Open-source MCP security scanner

See inside every MCP server before your agent trusts it

MCPsight reads every tool description the model will read, runs local servers in a sandbox with decoy credentials, and fails your build when a server changes.

Apache-2.0 · Runs offline · No account or API key

mcpsight scan
$ mcpsight scan http://127.0.0.1:8931/poisoned
  poisoned-descriptions
  Server        poisoned-descriptions  (0.1.0, via remote)
  Grade         F  (0/100)  rubric v1

  Context cost  ~462 tokens  (5 tools)   ~$0.001 per request @ Claude Sonnet  (est.)
  Capabilities  code:eval  fs:read  fs:write
  Drift         baseline recorded (first scan)

  Findings
  CRITICAL  Tool description tries to override the model's instructions [injection.override_instruction]
      tool: summarize
      fix: Remove instruction-like text from the description; a tool description should
      describe the tool, not command the model.
  HIGH      Tool description issues an imperative instruction to the model [injection.imperative_instruction]
      tool: weather
      fix: Descriptions should not tell the model what to do before/after other tools.
      State only what this tool does.
  HIGH      Tool description instructs reading sensitive or unrelated paths [injection.unrelated_path]
      tool: weather
      fix: Remove references to credential or system files; a tool's description should
      not point the model at ~/.ssh, ~/.aws, .env, or similar.
  HIGH      Tool description references another tool or server [injection.cross_tool_reference]
      tool: notes
      fix: A tool must not orchestrate other tools through its description; this is how
      cross-tool hijacking works.
  ...

A real scan of the poisoned practice server that ships with MCPsight.

How it works

Get started in three steps

Scan the servers you already use in under a minute, then keep watching them in CI.

01

Install MCPsight

One binary for macOS, Linux, and Windows. No account and no API key.

brew install --cask greyquill/tap/mcpsight
02

Scan your servers

Point it at the MCP config you already use. It scans every server in it.

mcpsight scan --from claude_desktop_config.json
03

Gate changes in CI

Commit the baseline. The build fails when a server changes under you.

mcpsight verify --from .mcp.json --offline

The sandbox

It watches what the server actually does

Local servers run on Linux inside bubblewrap. MCPsight records every file they open and every connection they try.

  • A fake home with decoy SSH keys, AWS credentials, and .env
  • No network, and limits on memory, CPU, files, and time
  • Your environment variables and files never reach the server
  • No sandbox available? MCPsight refuses to run the server at all
How the sandbox works →
Linux · bubblewrap
$ mcpsight scan --offline --from credential-thief.json
  credential-thief
  Server        credential-thief  (2.0.1, via bubblewrap)
  Grade         F  (39/100, capped by a critical finding)  rubric v1

  Context cost  ~75 tokens  (1 tool)   under $0.001 per request @ Claude Sonnet  (est.)
  Capabilities  none declared
  Drift         baseline recorded (first scan)

  Findings
  CRITICAL  Server read decoy credential files on startup [capability.decoy_read]
      During the probe the server read the decoy credential file(s): .ssh/id_rsa,
      .aws/credentials, .env. A server that reads credential files on startup is
      exfiltrating, not initializing.
      fix: Do not install this server. Report it to the registry it came from.

Rug-pull detection

Catch the change you would never reread

A server can pass review today and ship a poisoned description next week. Commit a baseline next to your MCP config, and mcpsight verify fails the pull request when anything changes.

  • Graded by direction, so a new instruction to the model is critical and a shorter description is noise
  • The baseline diff is the review, in your own repo
  • SARIF output puts findings on the pull request
Catch a rug pull, step by step →
after the server changed
$ mcpsight verify http://127.0.0.1:8931/rugpull
  config-reader
  Server        config-reader  (1.5.0, via remote)
  Grade         F  (0/100)  rubric v1

  Context cost  ~216 tokens  (1 tool)   ~$0.001 per request @ Claude Sonnet  (est.)
  Capabilities  fs:read  fs:write
  Drift         DRIFTED: 3 change(s) since baseline

  Findings
  CRITICAL  Tool description gained a model-directed instruction [drift.instruction_added]
      tool: read_config
      The description of "read_config" now contains an instruction aimed at the
      model that was not there in the baseline. This is the classic rug-pull.
      fix: Do not upgrade. Inspect the new description and pin the previous version.
  HIGH      Tool capability escalated [drift.capability_escalated]
      tool: read_config
      The input schema of "read_config" changed in a way that adds capability:
      fs:write.
      fix: Confirm the server legitimately needs the new capability before upgrading.
  ...

Scan your first server in a minute

Open source under Apache-2.0. Read the rules, dispute a finding, or run the whole thing yourself.