# filesystem_move

Move or rename a file or directory within the project (carrying its .import sidecar), then rescan. DESTRUCTIVE (moves on disk; does NOT remap references in other resources) — gated by confirmation.

Agent View of the PolicyLayer registry record for `filesystem_move`. HTML page: https://policylayer.com/tools/breakpoint-mcp/filesystem-move

## Facts

- Tool: `filesystem_move`
- Server: Breakpoint (`breakpoint-mcp`) — https://policylayer.com/tools/breakpoint-mcp.md
- Install: `npx -y breakpoint-mcp`
- Homepage: https://www.npmjs.com/package/breakpoint-mcp
- Risk category: Destructive (Critical risk)
- Registry record: grade F, identity unverified
- Server rate-limited: no
- Parameters: 3 (2 required)
- Recommended policy verdict: Hidden

## Parameters

| Parameter | Type | Required | Description |
| --- | --- | --- | --- |
| `confirm` | boolean | no | Auto-approve this destructive action (skip the confirmation prompt) |
| `to_path` | string | yes | Destination res:// path |
| `from_path` | string | yes | Source res:// path (file or directory) |

Parameters from the server's own tool schema.

## Example call (MCP tools/call, JSON-RPC 2.0)

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "filesystem_move",
    "arguments": {
      "to_path": "<to_path>",
      "from_path": "<from_path>"
    }
  }
}
```

## Why filesystem_move is rated Critical

The tool moves or renames files on disk, which is an irreversible filesystem operation. The description explicitly labels it DESTRUCTIVE and notes it does not remap references in other resources, meaning it can break project references.

From the tool's own definition: "DESTRUCTIVE (moves on disk; does NOT remap references in other resources) — gated by confirmation"

## Use case

AI agents call filesystem_move to permanently remove resources in Breakpoint, typically in cleanup and lifecycle workflows. It does its job in a single call, and there is no undo.

## Recommended policy (PolicyLayer)

Verdict: **Hidden**. Enforced by the PolicyLayer MCP gateway (https://policylayer.com/mcp-gateway) before a call reaches Breakpoint:

```json
{
  "version": "1",
  "default": "deny",
  "hide": [
    "filesystem_move"
  ]
}
```

## Other tools on Breakpoint (273)

- `anim_delete` — Destructive — https://policylayer.com/tools/breakpoint-mcp/anim-delete.md
- `anim_remove_key` — Destructive — https://policylayer.com/tools/breakpoint-mcp/anim-remove-key.md
- `gd_rename` — Destructive — https://policylayer.com/tools/breakpoint-mcp/gd-rename.md
- `inputmap_erase_action` — Destructive — https://policylayer.com/tools/breakpoint-mcp/inputmap-erase-action.md
- `mp_wire_rpc` — Destructive — https://policylayer.com/tools/breakpoint-mcp/mp-wire-rpc.md
- `node_delete` — Destructive — https://policylayer.com/tools/breakpoint-mcp/node-delete.md
- `project_remove_autoload` — Destructive — https://policylayer.com/tools/breakpoint-mcp/project-remove-autoload.md
- `resource_save` — Destructive — https://policylayer.com/tools/breakpoint-mcp/resource-save.md
- `resource_set_import_settings` — Destructive — https://policylayer.com/tools/breakpoint-mcp/resource-set-import-settings.md
- `runtime_node_remove` — Destructive — https://policylayer.com/tools/breakpoint-mcp/runtime-node-remove.md
- `runtime_peer_stop` — Destructive — https://policylayer.com/tools/breakpoint-mcp/runtime-peer-stop.md
- `scene_close` — Destructive — https://policylayer.com/tools/breakpoint-mcp/scene-close.md
- `scene_reload` — Destructive — https://policylayer.com/tools/breakpoint-mcp/scene-reload.md
- `shader_set_code` — Destructive — https://policylayer.com/tools/breakpoint-mcp/shader-set-code.md
- `tilemap_clear` — Destructive — https://policylayer.com/tools/breakpoint-mcp/tilemap-clear.md
- `vcs_restore` — Destructive — https://policylayer.com/tools/breakpoint-mcp/vcs-restore.md
- `vcs_stash` — Destructive — https://policylayer.com/tools/breakpoint-mcp/vcs-stash.md
- `cs_dbg_attach` — Execute — https://policylayer.com/tools/breakpoint-mcp/cs-dbg-attach.md
- `cs_dbg_continue` — Execute — https://policylayer.com/tools/breakpoint-mcp/cs-dbg-continue.md
- `cs_dbg_launch` — Execute — https://policylayer.com/tools/breakpoint-mcp/cs-dbg-launch.md
- `cs_dbg_restart` — Execute — https://policylayer.com/tools/breakpoint-mcp/cs-dbg-restart.md
- `cs_dbg_set_breakpoints` — Execute — https://policylayer.com/tools/breakpoint-mcp/cs-dbg-set-breakpoints.md
- `cs_dbg_set_exception_breakpoints` — Execute — https://policylayer.com/tools/breakpoint-mcp/cs-dbg-set-exception-breakpoints.md
- `cs_dbg_set_variable` — Execute — https://policylayer.com/tools/breakpoint-mcp/cs-dbg-set-variable.md
- `cs_dbg_step` — Execute — https://policylayer.com/tools/breakpoint-mcp/cs-dbg-step.md
- `dbg_attach` — Execute — https://policylayer.com/tools/breakpoint-mcp/dbg-attach.md
- `dbg_continue` — Execute — https://policylayer.com/tools/breakpoint-mcp/dbg-continue.md
- `dbg_data_breakpoints` — Execute — https://policylayer.com/tools/breakpoint-mcp/dbg-data-breakpoints.md
- `dbg_goto` — Execute — https://policylayer.com/tools/breakpoint-mcp/dbg-goto.md
- `dbg_launch` — Execute — https://policylayer.com/tools/breakpoint-mcp/dbg-launch.md
- …and 243 more: https://policylayer.com/tools/breakpoint-mcp.md

## For agents

This record is a snapshot. Live verdicts and the full registry:

- Check every server in your MCP config at once: `npx -y policylayer stack`
- Vet a server before you add it: install the mcp-precheck skill — `npx skills add https://policylayer.com` (skill text: https://policylayer.com/skill.md)
- Query the registry over MCP: endpoint `https://api.policylayer.com/mcp` — tools `check_mcp_server`, `check_mcp_stack`, `check_tool`, `search_registry`, `get_change_events`

---

Source: the PolicyLayer MCP registry — one continuously verified record per MCP server. Full record: https://policylayer.com/registry?q=breakpoint-mcp · API: https://policylayer.com/registry/api · Policy library: https://policylayer.com/policies/breakpoint-mcp
