From c439b1bb0099752a72075aa11d2a0e2d6cbf93c9 Mon Sep 17 00:00:00 2001 From: Evan Date: Thu, 16 Apr 2026 13:03:27 +0900 Subject: [PATCH] fix(integrations): use npx directly instead of sh -c wrapper (#61) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The librefang MCP security check blocks shell interpreters (sh, bash) as commands. Use `command = "npx"` with `$HOME` in args — the runtime now expands env vars in args natively. --- integrations/filesystem.toml | 7 ++----- 1 file changed, 2 insertions(+), 5 deletions(-) diff --git a/integrations/filesystem.toml b/integrations/filesystem.toml index d77975d..02f9bc9 100644 --- a/integrations/filesystem.toml +++ b/integrations/filesystem.toml @@ -7,11 +7,8 @@ tags = ["files", "local", "read", "write", "search"] [transport] type = "stdio" -command = "sh" -args = [ - "-c", - "exec npx -y @modelcontextprotocol/server-filesystem@latest \"$HOME\"", -] +command = "npx" +args = ["-y", "@modelcontextprotocol/server-filesystem@latest", "$HOME"] [health_check] interval_secs = 60