Walkthrough

Try it with the practice servers

The repo ships a practice server that pretends to be several MCP servers at once. It only returns tool descriptions and never runs anything, so it is safe on any machine.

What you need

  • MCPsight installed.
  • Go 1.26 or later, to run the practice server.
  • Two terminals: one runs the practice server, one runs scans.

The walkthrough takes about half an hour, and everything stays on your machine. Only The Linux sandbox needs Linux.

Start the practice server

In the first terminal:

git clone https://github.com/greyquill/mcpsight && cd mcpsight
make fixture     # serves on 127.0.0.1:8931

Leave it running. Each URL is a different server:

URLPretends to be
/cleanA well-behaved documentation server
/poisonedA server whose tool descriptions carry prompt injection
/rugpullA server that starts clean, then turns malicious when you flip a switch
/auth/cleanThe clean server, behind a bearer token

Set up the second terminal

Work from a scratch folder, so the scan files stay out of the repo:

mkdir -p /tmp/mcpsight-demo && cd /tmp/mcpsight-demo

Then start with Spot a poisoned server.

When you are done

Stop the practice server with Ctrl+C and delete /tmp/mcpsight-demo.