An SFTP and FTP MCP server that starts read-only
Connect your hosting account or any SFTP, FTPS or FTP server, and your AI client can browse folders, read logs, find what changed and check files. Uploads, edits and deletes stay off until you turn them on, tool by tool.
The files behind the site, in the conversation
A broken page usually ends with someone opening an FTP client to read an error log or check a config file. The File Server connector gives that job to your AI client: install the template, enter the login your host gave you, and Claude, ChatGPT or Cursor can look for themselves.
- Install from Templates, then fill in the server's File server settings
- Pick your host from the list and the protocol, port and login method are set for you, with a note on where that host shows the details
- Test connection before any client connects
// find_files: "what changed in the last day?" { "path": "/public_html", "pattern": "*.php", "modified_within_hours": 24, "sort": "modified" } // read_file: the last 50 lines of the error log { "path": "/public_html/error_log", "tail_lines": 50 }
Thirteen tools, in two groups
Six read tools are on from the moment you install. The seven that change files install switched off, and each one can be turned on individually from the Tools screen.
| Tool | What it does | On install |
|---|---|---|
| Read | ||
| list_directory | The files and folders in a folder, with size, last-modified time and permissions, paged for large folders | ✓ |
| get_file_info | Whether a path exists and what it is: file, folder or link, with size, time and permissions | ✓ |
| read_file | A text file's content, or only its first or last lines, which is how logs get read | ✓ |
| find_files | Search by name pattern, size or how recently a file changed | ✓ |
| download_file | Any file, including images and archives, under the connection's size cap | ✓ |
| checksum_file | A SHA-256, SHA-1 or MD5 checksum of a file, without sending its content | ✓ |
| Write, off until you enable them | ||
| write_file | Create a file, or replace one only when told to overwrite | |
| edit_file | Replace exact pieces of text in a file, with a preview before saving | |
| append_file | Add text to the end of a file | |
| create_directory | Create a folder | |
| move_path | Move or rename a file or folder | |
| delete_path | Delete a file, or a folder and what is in it when told to | |
| set_permissions | Change a file's permissions, on servers that allow it | |
Built so one wrong guess cannot break a live site
A model that can edit a production server needs limits it cannot argue its way around. These are enforced on your server, before a request goes out.
Read-only until you say otherwise
The connection starts read-only and the write tools install switched off. A write on a read-only connection is refused before GetMCP even connects to the server.
Kept inside one folder
Set a root folder such as /public_html and every path stays inside it. .. is refused, and so is any path that runs through a symbolic link.
Careful edits
An edit names the exact text it replaces, and that text must appear once. Nothing is saved unless every change matches, and a dry run shows the result first.
No half-written files
A written or edited file is uploaded to a temporary name first and moved into place, so a dropped connection never leaves a broken file behind. An existing file is only replaced when the call says to overwrite it.
The server you expect
FTPS verifies the TLS certificate, and SFTP can pin the host key fingerprint exactly as ssh-keygen -lf prints it, refusing to log in if it changes.
Bounded transfers
Each connection has a file size cap you set, from 1 to 20 MB, and a timeout. Large folders and searches are paged and bounded, so a single call cannot flood a conversation.
Clean up a hacked site, with your AI doing the digging
Malware on a site usually means hours in an FTP client: finding what changed, reading files nobody wrote, cutting out injected code without breaking the rest. With the File Server connector your AI client does that work, and you decide what changes.
- Investigate with the read tools only: list the PHP files that changed in the last few days and read the ones that look wrong
- Injected code tends to stand out, often obfuscated behind eval or base64_decode
- Take a backup, then turn on edit_file or delete_path for the cleanup itself
- Each edit names the exact code it removes, and a dry run shows the result before anything is saved
Keep the write tools off while the AI reads: a planted file can contain text written to mislead it. GetMCP does not detect malware; your AI suggests and you approve each change. Afterwards, close the way in by updating whatever was outdated and changing your FTP and admin passwords.
# 1. Investigate, read tools only // find_files: "which PHP files changed this week?" { "path": "/public_html", "pattern": "*.php", "modified_within_hours": 168 } // read_file: the one nobody uploaded { "path": "/public_html/wp-content/uploads/cache.php" } # 2. Clean up, after a backup // edit_file: remove the injected line, preview first { "path": "/public_html/wp-config.php", "edits": [{ "old_text": "@eval(base64_decode($_POST['x']));", "new_text": "" }], "dry_run": true }
Your host is probably already on the list
Hosts disagree on ports, protocols and where they hide the login. Choose yours and GetMCP fills in the protocol, port and login method, then tells you where that host shows the credentials. It never fills in a password.
- Log in with a password, or with an SSH private key on SFTP
- Credentials are encrypted on your install and never returned by the API
- Not on the list? Leave it empty and enter the host and port yourself
# Hosting provider presets cPanel hosting Hostinger Namecheap GoDaddy (cPanel) SiteGround WP Engine Kinsta Cloudways Pantheon AWS Transfer Family Azure Blob (SFTP) Synology NAS # Protocols sftp port 22 password or SSH key ftps port 21 explicit TLS ftps implicit port 990 ftp port 21 not encrypted
Questions about the file server connector
Does the AI get my FTP password or SSH key?
No. They are stored encrypted on your install and used only by your server to open the connection. The client sees tools, not connection details, and the API never returns a stored password or key, only whether one is set.
Can it reach a server on my own network?
Yes. A server on your LAN or a private address is allowed by default, because that is often where a NAS or staging box lives. Cloud metadata and link-local addresses are always refused.
Can it find and remove malware?
It can help you do it. The connector gives your AI client the evidence, recently changed files, their contents and checksums, and the precise edits to remove what it finds. Spotting malicious code is the AI's judgement, so you approve each change. Investigate with the write tools off, keep a backup, and treat it as a careful second pair of hands rather than a security scanner.
Should I use plain FTP?
Only if the server offers nothing else. Plain FTP sends the password and the files unencrypted, and the settings say so when you pick it. Choose SFTP or FTPS whenever your host supports them.
Can I connect more than one server?
Yes. Each file server is its own MCP server with its own connection, tools and logs. Publish several through the MCP Gateway if a client needs them together.
Let your AI read the logs for you.
Install the File Server template, enter the login your host gave you, and start asking. Nothing is written until you allow it.