Use it in CI

Gate pull requests

Put MCPsight in the pipeline of any repo whose agents use MCP. The job fails when a server changed since the baseline you committed, and the findings appear on the pull request.

Before you start

  1. Run mcpsight scan --from .mcp.json once on your machine.
  2. Commit .mcpsight/baseline.json. Without it, verify exits 2 and has nothing to compare against.

GitHub Actions

name: mcpsight
on: [pull_request]

permissions:
  contents: read
  security-events: write   # to upload SARIF

jobs:
  mcpsight:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
      - uses: actions/setup-go@v5
        with: { go-version: '1.26' }
      - run: go install github.com/greyquill/mcpsight/cmd/mcpsight@latest

      # Only needed to scan local (npx, uvx, command) servers.
      - run: sudo apt-get update && sudo apt-get install -y bubblewrap strace

      # Fails the job if any server changed since the committed baseline.
      - name: Verify MCP servers
        run: mcpsight verify --from .mcp.json --offline

      # Writes .mcpsight/report.sarif for code scanning, even if verify failed.
      - name: Scan for the SARIF report
        if: always()
        run: mcpsight scan --from .mcp.json || true

      - name: Upload SARIF
        if: always()
        uses: github/codeql-action/upload-sarif@v3
        with:
          sarif_file: .mcpsight/report.sarif

verify only checks for drift, so --offline costs nothing and keeps the gate fast and repeatable.

When the job fails

Read the drift findings first. If the change is expected, accept it in the same pull request:

mcpsight scan --update-baseline --from .mcp.json
git add .mcpsight/baseline.json

The baseline diff is the review. Someone has to look at it before it merges.

Choose what fails the build

scan exits 1 when a finding is at or above --fail-on, which is high by default. Use --fail-on critical to block only the worst. See Exit codes.

Scanning local servers on ubuntu-latest?

Ubuntu 24.04 blocks bubblewrap by default. Add the AppArmor profile from Troubleshooting as a step before the scan. Remote-only scans do not need it.