IH-MCP-003mediumMCP config

MCP server given a broad filesystem root

A filesystem MCP server pointed at /, a drive root, or a home directory can read far more than the project. A subdirectory such as ./notes or /home/alex/projects/notes is not a broad root.

What does IH-MCP-003 flag?

Flags a filesystem MCP server that is pointed at a filesystem root, a drive root, or a whole home directory.

  • A server argument that is /, a drive root, ~, or a home directory such as the home folder of one user.
  • Not reported: a project folder or any subdirectory such as ./notes or a path under your projects folder.

Why it matters

A file server given the whole disk or your whole home folder can read SSH keys, browser stores and every project, not just the folder the task needs.

Examples

Illustrative shapes with placeholders in angle brackets. They show what the rule looks at; they are not runnable and not taken from real malware.

Home directory as root
Flagged
args: ["~"]
Filesystem root
Flagged
args: ["/"]
Project folder
Not flagged
args: ["./notes"]

Can IH-MCP-003 fire on a safe skill?

  • A machine that only holds throwaway data, where a broad root is a deliberate choice.

How do I fix an IH-MCP-003 finding?

  • Pass the project directory the task needs, not a home directory or a filesystem root.

CLI guidance: Pass a project directory, not a home directory or a filesystem root.

How do I tune or allow IH-MCP-003?

If a broad root is intentional, record that with a config suppression and a reason, or lower the severity with ruleOverrides. Keep the exception in the project's own config.

{
  "ruleOverrides": {
    "IH-MCP-003": {
      "severity": "low"
    }
  }
}

Every key is described in Configuration. To print this rule from the CLI, run ironheights rules show IH-MCP-003.

What can IH-MCP-003 miss?

  • A narrow-looking path that is a symlink to somewhere broad.
  • Servers that take their root from an environment variable or a flag the rule does not read.
  • What the server does inside the folder you gave it.

No finding means no rule matched. It is not proof of safety. Files larger than 1 MiB are skipped without being read; the verdict is then incomplete, not no findings, but the file is still not checked. See Limitations.

Scores and thresholds shown are the CLI defaults; your config can change them. List every rule from the terminal with ironheights rules list.

All 35 rules