Get started

Reading a report

Every report has the same shape: a summary of the server, then its findings, worst first.

  benign-docs
  Server        benign-docs  (1.2.0, via remote)
  Grade         C  (60/100)  rubric v1

  Context cost  ~229 tokens  (2 tools)   ~$0.001 per request @ Claude Sonnet  (est.)
  Capabilities  none declared
  Drift         baseline recorded (first scan)

  Findings
  HIGH      Server lists its tools without authentication [authposture.unauthenticated_listing]
      tools/list returned successfully with no credentials. Anyone who can reach
      this endpoint can list its tools, and probably call them.
      fix: Require authentication (OAuth 2.1 or at least a bearer token) before serving
      tool listings.
  HIGH      Server is served over plaintext HTTP [authposture.plaintext_http]
      The endpoint uses http://, so tool traffic and any credentials travel
      unencrypted.
      fix: Serve the MCP endpoint over HTTPS.

  Report: .mcpsight/report.json  |  SARIF: .mcpsight/report.sarif

The summary

LineWhat it tells you
ServerThe name and version the server reports, and how MCPsight reached it: remote, bubblewrap, or docker.
GradeA letter and a score out of 100. Each finding subtracts points by severity. How scoring works lets you redo the sum by hand.
Context costTokens the tool definitions add to every request your agent makes, with a cost per request. It is an estimate, and the line says so.
CapabilitiesWhat the tools say they can do: read or write files, run shell commands, reach the network, read secrets, run code. MCPsight infers this from names, descriptions, and inputs.
DriftWhether the server changed since its baseline. The first scan records one.

A finding

Each finding has four parts:

  • Severity, from critical down to info. It decides the penalty.
  • A title and a rule ID in brackets, such as authposture.plaintext_http. Rule IDs never change meaning, so you can track them. Every rule lists them all.
  • The tool it applies to, when it is about one tool.
  • An explanation and a fix.
SeverityPenaltyWhat it usually means
critical40, and the grade is capped at FStop. Credential theft, or a description that overrides the model.
high20A real risk you should fix or understand before you trust the server.
medium8Worth fixing. Hidden payloads, new tools, missing source.
low3Housekeeping. Large descriptions, young packages.
info0Recorded so you can see it. Declared capabilities, skipped checks.

Notes on the grade line

Two notes can appear after the score. Capped by a critical finding means one critical finding held the grade at F, whatever the rest says. Behavior not observed means MCPsight ran a local server but could not watch it, so the grade covers what the server declared, not what it did. Install strace to fix that.

Token estimates

Token counts come from MCPsight's own estimator and carry (est.). Use them to compare servers and spot bloat. Do not bill anyone from them.