Use it in CI
Exit codes
The exit code is the whole interface for CI. Treat 1 and 2 differently.
| Code | Meaning |
|---|---|
0 | Nothing at or above --fail-on, and no drift. |
1 | A finding met the threshold, or verify found drift. The scan worked and found a problem. |
2 | The scan could not run: unreachable server, no sandbox, no baseline, bad flag, or bad input. |
Exit 1 means you have a problem. Exit 2 means the tool did not run. Never treat them the same in CI. A scanner that quietly reports clean when it could not scan is worse than none.
Moving the threshold
The default --fail-on is high. The practice server's /clean URL has two high findings and nothing critical:
mcpsight scan --fail-on critical http://127.0.0.1:8931/clean; echo "exit $?" mcpsight scan --fail-on info http://127.0.0.1:8931/clean; echo "exit $?"
exit 0 exit 1
Every finding is printed either way. The threshold only decides the exit code.
Several servers
MCPsight scans every target even if one fails. If any failed, the run exits 2 at the end.