
Security News
Lovable’s OJ Rewrites Vite’s Dev Server in Rust as AI Lowers the Cost of Forking Open Source
Lovable’s OJ rewrites Vite’s dev server in Rust, reducing memory use and preview times as AI lowers the cost of open source reimplementation.
mcp-folder-scout
Advanced tools
Read-only MCP server that summarizes a local folder: what is in it, what is stale, and where the space went.
Ask Claude what's in a folder, what's gone stale, and where the space went.
Points at one folder on your machine and reports names, sizes, and dates. It cannot read file contents, and it cannot move or delete anything.
> What's in my Downloads folder, and what haven't I opened in over a year?
771 files, 43.0 GB. Video is 96% of it.
Not opened in over a year: 102 files, 15.3 GB, almost all of it
video — Barclay lake (27 clips, ~12 GB) and Big (2 clips, 2.5 GB).
If those are backed up elsewhere, they're the obvious candidates.
76 files matched identity, legal, tax, or medical naming and were
excluded from the suggestions above.
claude mcp add --scope user folder-scout -- uvx mcp-folder-scout
For Claude Desktop, add this to claude_desktop_config.json and restart:
{
"mcpServers": {
"folder-scout": {
"command": "uvx",
"args": ["mcp-folder-scout"]
}
}
}
The config file lives at ~/Library/Application Support/Claude/claude_desktop_config.json on macOS and %APPDATA%\Claude\claude_desktop_config.json on Windows.
Requires uv and Python 3.10+. Works with any MCP client.
| Tool | What it does |
|---|---|
scan_folder | Rollup of a folder: type breakdown, age bands, largest subfolders. |
list_files | Individual files filtered by age, size, type, or subfolder. |
Both return metadata only.
It cannot delete, move, or rename anything. There is no write path in the code. Suggestions go to you; you act on them yourself in Finder.
It cannot read your files. Only names, sizes, and timestamps leave your machine.
It will not recommend removing your documents. Files and folders matching identity, legal, tax, or medical naming — passport, visa, W2, insurance, marriage, deed, and others — are counted in the totals and marked, but never offered as cleanup candidates. That protection inherits downward, so a file called scan1.pdf inside Passport Renewal/ is covered too.
Cloud-synced folders (iCloud, Dropbox, OneDrive) are skipped rather than handled, because their sizes and timestamps are meaningless on disk. System folders, app bundles, and build directories are skipped too. Every scan reports what it excluded.
Last-access time is a hint, not a fact. Spotlight, backups, and antivirus can all bump it, and some volumes stop tracking it entirely. When the server detects that access times aren't being maintained, it says so and falls back to modified dates.
Old and untouched describes archived tax records as accurately as it describes junk. That's what the protected list is for, and it will not catch everything. Review before you delete.
APFS clones and hard links share blocks on disk. Files sharing an inode are counted once, so totals don't double-count, but deleting one copy of a cloned file may free less than its listed size.
Scans stop at 50,000 files and descend three levels by default. Results are cached for five minutes; pass refresh to force a rescan.
Screenshot piles and near-duplicate images are not detected yet. Exact-duplicate detection is planned.
MIT
mcp-name: io.github.dharani0804/mcp-folder-scout
mcp-name: io.github.dharani0804/mcp-folder-scout
FAQs
Read-only MCP server that summarizes a local folder: what is in it, what is stale, and where the space went.
We found that mcp-folder-scout demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
Lovable’s OJ rewrites Vite’s dev server in Rust, reducing memory use and preview times as AI lowers the cost of open source reimplementation.

Security News
It has been one year since Shai-Hulud made its first appearance on npm.

Research
/Security News
Operators behind PolinRider used a compromised GitHub account to plant malware in four development versions of a Packagist package with 700,000+ downloads.