Reference

Commands and flags

Two commands do the work: scan inspects servers, and verify checks them against your baseline.

mcpsight scan

mcpsight scan [target...] [flags]

Probes each target, runs every analyzer, prints a report, and records a baseline on a server's first scan.

FlagDefaultWhat it does
--from <file>Scan every server in an MCP config file
--jsonoffPrint the report as JSON instead of the summary
--sarifoffPrint SARIF instead of the summary
--markdownoffPrint Markdown instead of the summary
--fail-on <severity>highExit 1 if any finding is at or above this severity
--update-baselineoffRecord the current server as the new baseline
--offlineoffSkip checks that need the network (supply chain)
--rules <file>built inUse your own injection rule file
--allow-netoffLet a local server reach the network while it starts
--no-sandboxoffDangerous. Run local servers with no isolation
--timeout <duration>30sTime budget per server, such as 60s or 2m
--dir <path>.Folder that holds .mcpsight/
--no-coloroffTurn off colour

Flags that surprise people

  • --fail-on changes the exit code, never the output.
  • --update-baseline is how you accept a change. After the first scan, drift is reported and the baseline is left alone until you pass it.
  • --allow-net weakens the scan. Once the server may connect, a connection cannot be pinned on it, so connection findings are not reported for that run.
  • If you set more than one of --json, --sarif, and --markdown, the first in that order wins.

mcpsight verify

mcpsight verify [target...] [flags]

Re-scans and compares with the committed baseline. It never writes a baseline. It exits 1 on drift and 2 if a server has no baseline or could not be scanned. It takes --from, --offline, --timeout, --dir, and --no-color.

mcpsight version

Prints the version, the commit, and the rubric version the build scores with.

Targets

FormExampleRuns code on your machine
npm packagenpx:@modelcontextprotocol/server-everything@2.0.0Yes, in the sandbox
PyPI packageuvx:some-mcp-serverYes, in the sandbox
Container imagedocker:ghcr.io/org/server:tagYes, in a locked-down container
Remote serverhttps://mcp.example.com/mcpNo

Pin versions the usual way: npx:pkg@1.2.3, docker:image:tag. http:// works and adds a finding. Anything else is rejected:

mcpsight: unrecognized target "foo": expected npx:, uvx:, docker:, or an https:// URL

Local commands and anything else your config describes go through --from. You can mix targets and --from in one run.