# move_file

Move or rename files and directories. Can move files between directories and rename them in a single operation. If the destination exists, the operation will fail. Works across different directories and can be used for simple renaming within the same directory. Both source and destination must be within allowed directories.

Agent View of the PolicyLayer registry record for `move_file`. HTML page: https://policylayer.com/tools/filesystem/move-file

## Facts

- Tool: `move_file`
- Server: Filesystem (`@modelcontextprotocol/server-filesystem`) — https://policylayer.com/tools/filesystem.md
- Install: `npx -y @modelcontextprotocol/server-filesystem`
- Homepage: https://github.com/modelcontextprotocol/server-filesystem
- Risk category: Write (Medium risk)
- Registry record: grade D, identity verified
- Server rate-limited: no
- Parameters: 2 (2 required)
- Recommended policy verdict: Rate-limited

## Parameters

| Parameter | Type | Required | Description |
| --- | --- | --- | --- |
| `source` | string | yes |  |
| `destination` | string | yes |  |

Parameters from the server's own tool schema.

## Example call (MCP tools/call, JSON-RPC 2.0)

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "move_file",
    "arguments": {
      "source": "<source>",
      "destination": "<destination>"
    }
  }
}
```

## Why move_file is rated Medium

The tool modifies file paths and locations but does not delete or irreversibly destroy data. Files can be moved back to their original locations, making this a Write operation rather than Destructive. The severity is medium because misuse could corrupt application state or file organization, but the impact is recoverable via a reverse move operation.

From the tool's own definition: "Tool description states it can 'Move or rename files and directories' and 'move files between directories'. These are reversible modifications to file system state."

Risk signals: Accepts file system path (destination)

## Use case

AI agents use move_file to create or update resources in Filesystem, usually the action step of a workflow, after the agent has gathered context. Every call changes real data in your Filesystem environment.

## Recommended policy (PolicyLayer)

Verdict: **Rate-limited**. Enforced by the PolicyLayer MCP gateway (https://policylayer.com/mcp-gateway) before a call reaches Filesystem:

```json
{
  "version": "1",
  "default": "deny",
  "tools": {
    "move_file": {
      "limits": [
        {
          "counter": "move_file_rate",
          "window": "minute",
          "max": 30,
          "scope": "grant"
        }
      ]
    }
  }
}
```

## Other tools on Filesystem (13)

- `directory_tree` — Read — https://policylayer.com/tools/filesystem/directory-tree.md
- `get_file_info` — Read — https://policylayer.com/tools/filesystem/get-file-info.md
- `list_allowed_directories` — Read — https://policylayer.com/tools/filesystem/list-allowed-directories.md
- `list_directory` — Read — https://policylayer.com/tools/filesystem/list-directory.md
- `list_directory_with_sizes` — Read — https://policylayer.com/tools/filesystem/list-directory-with-sizes.md
- `read_file` — Read — https://policylayer.com/tools/filesystem/read-file.md
- `read_media_file` — Read — https://policylayer.com/tools/filesystem/read-media-file.md
- `read_multiple_files` — Read — https://policylayer.com/tools/filesystem/read-multiple-files.md
- `read_text_file` — Read — https://policylayer.com/tools/filesystem/read-text-file.md
- `search_files` — Read — https://policylayer.com/tools/filesystem/search-files.md
- `create_directory` — Write — https://policylayer.com/tools/filesystem/create-directory.md
- `edit_file` — Write — https://policylayer.com/tools/filesystem/edit-file.md
- `write_file` — Write — https://policylayer.com/tools/filesystem/write-file.md

## For agents

This record is a snapshot. Live verdicts and the full registry:

- Check every server in your MCP config at once: `npx -y policylayer stack`
- Vet a server before you add it: install the mcp-precheck skill — `npx skills add https://policylayer.com` (skill text: https://policylayer.com/skill.md)
- Query the registry over MCP: endpoint `https://api.policylayer.com/mcp` — tools `check_mcp_server`, `check_mcp_stack`, `check_tool`, `search_registry`, `get_change_events`

---

Source: the PolicyLayer MCP registry — one continuously verified record per MCP server. Full record: https://policylayer.com/registry?q=filesystem · API: https://policylayer.com/registry/api · Policy library: https://policylayer.com/policies/filesystem
