MCP for Filesystems and Databases
What This Article Covers
- Building MCP tools for filesystems and databases.
- How agents read, write, and manage files.
- How agents query and manipulate databases.
- Practical examples for file and database operations.
- Security and permissions best practices.
Introduction: Understanding MCP for Filesystems and Databases
MCP tools connect agents to external systems. For filesystems: agents can read, write, and list files. For databases: agents can query, insert, and update records. Permissions ensure security.
This article targets developers building MCP tools for filesystems and databases. For foundations, see MCP and MCP Permissions.
Why Do You Need MCP for Filesystems and Databases?
Imagine your agent needs to process documents: it must read files (PDFs, text), analyze them, and save results. Without MCP, the agent cannot access files. With MCP, it reads files, processes them, and stores results.
MCP for Filesystems and Databases Explained
An MCP tool is an interface between an agent and a system. Filesystem tools include read_file, write_file, and list_files. Database tools include query, insert, and update. Permissions control access.
The core idea: Agent + Tool = Access to external systems.
Who Should Read This?
- Developers building MCP tools.
- Agent builders needing file or database access.
- DevOps engineers connecting agents to systems.
- Security-conscious teams implementing permissions.
Key Concepts
- MCP - Model Context Protocol. Useful for tool integration.
- MCP Permissions - Access control. Useful for security.
- Tool Calling - Invoking tools. Useful for agents.
- Ollama - Local model server. Useful for agents.
Filesystem MCP Tool
class FileSystemMCPTool:
"""MCP tool for filesystem"""
def __init__(self):
self.permissions = {
"read": True,
"write": True,
"delete": False,
"allowed_paths": ["/data", "/tmp", "/workspace"]
}
def get_tools(self):
"""Tool definitions for MCP"""
return [
{
"name": "read_file",
"description": "Read a file",
"parameters": {
"type": "object",
"properties": {
"path": {"type": "string", "description": "File path"}
},
"required": ["path"]
}
},
{
"name": "write_file",
"description": "Write to a file",
"parameters": {
"type": "object",
"properties": {
"path": {"type": "string"},
"content": {"type": "string"}
},
"required": ["path", "content"]
}
},
{
"name": "list_files",
"description": "List files in a directory",
"parameters": {
"type": "object",
"properties": {
"directory": {"type": "string"}
},
"required": ["directory"]
}
}
]
def read_file(self, path):
"""Read a file"""
self.check_permission("read", path)
with open(path) as f:
return f.read()
def write_file(self, path, content):
"""Write to a file"""
self.check_permission("write", path)
with open(path, "w") as f:
f.write(content)
def list_files(self, directory):
"""List files in a directory"""
self.check_permission("read", directory)
import os
return os.listdir(directory)
Database MCP Tool
class DatabaseMCPTool:
"""MCP tool for databases"""
def __init__(self, db_connection):
self.db = db_connection
self.permissions = {
"read": True,
"insert": True,
"update": False,
"delete": False,
"allowed_tables": ["users", "logs", "events"]
}
def get_tools(self):
"""Tool definitions for MCP"""
return [
{
"name": "query_database",
"description": "Query the database",
"parameters": {
"type": "object",
"properties": {
"table": {"type": "string"},
"filters": {"type": "object"}
},
"required": ["table"]
}
},
{
"name": "insert_data",
"description": "Insert data",
"parameters": {
"type": "object",
"properties": {
"table": {"type": "string"},
"data": {"type": "object"}
},
"required": ["table", "data"]
}
}
]
def query(self, table, filters=None):
"""Query the database"""
self.check_permission("read", table)
return self.db.query(table, filters)
def insert(self, table, data):
"""Insert data"""
self.check_permission("insert", table)
return self.db.insert(table, data)
Practical Example: Agent with Filesystem MCP
# Agent uses filesystem tool
agent = Agent(
model="llama3.1",
tools=[FileSystemMCPTool()]
)
# Agent can now:
# - read_file("/data/document.txt")
# - write_file("/data/result.txt", "...")
# - list_files("/data")
# Example task:
task = "Read the file /data/report.txt and summarize it."
# Agent: read_file → summarize → response
Practical Example: Agent with Database MCP
# Agent uses database tool
agent = Agent(
model="llama3.1",
tools=[DatabaseMCPTool(db_connection)]
)
# Agent can now:
# - query_database("users", {"status": "active"})
# - insert_data("logs", {"event": "...", "timestamp": "..."})
# Example task:
task = "How many active users are there?"
# Agent: query_database → count → response
Security Considerations
- Path restrictions: For filesystems, allow only specific paths. See MCP Permissions.
- SQL injection: For databases, use parameterized queries, never string concatenation.
- Minimal permissions: Grant only necessary actions (read/write, not delete).
- Audit logging: Log all file and database access. See Audit Logging.
Common Pitfalls
- Overly permissive access: Agents should not access all paths or tables.
- Missing validation: Paths and queries should be validated.
- SQL injection: Never use string concatenation for queries. Use parameterized queries.
- Poor error handling: Handle file not found, database errors, and other failures.
- No rate limiting: Prevent agents from sending excessive requests.
Further Reading
- MCP - Model Context Protocol.
- MCP Permissions - Access control.
- Custom MCP Tools - Building tools.
- MCP Security - Security practices.
- Tool Permissions - Permission management.
Key Takeaways:
- Filesystem MCP: read_file, write_file, list_files with path restrictions.
- Database MCP: query, insert with table restrictions.
- Enforce path restrictions for filesystems and table restrictions for databases.
- Use parameterized queries to prevent SQL injection.
- Maintain audit logs for all access.
FAQ
What is MCP for filesystems?
What is MCP for databases?
Is this secure?
How do I set permissions?
How do I prevent SQL injection?
What tools are available?
How do I log access?
Sources and Further Reading
- MCP - Model Context Protocol.
- SQL Injection Prevention - OWASP.


