# read_multiple_files

Read the contents of multiple files simultaneously. This is more efficient than reading files one by one when you need to analyze or compare multiple files. Each file's content is returned with its path as a reference. Failed reads for individual files won't stop the entire operation. Only works within allowed directories.

Agent View of the PolicyLayer registry record for `read_multiple_files`. HTML page: https://policylayer.com/tools/filesystem/read-multiple-files

## Facts

- Tool: `read_multiple_files`
- Server: Filesystem (`@modelcontextprotocol/server-filesystem`) — https://policylayer.com/tools/filesystem.md
- Install: `npx -y @modelcontextprotocol/server-filesystem`
- Homepage: https://github.com/modelcontextprotocol/server-filesystem
- Risk category: Read (Low risk)
- Registry record: grade D, identity verified
- Server rate-limited: no
- Parameters: 1 (1 required)
- Recommended policy verdict: Allowed

## Parameters

| Parameter | Type | Required | Description |
| --- | --- | --- | --- |
| `paths` | array | yes | Array of file paths to read. Each path must be a string pointing to a valid file within allowed directories. |

Parameters from the server's own tool schema.

## Example call (MCP tools/call, JSON-RPC 2.0)

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "read_multiple_files",
    "arguments": {
      "paths": []
    }
  }
}
```

## Why read_multiple_files is rated Low

This tool retrieves file contents without any side effects or modifications. It queries and returns data from the filesystem. The constraint to 'allowed directories' and the read-only nature make this a straightforward Read category tool with low severity—misuse would only expose data already accessible to the agent, not cause irreversible changes or execute arbitrary operations.

From the tool's own definition: "Tool name is 'read_multiple_files' and description states it 'Read the contents of multiple files simultaneously' with no modification or deletion capability mentioned."

Risk signals: Bulk/mass operation — affects multiple targets

## Use case

AI agents call read_multiple_files to retrieve information from Filesystem without modifying anything. It is typically the context-gathering step in research, monitoring, and reporting workflows, before the agent takes action elsewhere.

## Recommended policy (PolicyLayer)

Verdict: **Allowed**. Enforced by the PolicyLayer MCP gateway (https://policylayer.com/mcp-gateway) before a call reaches Filesystem:

```json
{
  "version": "1",
  "default": "deny",
  "tools": {
    "read_multiple_files": {}
  }
}
```

## Other tools on Filesystem (13)

- `directory_tree` — Read — https://policylayer.com/tools/filesystem/directory-tree.md
- `get_file_info` — Read — https://policylayer.com/tools/filesystem/get-file-info.md
- `list_allowed_directories` — Read — https://policylayer.com/tools/filesystem/list-allowed-directories.md
- `list_directory` — Read — https://policylayer.com/tools/filesystem/list-directory.md
- `list_directory_with_sizes` — Read — https://policylayer.com/tools/filesystem/list-directory-with-sizes.md
- `read_file` — Read — https://policylayer.com/tools/filesystem/read-file.md
- `read_media_file` — Read — https://policylayer.com/tools/filesystem/read-media-file.md
- `read_text_file` — Read — https://policylayer.com/tools/filesystem/read-text-file.md
- `search_files` — Read — https://policylayer.com/tools/filesystem/search-files.md
- `create_directory` — Write — https://policylayer.com/tools/filesystem/create-directory.md
- `edit_file` — Write — https://policylayer.com/tools/filesystem/edit-file.md
- `move_file` — Write — https://policylayer.com/tools/filesystem/move-file.md
- `write_file` — Write — https://policylayer.com/tools/filesystem/write-file.md

## For agents

This record is a snapshot. Live verdicts and the full registry:

- Check every server in your MCP config at once: `npx -y policylayer stack`
- Vet a server before you add it: install the mcp-precheck skill — `npx skills add https://policylayer.com` (skill text: https://policylayer.com/skill.md)
- Query the registry over MCP: endpoint `https://api.policylayer.com/mcp` — tools `check_mcp_server`, `check_mcp_stack`, `check_tool`, `search_registry`, `get_change_events`

---

Source: the PolicyLayer MCP registry — one continuously verified record per MCP server. Full record: https://policylayer.com/registry?q=filesystem · API: https://policylayer.com/registry/api · Policy library: https://policylayer.com/policies/filesystem
