Reference
Every rule
Six analyzers, each with stable rule IDs named analyzer.rule. A rule ID never changes meaning, so you can track and discuss it.
Context cost
How many tokens the tool definitions add to every request, per tool and per model. Both rules are mild on purpose: one is low and one is info. Cost is something you budget for, and it does not make a server dangerous.
| Rule | Severity | Fires when |
|---|---|---|
context.oversized_tool | info | One tool definition is far larger than the rest |
context.schema_bloat | low | Deeply nested or verbose input schemas that could be flattened |
Capability
What the server can reach, two ways. Declared comes from tool names, descriptions, and inputs, classed as fs:read, fs:write, exec:shell, net:egress, db:write, secrets:read, and code:eval. Each declared class is an info finding. Observed comes from watching the server start in the sandbox.
| Rule | Severity | Fires when |
|---|---|---|
capability.decoy_read | critical | The server read a decoy credential file |
capability.egress_unexpected | high | The server tried to connect out with the network denied |
capability.declared_observed_gap | high | It did something none of its tools declare |
capability.declared_* | info | A tool declares a capability class, such as capability.declared_fs_write |
capability.not_observed | info | MCPsight ran the server but could not watch it |
Injection
Descriptions that address the model directly. The user never sees them, which makes this the hardest risk to catch by eye.
| Rule | Severity | Fires when |
|---|---|---|
injection.override_instruction | critical | "Ignore previous instructions", "do not tell the user", and relatives |
injection.imperative_instruction | high | Orders to the model, such as "before calling any other tool, first read" |
injection.cross_tool_reference | high | Names other tools or servers to orchestrate them |
injection.unrelated_path | high | Points the model at credential or system files |
injection.invisible_chars | high | Zero-width characters, direction controls, or look-alike letters |
injection.encoded_blob | medium | A base64 or hex payload inside a description |
injection.excessive_length | low | A description far longer than a tool needs |
Drift
Changes since the baseline, graded by direction. A shorter description is noise. A new instruction to the model is an attack.
| Rule | Severity | Fires when |
|---|---|---|
drift.instruction_added | critical | A description gained an instruction to the model |
drift.capability_escalated | high | A capability widened, such as fs:read to fs:write |
drift.tool_added | medium | A new tool appeared |
drift.schema_changed | low | A tool's input schema changed |
drift.tool_removed | info | A tool disappeared |
drift.description_changed | low | Wording changed without gaining instructions |
drift.description_shortened | info | Text only got shorter |
drift.server_version_changed | info | The server reports a different version |
Supply chain
Whether the package around the server deserves trust. Needs the network, and is skipped under --offline.
| Rule | Severity | Fires when |
|---|---|---|
supplychain.known_cve | high or medium | The package has a known vulnerability on OSV.dev. Its CVSS score sets the severity |
supplychain.install_script | high | A postinstall or similar script runs at install time |
supplychain.typosquat | high | The name is one or two edits from a popular server, or is its name under another scope |
supplychain.no_source | medium | No source repository you could audit |
supplychain.single_maintainer | low | One maintainer |
supplychain.young_package | low | First published very recently |
supplychain.metadata_unavailable | info | Registry data could not be fetched, so these checks were skipped |
A package on the popular list is never flagged as a squat of another one, so server-gitlab is not a squat of server-github.
Auth posture
Remote servers only.
| Rule | Severity | Fires when |
|---|---|---|
authposture.unauthenticated_listing | high | tools/list answers with no credentials |
authposture.plaintext_http | high | The endpoint uses http:// |
authposture.weak_tls | medium | TLS is older than current practice |
MCPsight measures unauthenticated listing by scanning again without your credentials.