Get started

Your first scan

Point MCPsight at the servers you already use, or at one URL. A scan takes a few seconds.

Scan your MCP config

MCPsight reads the same config file your client uses and scans every server in it:

mcpsight scan --from claude_desktop_config.json

It understands Claude Desktop, Claude Code, Cursor, and VS Code configs. Scan your own setup lists where each one keeps its file.

Scan one server

mcpsight scan https://mcp.example.com/mcp

On Linux you can also scan a package directly, such as npx:@modelcontextprotocol/server-everything. It runs in the sandbox.

What you see

This is a scan of a practice server that ships with MCPsight. Its tools are harmless, but it is served badly:

mcpsight scan http://127.0.0.1:8931/clean
  benign-docs
  Server        benign-docs  (1.2.0, via remote)
  Grade         C  (60/100)  rubric v1

  Context cost  ~229 tokens  (2 tools)   ~$0.001 per request @ Claude Sonnet  (est.)
  Capabilities  none declared
  Drift         baseline recorded (first scan)

  Findings
  HIGH      Server lists its tools without authentication [authposture.unauthenticated_listing]
      tools/list returned successfully with no credentials. Anyone who can reach
      this endpoint can list its tools, and probably call them.
      fix: Require authentication (OAuth 2.1 or at least a bearer token) before serving
      tool listings.
  HIGH      Server is served over plaintext HTTP [authposture.plaintext_http]
      The endpoint uses http://, so tool traffic and any credentials travel
      unencrypted.
      fix: Serve the MCP endpoint over HTTPS.

  Report: .mcpsight/report.json  |  SARIF: .mcpsight/report.sarif

The grade is C because anyone can list its tools, and it uses plain HTTP. The same server on HTTPS with authentication would grade A. Reading a report walks through every line.

What it wrote

Each scan writes a .mcpsight/ folder in the current directory:

FileWhat it holdsCommit it?
baseline.jsonA fingerprint of each server, recorded on its first scanYes
report.jsonThe full report from the last scanNo
report.sarifThe same findings for GitHub code scanningNo

Committing the baseline is what lets MCPsight tell you later that a server changed. --dir puts the folder somewhere else.