": "uv",
"args": [
"--directory",
"/path/to/project",
"run",
"server.py",
"/absolute/path/to/sandbox"
]
}
}
}
```
After updating the configuration, restart Claude Desktop.
Note: Depending on your system, you may need to use the full
path to the `uv` executable (for example `/Users/you/.local/bin/uv`)
instead of `uv` in the MCP configuration.
---
## Safety notes
* All paths are resolved relative to the sandbox directory
* Absolute paths and directory traversal (`..`) are blocked
* Directories cannot be deleted
* No shell commands are executed
This server is intended for safe experimentation and learning.
TDQS
A3.9/5.0
Scored across 5 tools
Disambiguation3/5
list_files and list_root overlap significantly—both list contents of the sandbox, with list_files able to list the root via '.', making list_root redundant. Other tools are distinct, but the boundary between the two listing tools is unclear.
Naming Consistency5/5
All tools follow a consistent verb_noun snake_case pattern (list_files, list_root, move_file, make_directory, delete_file), making the set predictable.
Tool Count5/5
Five tools is well-scoped for a sandboxed filesystem utility, covering essential operations without bloat.
Completeness3/5
The set covers listing, moving, creating directories, and deleting files, but lacks common file operations like reading/writing file contents or deleting directories, leaving notable gaps for a filesystem tool.
Maintenance
ActivityInactive
ResponsivenessNo issues