Reference

Every rule

Six analyzers, each with stable rule IDs named analyzer.rule. A rule ID never changes meaning, so you can track and discuss it.

Context cost

How many tokens the tool definitions add to every request, per tool and per model. Both rules are mild on purpose: one is low and one is info. Cost is something you budget for, and it does not make a server dangerous.

RuleSeverityFires when
context.oversized_toolinfoOne tool definition is far larger than the rest
context.schema_bloatlowDeeply nested or verbose input schemas that could be flattened

Capability

What the server can reach, two ways. Declared comes from tool names, descriptions, and inputs, classed as fs:read, fs:write, exec:shell, net:egress, db:write, secrets:read, and code:eval. Each declared class is an info finding. Observed comes from watching the server start in the sandbox.

RuleSeverityFires when
capability.decoy_readcriticalThe server read a decoy credential file
capability.egress_unexpectedhighThe server tried to connect out with the network denied
capability.declared_observed_gaphighIt did something none of its tools declare
capability.declared_*infoA tool declares a capability class, such as capability.declared_fs_write
capability.not_observedinfoMCPsight ran the server but could not watch it

Injection

Descriptions that address the model directly. The user never sees them, which makes this the hardest risk to catch by eye.

RuleSeverityFires when
injection.override_instructioncritical"Ignore previous instructions", "do not tell the user", and relatives
injection.imperative_instructionhighOrders to the model, such as "before calling any other tool, first read"
injection.cross_tool_referencehighNames other tools or servers to orchestrate them
injection.unrelated_pathhighPoints the model at credential or system files
injection.invisible_charshighZero-width characters, direction controls, or look-alike letters
injection.encoded_blobmediumA base64 or hex payload inside a description
injection.excessive_lengthlowA description far longer than a tool needs

Drift

Changes since the baseline, graded by direction. A shorter description is noise. A new instruction to the model is an attack.

RuleSeverityFires when
drift.instruction_addedcriticalA description gained an instruction to the model
drift.capability_escalatedhighA capability widened, such as fs:read to fs:write
drift.tool_addedmediumA new tool appeared
drift.schema_changedlowA tool's input schema changed
drift.tool_removedinfoA tool disappeared
drift.description_changedlowWording changed without gaining instructions
drift.description_shortenedinfoText only got shorter
drift.server_version_changedinfoThe server reports a different version

Supply chain

Whether the package around the server deserves trust. Needs the network, and is skipped under --offline.

RuleSeverityFires when
supplychain.known_cvehigh or mediumThe package has a known vulnerability on OSV.dev. Its CVSS score sets the severity
supplychain.install_scripthighA postinstall or similar script runs at install time
supplychain.typosquathighThe name is one or two edits from a popular server, or is its name under another scope
supplychain.no_sourcemediumNo source repository you could audit
supplychain.single_maintainerlowOne maintainer
supplychain.young_packagelowFirst published very recently
supplychain.metadata_unavailableinfoRegistry data could not be fetched, so these checks were skipped

A package on the popular list is never flagged as a squat of another one, so server-gitlab is not a squat of server-github.

Auth posture

Remote servers only.

RuleSeverityFires when
authposture.unauthenticated_listinghightools/list answers with no credentials
authposture.plaintext_httphighThe endpoint uses http://
authposture.weak_tlsmediumTLS is older than current practice

MCPsight measures unauthenticated listing by scanning again without your credentials.