write_file
on npm:@modelcontextprotocol/server-filesystem@2026.1.14
Severity
3 findings on this tool
- highexcessive agencyf-r3-write_file
Tool `write_file` name implies a side effect that is not declared
`write_file` looks like a side-effecting tool (its name contains a mutation verb), but its `side_effects` declaration is []. A policy synthesizer cannot produce safe rules for this tool because it cannot tell what it actually does.
fix: Declare the tool's true side effects explicitly. If the tool is genuinely read-only, rename it to match (e.g. `email.preview` rather than `email.send`).
OWASP LLM08NIST MEASURE-2.6ATLAS T0051CAST-01 - highfilesystem egressf-r9-write_file
Tool `write_file` writes to or deletes from the host filesystem
`write_file` appears to write, create, move, or delete files on the host filesystem (Create a new file or completely overwrite an existing file with new content. Use with caution as it will overwrite existing files without warning. Handles text content with proper encoding. Only works within allowed directories.). An agent manipulated by an indirect-injection payload can target sensitive paths (SSH keys, shell configs, application secrets) or establish persistence via cron / systemd.
fix: Restrict the tool to an explicit allow-list of safe directories. Validate all path parameters server-side, reject traversal sequences (`../`), and gate write / delete operations behind a capframe-bind `path starts_with /safe/dir` caveat.
OWASP LLM08NIST MANAGE-2.2ATLAS T0051CAST-01 - mediumunconstrained inputf-r1-write_file
Tool `write_file` accepts unconstrained string input
The following string parameter(s) have no `maxLength` constraint: `content`, `path`. Unbounded strings let an attacker stuff arbitrary payloads through the tool, including indirect-injection content.
fix: Add a `maxLength` to each string property, or constrain with an `enum` or `pattern`. Most legitimate tool inputs fit under a few hundred bytes.
OWASP LLM01NIST MEASURE-2.3ATLAS T0051CAST-03
About this tool
write_file is one of 14 tools exposed by server-filesystem. The server scored 52/100 overall against the capframe rule engine (source: sandbox). Last scanned 2026-07-20.
The findings above are emitted by the public capframe.findings.v1 schema. Disagree with one? Open an issue.