Get started
Reading a report
Every report has the same shape: a summary of the server, then its findings, worst first.
benign-docs
Server benign-docs (1.2.0, via remote)
Grade C (60/100) rubric v1
Context cost ~229 tokens (2 tools) ~$0.001 per request @ Claude Sonnet (est.)
Capabilities none declared
Drift baseline recorded (first scan)
Findings
HIGH Server lists its tools without authentication [authposture.unauthenticated_listing]
tools/list returned successfully with no credentials. Anyone who can reach
this endpoint can list its tools, and probably call them.
fix: Require authentication (OAuth 2.1 or at least a bearer token) before serving
tool listings.
HIGH Server is served over plaintext HTTP [authposture.plaintext_http]
The endpoint uses http://, so tool traffic and any credentials travel
unencrypted.
fix: Serve the MCP endpoint over HTTPS.
Report: .mcpsight/report.json | SARIF: .mcpsight/report.sarif
The summary
| Line | What it tells you |
|---|---|
| Server | The name and version the server reports, and how MCPsight reached it: remote, bubblewrap, or docker. |
| Grade | A letter and a score out of 100. Each finding subtracts points by severity. How scoring works lets you redo the sum by hand. |
| Context cost | Tokens the tool definitions add to every request your agent makes, with a cost per request. It is an estimate, and the line says so. |
| Capabilities | What the tools say they can do: read or write files, run shell commands, reach the network, read secrets, run code. MCPsight infers this from names, descriptions, and inputs. |
| Drift | Whether the server changed since its baseline. The first scan records one. |
A finding
Each finding has four parts:
- Severity, from critical down to info. It decides the penalty.
- A title and a rule ID in brackets, such as
authposture.plaintext_http. Rule IDs never change meaning, so you can track them. Every rule lists them all. - The tool it applies to, when it is about one tool.
- An explanation and a fix.
| Severity | Penalty | What it usually means |
|---|---|---|
| critical | 40, and the grade is capped at F | Stop. Credential theft, or a description that overrides the model. |
| high | 20 | A real risk you should fix or understand before you trust the server. |
| medium | 8 | Worth fixing. Hidden payloads, new tools, missing source. |
| low | 3 | Housekeeping. Large descriptions, young packages. |
| info | 0 | Recorded so you can see it. Declared capabilities, skipped checks. |
Notes on the grade line
Two notes can appear after the score. Capped by a critical finding means one critical finding held the grade at F, whatever the rest says. Behavior not observed means MCPsight ran a local server but could not watch it, so the grade covers what the server declared, not what it did. Install strace to fix that.
Token estimates
Token counts come from MCPsight's own estimator and carry (est.). Use them to compare servers and spot bloat. Do not bill anyone from them.