Security

What MCPsight protects you from

MCPsight looks for the ways an MCP server can hurt you. It is honest about where it stops.

Threats and checks

What an attacker wantsHowWhat catches it
Your credentialsReads ~/.ssh/id_rsa and similar on startupDecoy files in the sandbox, a critical finding
Your dataConnects out on startupRecorded connection attempts, and the gap between declared and observed
Control of your agentOrders hidden in a tool descriptionInjection rules
Your other toolsA description that drives tools on another serverCross-tool rule
To slip past reviewInvisible characters, look-alike letters, base64Invisible-character and encoded-payload checks
Your trust, laterA clean server that changes after you adopt itDrift against your committed baseline
To be installed by mistakeA name close to a popular packageTyposquat check
Code you cannot auditNo source, install scripts, known CVEsSupply-chain checks
An open doorA remote server that lists tools to anyone, or plain HTTPAuth-posture checks

MCPsight itself is hardened

  • Local servers only run in the sandbox. If there is no sandbox, the scan is refused.
  • Your environment variables and home folder never reach the server.
  • Header and environment values are redacted from reports.
  • Messages from a server are capped at 16 MiB, and its text is escaped before it reaches your terminal or a Markdown comment.

What it does not claim

  • It is not a malware scanner. It finds risk and change. It cannot prove a server is safe.
  • Code written to dodge strace can hide what it does.
  • npx: and uvx: servers start with the network on, so connection findings do not fire for them.
  • Injection rules are patterns. A new trick can get past them until a rule is added.
  • Token counts are estimates.

The full statement is the threat model.