Get started

Install

MCPsight is a single binary with no runtime dependencies. Pick the install that suits you, then check it runs.

macOS with Homebrew

brew install --cask greyquill/tap/mcpsight

Download a release

Every release has builds for macOS, Linux, and Windows on amd64 and arm64. Unpack the archive and put mcpsight on your PATH. Before you run it, verify the download. It takes a minute.

With Go

You need Go 1.26 or later.

go install github.com/greyquill/mcpsight/cmd/mcpsight@latest

From source

git clone https://github.com/greyquill/mcpsight && cd mcpsight
make build     # writes bin/mcpsight

Check it runs

mcpsight version
mcpsight v0.1.0 (commit 1a2b3c4, rubric v1)

The rubric version tells you which scoring rules this build uses. It matters when you compare grades over time.

What each platform can scan

Scanning a local server means running its code, so that part needs the Linux sandbox.

TargetmacOSWindowsLinux
Remote server, https://YesYesYes
Local server, npx:, uvx:, or a commandRefusedRefusedYes, with bubblewrap
Container, docker:With DockerWith DockerWith Docker

Set up the Linux sandbox

Install bubblewrap to run local servers safely, and strace so MCPsight can watch what they do:

sudo apt-get install -y bubblewrap strace

Without bubblewrap, MCPsight refuses local servers instead of running them unprotected. Without strace, it runs them but cannot watch them, and the report says so.

Ubuntu 24.04 blocks bubblewrap by default.

See Troubleshooting for a fix that exempts bubblewrap only.