Security
Report a vulnerability
MCPsight runs code from servers you do not control, so a bug in it can put your machine at risk. Please tell us privately.
How to report
Use either private channel. Please do not open a public issue.
- GitHub: open the Security tab and choose Report a vulnerability. Only the maintainers can see it.
- Email: write to contact@greyquill.io and start the subject with "MCPsight security".
Include what you can: the version (mcpsight version), your OS, what you did, and what happened. A minimal MCP server that triggers the problem is ideal.
What happens next
- We confirm we received it within 3 working days.
- We tell you whether we accept it, and our plan, within 10 working days.
- We fix it in a release, publish an advisory, and credit you unless you ask us not to.
Please give us 90 days, or until a fix ships, before you disclose.
In scope
- Escaping the sandbox, or reaching real files, credentials, or environment variables from inside it.
- Running a server's code without a sandbox, unless you passed
--no-sandbox. - Making MCPsight hang, crash, or exhaust memory.
- Injecting terminal control sequences or Markdown into reports.
- Secrets from your config appearing in reports.
- Tampering with a release or its signature.
A wrong grade is an ordinary bug. Open an issue for that. The full policy is SECURITY.md.