What does IH-MCP-003 flag?
Flags a filesystem MCP server that is pointed at a filesystem root, a drive root, or a whole home directory.
- A server argument that is /, a drive root, ~, or a home directory such as the home folder of one user.
- Not reported: a project folder or any subdirectory such as ./notes or a path under your projects folder.
Why it matters
A file server given the whole disk or your whole home folder can read SSH keys, browser stores and every project, not just the folder the task needs.
Examples
Illustrative shapes with placeholders in angle brackets. They show what the rule looks at; they are not runnable and not taken from real malware.
Can IH-MCP-003 fire on a safe skill?
- A machine that only holds throwaway data, where a broad root is a deliberate choice.
How do I fix an IH-MCP-003 finding?
- Pass the project directory the task needs, not a home directory or a filesystem root.
CLI guidance: Pass a project directory, not a home directory or a filesystem root.
How do I tune or allow IH-MCP-003?
If a broad root is intentional, record that with a config suppression and a reason, or lower the severity with ruleOverrides. Keep the exception in the project's own config.
Every key is described in Configuration. To print this rule from the CLI, run ironheights rules show IH-MCP-003.
What can IH-MCP-003 miss?
- A narrow-looking path that is a symlink to somewhere broad.
- Servers that take their root from an environment variable or a flag the rule does not read.
- What the server does inside the folder you gave it.
No finding means no rule matched. It is not proof of safety. Files larger than 1 MiB are skipped without being read; the verdict is then incomplete, not no findings, but the file is still not checked. See Limitations.
Related rules
ironheights rules list.