Reference
Commands and flags
Two commands do the work: scan inspects servers, and verify checks them against your baseline.
mcpsight scan
mcpsight scan [target...] [flags]
Probes each target, runs every analyzer, prints a report, and records a baseline on a server's first scan.
| Flag | Default | What it does |
|---|---|---|
--from <file> | Scan every server in an MCP config file | |
--json | off | Print the report as JSON instead of the summary |
--sarif | off | Print SARIF instead of the summary |
--markdown | off | Print Markdown instead of the summary |
--fail-on <severity> | high | Exit 1 if any finding is at or above this severity |
--update-baseline | off | Record the current server as the new baseline |
--offline | off | Skip checks that need the network (supply chain) |
--rules <file> | built in | Use your own injection rule file |
--allow-net | off | Let a local server reach the network while it starts |
--no-sandbox | off | Dangerous. Run local servers with no isolation |
--timeout <duration> | 30s | Time budget per server, such as 60s or 2m |
--dir <path> | . | Folder that holds .mcpsight/ |
--no-color | off | Turn off colour |
Flags that surprise people
--fail-onchanges the exit code, never the output.--update-baselineis how you accept a change. After the first scan, drift is reported and the baseline is left alone until you pass it.--allow-netweakens the scan. Once the server may connect, a connection cannot be pinned on it, so connection findings are not reported for that run.- If you set more than one of
--json,--sarif, and--markdown, the first in that order wins.
mcpsight verify
mcpsight verify [target...] [flags]
Re-scans and compares with the committed baseline. It never writes a baseline. It exits 1 on drift and 2 if a server has no baseline or could not be scanned. It takes --from, --offline, --timeout, --dir, and --no-color.
mcpsight version
Prints the version, the commit, and the rubric version the build scores with.
Targets
| Form | Example | Runs code on your machine |
|---|---|---|
| npm package | npx:@modelcontextprotocol/server-everything@2.0.0 | Yes, in the sandbox |
| PyPI package | uvx:some-mcp-server | Yes, in the sandbox |
| Container image | docker:ghcr.io/org/server:tag | Yes, in a locked-down container |
| Remote server | https://mcp.example.com/mcp | No |
Pin versions the usual way: npx:pkg@1.2.3, docker:image:tag. http:// works and adds a finding. Anything else is rejected:
mcpsight: unrecognized target "foo": expected npx:, uvx:, docker:, or an https:// URL
Local commands and anything else your config describes go through --from. You can mix targets and --from in one run.