Walkthrough

The Linux sandbox

This is where MCPsight watches what a server does, not only what it says. It runs local servers inside bubblewrap, with a fake home folder full of decoy credentials, and records every file they open and every connection they try.

What the sandbox does

  • No network for local commands. Connection attempts are recorded. --allow-net opens it for servers that need it to start.
  • No access to your files. The server sees a throwaway filesystem, plus its own code, read-only.
  • A decoy home. ~/.ssh/id_rsa, ~/.aws/credentials, and .env are fakes. Reading any of them is a critical finding.
  • Limits on memory, CPU time, open files, file size, processes, and time. A runaway server is killed and your machine stays healthy.
  • A clean environment. Your environment variables never reach the server.

Try it

You need Linux with bubblewrap, strace, and Node. From the repo, scan three practice servers. A local command goes through a config file:

make build
for f in benign-docs credential-thief egress-on-init; do
  printf '{"mcpServers":{"%s":{"command":"node","args":["%s"]}}}' \
    "$f" "$PWD/testdata/servers/$f/server.js" > /tmp/$f.json
  ./bin/mcpsight scan --offline --from /tmp/$f.json
done

A server that steals credentials

  credential-thief
  Server        credential-thief  (2.0.1, via bubblewrap)
  Grade         F  (39/100, capped by a critical finding)  rubric v1

  Context cost  ~75 tokens  (1 tool)   under $0.001 per request @ Claude Sonnet  (est.)
  Capabilities  none declared
  Drift         baseline recorded (first scan)

  Findings
  CRITICAL  Server read decoy credential files on startup [capability.decoy_read]
      During the probe the server read the decoy credential file(s): .ssh/id_rsa,
      .aws/credentials, .env. A server that reads credential files on startup is
      exfiltrating, not initializing.
      fix: Do not install this server. Report it to the registry it came from.

  Report: .mcpsight/report.json  |  SARIF: .mcpsight/report.sarif

It read the decoys the moment it started. Your real keys were never inside the sandbox.

A server that phones home

  egress-on-init
  Server        egress-on-init  (1.0.0, via bubblewrap)
  Grade         C  (60/100)  rubric v1

  Context cost  ~108 tokens  (1 tool)   under $0.001 per request @ Claude Sonnet  (est.)
  Capabilities  none declared
  Drift         baseline recorded (first scan)

  Findings
  HIGH      Server attempted network egress on startup [capability.egress_unexpected]
      The server tried to reach 203.0.113.7:443 during startup, with the network
      denied. It should not need the network to list its tools.
      fix: Investigate why the server connects out on startup before trusting it.
  HIGH      Observed network egress exceeds declared capability [capability.declared_observed_gap]
      The server contacted the network but none of its tools declare a net:egress
      capability. Observed behavior exceeding the declared surface is a red flag.
      fix: Treat the undeclared capability as the true capability of the server.

  Report: .mcpsight/report.json  |  SARIF: .mcpsight/report.sarif

None of its tools say they need the network, yet it connected out on startup. That gap is the signal.

An honest server

  benign-docs
  Server        benign-docs  (1.2.0, via bubblewrap)
  Grade         A  (100/100)  rubric v1

  Context cost  ~229 tokens  (2 tools)   ~$0.001 per request @ Claude Sonnet  (est.)
  Capabilities  none declared
  Drift         baseline recorded (first scan)

  No findings.

  Report: .mcpsight/report.json  |  SARIF: .mcpsight/report.sarif

A real package

Package servers download inside the sandbox, so they need the network:

mcpsight scan npx:@modelcontextprotocol/server-everything
  mcp-servers/everything
  Server        mcp-servers/everything  (2.0.0, via bubblewrap)
  Grade         A  (100/100)  rubric v1

  Context cost  ~2,186 tokens  (13 tools)   ~$0.007 per request @ Claude Sonnet  (est.)
  Capabilities  fs:write  net:egress
  Drift         baseline recorded (first scan)

  Findings
  INFO      Declares fs:write capability [capability.declared_fs_write]
      tool: gzip-file-as-resource
      Tool "gzip-file-as-resource" appears to declare the fs:write capability from
      its name, description, or schema.

  Report: .mcpsight/report.json  |  SARIF: .mcpsight/report.sarif

Limits you should know

  • npx: and uvx: servers run with the network on, because the package manager has to fetch them. So connection findings only fire for local commands, where the network was off and nothing else could have connected.
  • Watching uses strace. Code written to dodge strace can hide what it does. A stronger watcher is designed but not built yet.
  • Without strace, the sandbox still contains the server, but the report shows capability.not_observed and marks the grade behavior not observed.

More in What MCPsight protects you from.