Walkthrough
Scan your own setup
--from reads your MCP client's config and scans every server in it. Each server's key in the config becomes its name and its baseline key.
Where your config lives
| Client | Config file |
|---|---|
| Claude Desktop, macOS | ~/Library/Application Support/Claude/claude_desktop_config.json |
| Claude Desktop, Windows | %APPDATA%\Claude\claude_desktop_config.json |
| Claude Code | .mcp.json in your project |
| Cursor | ~/.cursor/mcp.json, or .cursor/mcp.json in your project |
| VS Code | .vscode/mcp.json in your project |
mcpsight scan --from ~/Library/Application\ Support/Claude/claude_desktop_config.json
MCPsight reads an mcpServers object, or servers as VS Code writes it. It understands both kinds of entry:
{
"mcpServers": {
"postgres": {
"command": "npx",
"args": ["-y", "@modelcontextprotocol/server-postgres"],
"env": { "DATABASE_URL": "postgres://..." }
},
"remote-docs": {
"url": "https://mcp.example.com/mcp",
"headers": { "Authorization": "Bearer ..." }
}
}
}
npx and uvx commands get supply-chain checks too. Any other command runs as a local server, in the sandbox.
On macOS and Windows
Remote entries scan. Local entries are refused and named, because running them needs the Linux sandbox. This config has one of each:
benign-docs
Server benign-docs (1.2.0, via remote)
Grade C (60/100) rubric v1
Context cost ~229 tokens (2 tools) ~$0.001 per request @ Claude Sonnet (est.)
Capabilities none declared
Drift baseline recorded (first scan)
Findings
HIGH Server lists its tools without authentication [authposture.unauthenticated_listing]
tools/list returned successfully with no credentials. Anyone who can reach
this endpoint can list its tools, and probably call them.
fix: Require authentication (OAuth 2.1 or at least a bearer token) before serving
tool listings.
HIGH Server is served over plaintext HTTP [authposture.plaintext_http]
The endpoint uses http://, so tool traffic and any credentials travel
unencrypted.
fix: Serve the MCP endpoint over HTTPS.
✗ local: no sandbox backend available (bubblewrap requires Linux; this host is darwin); refusing to run untrusted stdio code. Use --no-sandbox to override (dangerous), or scan remote targets only
Report: .mcpsight/report.json | SARIF: .mcpsight/report.sarif
exit 2
The run exits 2 because one server could not be scanned. The other report is still complete.
--no-sandbox on your own machine.It runs server code with full access to your files and keys. It exists for environments that isolate the process some other way. If you are not sure you are in one, you are not.
Your next step
Commit .mcpsight/baseline.json next to your config, then add the check to CI: Gate pull requests.