ContextFS gives LLM agents a persistent, structured filesystem via MCP, enabling sandboxed file operations, workspace management, and memory/skills storage without direct machine access.
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
ws affected by a DoS when handling a request with many HTTP headers
ws: Memory exhaustion DoS from tiny fragments and data chunks
express vulnerable to XSS via response.redirect()
Express.js Open Redirect in malformed URLs
ws: Uninitialized memory disclosure
process.env. You'll be asked to provide them before it can run.CONTEXTFS_BASE_URLCONTEXTFS_INSECURE— Enable bash_script_once (1) —CONTEXTFS_LOCAL— local Local mode: tools run in-process, no WS clients (env: =1)CONTEXTFS_MCP_SERVER— MCP server base URL for chat http://localhost:3010CONTEXTFS_MODEL— model <model> LLM model via OpenRouter (env: )CONTEXTFS_RTK_ENABLED— Enable RTK optimization (true/false) true (auto-detect)CONTEXTFS_RTK_PATHCONTEXTFS_RTK_STATUSCONTEXTFS_RTK_TEE_ON_ERRORCONTEXTFS_RTK_TIMEOUTCONTEXTFS_RTK_ULTRA_COMPACT— Ultra-Compact Mode: Force maximum compression by setting =true or passing the -u flag to supported commands.CONTEXTFS_VC_ID— id> CONTEXTFS_VC_KEY=<key> OPENROUTER_API_KEY=sk-or-... \CONTEXTFS_VC_KEY— CONTEXTFS_VC_ID=<id> =<key> OPENROUTER_API_KEY=sk-or-... \OPENROUTER_API_KEY— CONTEXTFS_VC_ID=<id> CONTEXTFS_VC_KEY=<key> =sk-or-... \PORT— port <port> HTTP + WS port (default: 3010, env: )[](https://m8ven.ai/mcp/javimosch-contextfs-wa5q2g)