Releases: greyquill/mcpsight
Release list
MCPsight v0.1.0
The first public release of MCPsight, an open-source scanner that inspects an MCP server before your agent trusts it.
An MCP server hands your agent tool descriptions that the model reads and you usually don't. MCPsight reads them for you, runs local servers in a sandbox to see what they actually do, and fails your build when a server changes after you adopted it.
What it checks
- Prompt injection in tool descriptions: orders to the model, pointers at your SSH key, hidden characters, encoded payloads.
- What a local server does when it starts, inside a bubblewrap sandbox with decoy credentials and no network.
- Drift against a baseline you commit, graded by how dangerous the change is.
- Supply chain: known CVEs from OSV.dev, install scripts, typosquatted names, missing source.
- Auth posture for remote servers, and the token cost of every tool definition.
Six analyzers and 32 rules produce one score under a published rubric, so you can recompute any grade by hand. It runs offline, with no account and no API key.
Install
brew install --cask greyquill/tap/mcpsight
go install github.com/greyquill/mcpsight/cmd/mcpsight@latest
Or download an archive below. Every release is signed, and Verify a download shows how to check yours.
Get started
mcpsight scan --from claude_desktop_config.json
The docs walk through catching a poisoned server and a rug pull with practice servers that ship in the repo.
Known limitations
- Local servers (
npx:,uvx:, or a command) are scanned on Linux only. macOS and Windows scan remote servers. - Behavior is watched with strace, and code written to dodge strace can hide what it does.
- Token counts are estimates.
Found a problem? Open an issue. For security reports, see SECURITY.md.
Full changelog: https://github.com/greyquill/mcpsight/commits/v0.1.0