Reference

Custom injection rules

The injection rules are a YAML file anyone can read and argue with. Copy it, change it, and scan with your version.

The rule file

Each rule has an ID, a severity, a title, a fix, and a list of patterns. A rule fires if any pattern matches the tool's name or description. Patterns are case-insensitive regular expressions.

version: 1
rules:
  - id: injection.override_instruction
    severity: critical
    title: "Tool description tries to override the model's instructions"
    remediation: "Remove instruction-like text from the description; ..."
    any:
      - '(?i)ignore\s+(all\s+)?(previous|prior|above)\s+instructions'
      - '(?i)do\s+not\s+(tell|inform|mention\s+to|reveal\s+to|notify)\s+the\s+user'

Some checks cannot be written as patterns: invisible characters, encoded payloads, and length. Those are built in and always run.

Use your own

Copy the built-in file, edit it, and pass it with --rules. For example, remove the injection.cross_tool_reference block and scan the poisoned practice server:

mcpsight scan --rules my-rules.yaml http://127.0.0.1:8931/poisoned
  poisoned-descriptions
  Server        poisoned-descriptions  (0.1.0, via remote)
  Grade         F  (0/100)  rubric v1

  Context cost  ~462 tokens  (5 tools)   ~$0.001 per request @ Claude Sonnet  (est.)
  Capabilities  code:eval  fs:read  fs:write
  Drift         unchanged since baseline

  Findings
  CRITICAL  Tool description tries to override the model's instructions [injection.override_instruction]
      tool: summarize
      fix: Remove instruction-like text from the description; a tool description should
      describe the tool, not command the model.
  HIGH      Tool description issues an imperative instruction to the model [injection.imperative_instruction]
      tool: weather
      fix: Descriptions should not tell the model what to do before/after other tools.
      State only what this tool does.
  HIGH      Tool description instructs reading sensitive or unrelated paths [injection.unrelated_path]
      tool: weather
      fix: Remove references to credential or system files; a tool's description should
      not point the model at ~/.ssh, ~/.aws, .env, or similar.
  HIGH      Description contains hidden or deceptive characters [injection.invisible_chars]
      tool: translate
      The description contains zero-width characters and mixed-script (homoglyph)
      text, which can hide instructions from human review while still reaching the
      model.
      fix: Strip zero-width and bidirectional control characters; use a single script per
      word.

  Report: .mcpsight/report.json  |  SARIF: .mcpsight/report.sarif

The cross-tool finding on notes is gone, and everything else stays.

Mistakes fail loudly

A missing file or broken YAML stops the run before any server is touched, so a typo never passes silently:

mcpsight: loading rules from bad.yaml: parsing injection rules: yaml: line 1: did not find expected ',' or ']'
exit 2

Found a false positive?

Please open an issue with the description that tripped it. The rules are public so people can dispute them.