Walkthrough

Scan your own setup

--from reads your MCP client's config and scans every server in it. Each server's key in the config becomes its name and its baseline key.

Where your config lives

ClientConfig file
Claude Desktop, macOS~/Library/Application Support/Claude/claude_desktop_config.json
Claude Desktop, Windows%APPDATA%\Claude\claude_desktop_config.json
Claude Code.mcp.json in your project
Cursor~/.cursor/mcp.json, or .cursor/mcp.json in your project
VS Code.vscode/mcp.json in your project
mcpsight scan --from ~/Library/Application\ Support/Claude/claude_desktop_config.json

MCPsight reads an mcpServers object, or servers as VS Code writes it. It understands both kinds of entry:

{
  "mcpServers": {
    "postgres": {
      "command": "npx",
      "args": ["-y", "@modelcontextprotocol/server-postgres"],
      "env": { "DATABASE_URL": "postgres://..." }
    },
    "remote-docs": {
      "url": "https://mcp.example.com/mcp",
      "headers": { "Authorization": "Bearer ..." }
    }
  }
}

npx and uvx commands get supply-chain checks too. Any other command runs as a local server, in the sandbox.

On macOS and Windows

Remote entries scan. Local entries are refused and named, because running them needs the Linux sandbox. This config has one of each:

  benign-docs
  Server        benign-docs  (1.2.0, via remote)
  Grade         C  (60/100)  rubric v1

  Context cost  ~229 tokens  (2 tools)   ~$0.001 per request @ Claude Sonnet  (est.)
  Capabilities  none declared
  Drift         baseline recorded (first scan)

  Findings
  HIGH      Server lists its tools without authentication [authposture.unauthenticated_listing]
      tools/list returned successfully with no credentials. Anyone who can reach
      this endpoint can list its tools, and probably call them.
      fix: Require authentication (OAuth 2.1 or at least a bearer token) before serving
      tool listings.
  HIGH      Server is served over plaintext HTTP [authposture.plaintext_http]
      The endpoint uses http://, so tool traffic and any credentials travel
      unencrypted.
      fix: Serve the MCP endpoint over HTTPS.

✗ local: no sandbox backend available (bubblewrap requires Linux; this host is darwin); refusing to run untrusted stdio code. Use --no-sandbox to override (dangerous), or scan remote targets only
  Report: .mcpsight/report.json  |  SARIF: .mcpsight/report.sarif

exit 2

The run exits 2 because one server could not be scanned. The other report is still complete.

Do not use --no-sandbox on your own machine.

It runs server code with full access to your files and keys. It exists for environments that isolate the process some other way. If you are not sure you are in one, you are not.

Your next step

Commit .mcpsight/baseline.json next to your config, then add the check to CI: Gate pull requests.