Skip to content

Releases: greyquill/mcpsight

Release list

MCPsight v0.1.0

Choose a tag to compare

@github-actions github-actions released this 03 Oct 09:52

The first public release of MCPsight, an open-source scanner that inspects an MCP server before your agent trusts it.

An MCP server hands your agent tool descriptions that the model reads and you usually don't. MCPsight reads them for you, runs local servers in a sandbox to see what they actually do, and fails your build when a server changes after you adopted it.

What it checks

  • Prompt injection in tool descriptions: orders to the model, pointers at your SSH key, hidden characters, encoded payloads.
  • What a local server does when it starts, inside a bubblewrap sandbox with decoy credentials and no network.
  • Drift against a baseline you commit, graded by how dangerous the change is.
  • Supply chain: known CVEs from OSV.dev, install scripts, typosquatted names, missing source.
  • Auth posture for remote servers, and the token cost of every tool definition.

Six analyzers and 32 rules produce one score under a published rubric, so you can recompute any grade by hand. It runs offline, with no account and no API key.

Install

brew install --cask greyquill/tap/mcpsight
go install github.com/greyquill/mcpsight/cmd/mcpsight@latest

Or download an archive below. Every release is signed, and Verify a download shows how to check yours.

Get started

mcpsight scan --from claude_desktop_config.json

The docs walk through catching a poisoned server and a rug pull with practice servers that ship in the repo.

Known limitations

  • Local servers (npx:, uvx:, or a command) are scanned on Linux only. macOS and Windows scan remote servers.
  • Behavior is watched with strace, and code written to dodge strace can hide what it does.
  • Token counts are estimates.

Found a problem? Open an issue. For security reports, see SECURITY.md.

Full changelog: https://github.com/greyquill/mcpsight/commits/v0.1.0