Reference

Troubleshooting

The errors people hit most, what they mean, and what to do.

no sandbox backend available

You tried to scan a local server without bubblewrap. Install it on Linux (sudo apt-get install -y bubblewrap), or scan remote servers. macOS and Windows have no bubblewrap. The refusal is deliberate.

Ubuntu 24.04 blocks bubblewrap

Ubuntu 24.04 stops unprivileged programs from creating user namespaces, which bubblewrap needs. You see errors like this:

bwrap: setting up uid map: Permission denied
bwrap: loopback: Failed RTM_NEWADDR: Operation not permitted

The usual advice turns the protection off for every program. This profile exempts bubblewrap only, and survives a reboot:

sudo tee /etc/apparmor.d/bwrap >/dev/null <<'EOF'
abi <abi/4.0>,
include <tunables/global>

profile bwrap /usr/bin/bwrap flags=(unconfined) {
  userns,
  include if exists <local/bwrap>
}
EOF
sudo apparmor_parser -r /etc/apparmor.d/bwrap

capability.not_observed on a local server

Install strace. Without it the sandbox still contains the server, but nothing watches it, so credential reads and connections cannot be caught. docker: targets and --no-sandbox runs get the same finding, because neither is watched yet.

no baseline recorded

verify never creates a baseline. Run scan once and commit .mcpsight/baseline.json.

✗ http://127.0.0.1:8931/clean: no baseline recorded. Run 'mcpsight scan' first
exit 2

The server times out

The default budget is 30 seconds per server. Package servers that download on first run often need more. Use --timeout 120s.

A local server will not start in the sandbox

It probably needs the network while it starts. Retry with --allow-net. Connection findings are not reported for that run.

server sent a message larger than 16 MiB

MCPsight reads at most 16 MiB per message, so a hostile server cannot exhaust your memory. Real tool lists are a few kilobytes. If an honest server hits this, open an issue.

\x1b and similar in the output

MCPsight shows control characters from a server as visible escapes, so a server cannot clear your screen, change your window title, or fake report lines.

Drift on every scan

Something in the server's tool list changes every time, such as a timestamp in a description. Compare runs in report.json. That is worth reporting to the server's maintainer, because it hides real changes for everyone.

No supply-chain findings

You ran with --offline, the target is not a package, or the machine cannot reach OSV.dev and the package registry.