Security

Report a vulnerability

MCPsight runs code from servers you do not control, so a bug in it can put your machine at risk. Please tell us privately.

How to report

Use either private channel. Please do not open a public issue.

  • GitHub: open the Security tab and choose Report a vulnerability. Only the maintainers can see it.
  • Email: write to contact@greyquill.io and start the subject with "MCPsight security".

Include what you can: the version (mcpsight version), your OS, what you did, and what happened. A minimal MCP server that triggers the problem is ideal.

What happens next

  • We confirm we received it within 3 working days.
  • We tell you whether we accept it, and our plan, within 10 working days.
  • We fix it in a release, publish an advisory, and credit you unless you ask us not to.

Please give us 90 days, or until a fix ships, before you disclose.

In scope

  • Escaping the sandbox, or reaching real files, credentials, or environment variables from inside it.
  • Running a server's code without a sandbox, unless you passed --no-sandbox.
  • Making MCPsight hang, crash, or exhaust memory.
  • Injecting terminal control sequences or Markdown into reports.
  • Secrets from your config appearing in reports.
  • Tampering with a release or its signature.

A wrong grade is an ordinary bug. Open an issue for that. The full policy is SECURITY.md.