Get started
Overview
MCPsight inspects an MCP server before you trust it. One command tells you what the server costs in tokens, what it can reach, and whether it changed since you last looked.
Why it exists
An MCP server hands your AI agent a list of tools. The model reads every tool description, and you usually never do. A description can tell the model to read your SSH key. A server can pass review today and ship a different description next week. MCPsight reads what the model reads, runs local servers in a sandbox to see what they actually do, and keeps a baseline so a change cannot slip past you.
Quick start
- Install it.
brew install --cask greyquill/tap/mcpsight
Linux, Windows, and Go installs are on the Install page.
- Scan the servers you already use.
mcpsight scan --from claude_desktop_config.json
Or scan one remote server by its URL:
mcpsight scan https://mcp.example.com/mcp. - Gate changes in CI.
mcpsight verify --from .mcp.json --offline
This fails the build when a server changed since the baseline you committed. See Gate pull requests.
What it checks
How it works
MCPsight connects to a server the way an agent does. It completes the handshake and reads the tools, resources, and prompts. Six analyzers read that result. Each problem becomes a finding with a stable rule ID, a severity, and a fix. The findings add up to a score out of 100 under a published rubric.
Local servers (npx:, uvx:, or a command) are other people's code, so MCPsight only runs them inside a sandbox on Linux. Remote servers run nothing on your machine and scan from any OS.
The checks are plain rules that run offline. Nothing is sent anywhere, except package lookups to OSV.dev and the npm or PyPI registry for supply-chain checks. --offline turns those off.