Walkthrough
Try it with the practice servers
The repo ships a practice server that pretends to be several MCP servers at once. It only returns tool descriptions and never runs anything, so it is safe on any machine.
What you need
- MCPsight installed.
- Go 1.26 or later, to run the practice server.
- Two terminals: one runs the practice server, one runs scans.
The walkthrough takes about half an hour, and everything stays on your machine. Only The Linux sandbox needs Linux.
Start the practice server
In the first terminal:
git clone https://github.com/greyquill/mcpsight && cd mcpsight make fixture # serves on 127.0.0.1:8931
Leave it running. Each URL is a different server:
| URL | Pretends to be |
|---|---|
/clean | A well-behaved documentation server |
/poisoned | A server whose tool descriptions carry prompt injection |
/rugpull | A server that starts clean, then turns malicious when you flip a switch |
/auth/clean | The clean server, behind a bearer token |
Set up the second terminal
Work from a scratch folder, so the scan files stay out of the repo:
mkdir -p /tmp/mcpsight-demo && cd /tmp/mcpsight-demo
Then start with Spot a poisoned server.
When you are done
Stop the practice server with Ctrl+C and delete /tmp/mcpsight-demo.