Reference
Custom injection rules
The injection rules are a YAML file anyone can read and argue with. Copy it, change it, and scan with your version.
The rule file
Each rule has an ID, a severity, a title, a fix, and a list of patterns. A rule fires if any pattern matches the tool's name or description. Patterns are case-insensitive regular expressions.
version: 1
rules:
- id: injection.override_instruction
severity: critical
title: "Tool description tries to override the model's instructions"
remediation: "Remove instruction-like text from the description; ..."
any:
- '(?i)ignore\s+(all\s+)?(previous|prior|above)\s+instructions'
- '(?i)do\s+not\s+(tell|inform|mention\s+to|reveal\s+to|notify)\s+the\s+user'
Some checks cannot be written as patterns: invisible characters, encoded payloads, and length. Those are built in and always run.
Use your own
Copy the built-in file, edit it, and pass it with --rules. For example, remove the injection.cross_tool_reference block and scan the poisoned practice server:
mcpsight scan --rules my-rules.yaml http://127.0.0.1:8931/poisoned
poisoned-descriptions
Server poisoned-descriptions (0.1.0, via remote)
Grade F (0/100) rubric v1
Context cost ~462 tokens (5 tools) ~$0.001 per request @ Claude Sonnet (est.)
Capabilities code:eval fs:read fs:write
Drift unchanged since baseline
Findings
CRITICAL Tool description tries to override the model's instructions [injection.override_instruction]
tool: summarize
fix: Remove instruction-like text from the description; a tool description should
describe the tool, not command the model.
HIGH Tool description issues an imperative instruction to the model [injection.imperative_instruction]
tool: weather
fix: Descriptions should not tell the model what to do before/after other tools.
State only what this tool does.
HIGH Tool description instructs reading sensitive or unrelated paths [injection.unrelated_path]
tool: weather
fix: Remove references to credential or system files; a tool's description should
not point the model at ~/.ssh, ~/.aws, .env, or similar.
HIGH Description contains hidden or deceptive characters [injection.invisible_chars]
tool: translate
The description contains zero-width characters and mixed-script (homoglyph)
text, which can hide instructions from human review while still reaching the
model.
fix: Strip zero-width and bidirectional control characters; use a single script per
word.
Report: .mcpsight/report.json | SARIF: .mcpsight/report.sarif
The cross-tool finding on notes is gone, and everything else stays.
Mistakes fail loudly
A missing file or broken YAML stops the run before any server is touched, so a typo never passes silently:
mcpsight: loading rules from bad.yaml: parsing injection rules: yaml: line 1: did not find expected ',' or ']' exit 2
Found a false positive?
Please open an issue with the description that tripped it. The rules are public so people can dispute them.