Walkthrough
The Linux sandbox
This is where MCPsight watches what a server does, not only what it says. It runs local servers inside bubblewrap, with a fake home folder full of decoy credentials, and records every file they open and every connection they try.
What the sandbox does
- No network for local commands. Connection attempts are recorded.
--allow-netopens it for servers that need it to start. - No access to your files. The server sees a throwaway filesystem, plus its own code, read-only.
- A decoy home.
~/.ssh/id_rsa,~/.aws/credentials, and.envare fakes. Reading any of them is a critical finding. - Limits on memory, CPU time, open files, file size, processes, and time. A runaway server is killed and your machine stays healthy.
- A clean environment. Your environment variables never reach the server.
Try it
You need Linux with bubblewrap, strace, and Node. From the repo, scan three practice servers. A local command goes through a config file:
make build
for f in benign-docs credential-thief egress-on-init; do
printf '{"mcpServers":{"%s":{"command":"node","args":["%s"]}}}' \
"$f" "$PWD/testdata/servers/$f/server.js" > /tmp/$f.json
./bin/mcpsight scan --offline --from /tmp/$f.json
done
A server that steals credentials
credential-thief
Server credential-thief (2.0.1, via bubblewrap)
Grade F (39/100, capped by a critical finding) rubric v1
Context cost ~75 tokens (1 tool) under $0.001 per request @ Claude Sonnet (est.)
Capabilities none declared
Drift baseline recorded (first scan)
Findings
CRITICAL Server read decoy credential files on startup [capability.decoy_read]
During the probe the server read the decoy credential file(s): .ssh/id_rsa,
.aws/credentials, .env. A server that reads credential files on startup is
exfiltrating, not initializing.
fix: Do not install this server. Report it to the registry it came from.
Report: .mcpsight/report.json | SARIF: .mcpsight/report.sarif
It read the decoys the moment it started. Your real keys were never inside the sandbox.
A server that phones home
egress-on-init
Server egress-on-init (1.0.0, via bubblewrap)
Grade C (60/100) rubric v1
Context cost ~108 tokens (1 tool) under $0.001 per request @ Claude Sonnet (est.)
Capabilities none declared
Drift baseline recorded (first scan)
Findings
HIGH Server attempted network egress on startup [capability.egress_unexpected]
The server tried to reach 203.0.113.7:443 during startup, with the network
denied. It should not need the network to list its tools.
fix: Investigate why the server connects out on startup before trusting it.
HIGH Observed network egress exceeds declared capability [capability.declared_observed_gap]
The server contacted the network but none of its tools declare a net:egress
capability. Observed behavior exceeding the declared surface is a red flag.
fix: Treat the undeclared capability as the true capability of the server.
Report: .mcpsight/report.json | SARIF: .mcpsight/report.sarif
None of its tools say they need the network, yet it connected out on startup. That gap is the signal.
An honest server
benign-docs Server benign-docs (1.2.0, via bubblewrap) Grade A (100/100) rubric v1 Context cost ~229 tokens (2 tools) ~$0.001 per request @ Claude Sonnet (est.) Capabilities none declared Drift baseline recorded (first scan) No findings. Report: .mcpsight/report.json | SARIF: .mcpsight/report.sarif
A real package
Package servers download inside the sandbox, so they need the network:
mcpsight scan npx:@modelcontextprotocol/server-everything
mcp-servers/everything
Server mcp-servers/everything (2.0.0, via bubblewrap)
Grade A (100/100) rubric v1
Context cost ~2,186 tokens (13 tools) ~$0.007 per request @ Claude Sonnet (est.)
Capabilities fs:write net:egress
Drift baseline recorded (first scan)
Findings
INFO Declares fs:write capability [capability.declared_fs_write]
tool: gzip-file-as-resource
Tool "gzip-file-as-resource" appears to declare the fs:write capability from
its name, description, or schema.
Report: .mcpsight/report.json | SARIF: .mcpsight/report.sarif
Limits you should know
npx:anduvx:servers run with the network on, because the package manager has to fetch them. So connection findings only fire for local commands, where the network was off and nothing else could have connected.- Watching uses strace. Code written to dodge strace can hide what it does. A stronger watcher is designed but not built yet.
- Without strace, the sandbox still contains the server, but the report shows
capability.not_observedand marks the grade behavior not observed.
More in What MCPsight protects you from.