Get started
Your first scan
Point MCPsight at the servers you already use, or at one URL. A scan takes a few seconds.
Scan your MCP config
MCPsight reads the same config file your client uses and scans every server in it:
mcpsight scan --from claude_desktop_config.json
It understands Claude Desktop, Claude Code, Cursor, and VS Code configs. Scan your own setup lists where each one keeps its file.
Scan one server
mcpsight scan https://mcp.example.com/mcp
On Linux you can also scan a package directly, such as npx:@modelcontextprotocol/server-everything. It runs in the sandbox.
What you see
This is a scan of a practice server that ships with MCPsight. Its tools are harmless, but it is served badly:
mcpsight scan http://127.0.0.1:8931/clean
benign-docs
Server benign-docs (1.2.0, via remote)
Grade C (60/100) rubric v1
Context cost ~229 tokens (2 tools) ~$0.001 per request @ Claude Sonnet (est.)
Capabilities none declared
Drift baseline recorded (first scan)
Findings
HIGH Server lists its tools without authentication [authposture.unauthenticated_listing]
tools/list returned successfully with no credentials. Anyone who can reach
this endpoint can list its tools, and probably call them.
fix: Require authentication (OAuth 2.1 or at least a bearer token) before serving
tool listings.
HIGH Server is served over plaintext HTTP [authposture.plaintext_http]
The endpoint uses http://, so tool traffic and any credentials travel
unencrypted.
fix: Serve the MCP endpoint over HTTPS.
Report: .mcpsight/report.json | SARIF: .mcpsight/report.sarif
The grade is C because anyone can list its tools, and it uses plain HTTP. The same server on HTTPS with authentication would grade A. Reading a report walks through every line.
What it wrote
Each scan writes a .mcpsight/ folder in the current directory:
| File | What it holds | Commit it? |
|---|---|---|
baseline.json | A fingerprint of each server, recorded on its first scan | Yes |
report.json | The full report from the last scan | No |
report.sarif | The same findings for GitHub code scanning | No |
Committing the baseline is what lets MCPsight tell you later that a server changed. --dir puts the folder somewhere else.