Use it in CI
Gate pull requests
Put MCPsight in the pipeline of any repo whose agents use MCP. The job fails when a server changed since the baseline you committed, and the findings appear on the pull request.
Before you start
- Run
mcpsight scan --from .mcp.jsononce on your machine. - Commit
.mcpsight/baseline.json. Without it,verifyexits 2 and has nothing to compare against.
GitHub Actions
name: mcpsight
on: [pull_request]
permissions:
contents: read
security-events: write # to upload SARIF
jobs:
mcpsight:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: actions/setup-go@v5
with: { go-version: '1.26' }
- run: go install github.com/greyquill/mcpsight/cmd/mcpsight@latest
# Only needed to scan local (npx, uvx, command) servers.
- run: sudo apt-get update && sudo apt-get install -y bubblewrap strace
# Fails the job if any server changed since the committed baseline.
- name: Verify MCP servers
run: mcpsight verify --from .mcp.json --offline
# Writes .mcpsight/report.sarif for code scanning, even if verify failed.
- name: Scan for the SARIF report
if: always()
run: mcpsight scan --from .mcp.json || true
- name: Upload SARIF
if: always()
uses: github/codeql-action/upload-sarif@v3
with:
sarif_file: .mcpsight/report.sarif
verify only checks for drift, so --offline costs nothing and keeps the gate fast and repeatable.
When the job fails
Read the drift findings first. If the change is expected, accept it in the same pull request:
mcpsight scan --update-baseline --from .mcp.json git add .mcpsight/baseline.json
The baseline diff is the review. Someone has to look at it before it merges.
Choose what fails the build
scan exits 1 when a finding is at or above --fail-on, which is high by default. Use --fail-on critical to block only the worst. See Exit codes.
Scanning local servers on
ubuntu-latest?Ubuntu 24.04 blocks bubblewrap by default. Add the AppArmor profile from Troubleshooting as a step before the scan. Remote-only scans do not need it.