Use it in CI

Output formats

The terminal summary is for people. JSON, SARIF, and Markdown are for scripts, code scanning, and pull-request comments.

JSON, for scripts

The full report, including the manifest, every finding, and per-tool token counts. One object for one server, an array for several.

mcpsight scan --json http://127.0.0.1:8931/poisoned | jq '.score | {score, grade}'
{
  "score": 0,
  "grade": "F"
}

SARIF, for GitHub code scanning

SARIF 2.1.0. Upload it and the findings appear on the pull request.

mcpsight scan --sarif http://127.0.0.1:8931/poisoned | jq '.runs[0].results | length'
10

Markdown, for pull-request comments

mcpsight scan --markdown http://127.0.0.1:8931/poisoned
### mcpsight: `poisoned-descriptions`, grade F (0/100)

**Context cost:** ~462 tokens (5 tools) · ~$0.001/req @ Claude Sonnet _(est.)_

**Capabilities:** code:eval, fs:read, fs:write

**Drift:** unchanged since baseline

| Severity | Finding | Tool |
|---|---|---|
| **critical** | Tool description tries to override the model's instructions <sub>`injection.override_instruction`</sub> | `summarize` |
| **high** | Tool description issues an imperative instruction to the model <sub>`injection.imperative_instruction`</sub> | `weather` |
| **high** | Tool description instructs reading sensitive or unrelated paths <sub>`injection.unrelated_path`</sub> | `weather` |
| **high** | Tool description references another tool or server <sub>`injection.cross_tool_reference`</sub> | `notes` |
| **high** | Description contains hidden or deceptive characters <sub>`injection.invisible_chars`</sub> | `translate` |
| **high** | Server lists its tools without authentication <sub>`authposture.unauthenticated_listing`</sub> |  |
| **high** | Server is served over plaintext HTTP <sub>`authposture.plaintext_http`</sub> |  |
| medium | Description embeds an encoded payload <sub>`injection.encoded_blob`</sub> | `format` |
| info | Declares fs:write capability <sub>`capability.declared_fs_write`</sub> | `notes` |
| info | Declares code:eval capability <sub>`capability.declared_code_eval`</sub> | `format` |

<sub>Generated by [mcpsight](https://github.com/greyquill/mcpsight) · rubric v1</sub>

Text from the server is escaped, so a server cannot add links, HTML, or table cells to your comment.

Files written every time

Whatever you print, each scan writes .mcpsight/report.json and .mcpsight/report.sarif, so a CI job can upload SARIF without extra flags. Ignore the reports and commit the baseline:

.mcpsight/report.json
.mcpsight/report.sarif

Colour

Colour appears only in a terminal. Piping to a file, --no-color, or NO_COLOR=1 turns it off.