Use it in CI

Exit codes

The exit code is the whole interface for CI. Treat 1 and 2 differently.

CodeMeaning
0Nothing at or above --fail-on, and no drift.
1A finding met the threshold, or verify found drift. The scan worked and found a problem.
2The scan could not run: unreachable server, no sandbox, no baseline, bad flag, or bad input.

Exit 1 means you have a problem. Exit 2 means the tool did not run. Never treat them the same in CI. A scanner that quietly reports clean when it could not scan is worse than none.

Moving the threshold

The default --fail-on is high. The practice server's /clean URL has two high findings and nothing critical:

mcpsight scan --fail-on critical http://127.0.0.1:8931/clean; echo "exit $?"
mcpsight scan --fail-on info http://127.0.0.1:8931/clean; echo "exit $?"
exit 0
exit 1

Every finding is printed either way. The threshold only decides the exit code.

Several servers

MCPsight scans every target even if one fails. If any failed, the run exits 2 at the end.