Observed arrival · 2026-10-06
MCPsight’s decoy-credential test
An open-source scanner checks MCP servers for security risks, runs local servers in a sandbox, and can fail a build when a server changes.
○Open
⊠Login
$Paid
†Ads
✦Pretty
●Pro
◎Niche
◉Human
⚑Risk
ƒJS
- For
- Developers reviewing MCP servers in local configs or CI
- Worth noticing
- Each finding has a stable rule ID, severity, and fix; grades use a published rubric readers can recompute by hand.
Field notes
The homepage gives findings a stable rule ID, severity, and suggested fix, and says its grading rubric can be recomputed by hand. Its sample report assigns a critical grade to a server that reads decoy credential files; the listed checks also include OSV.dev vulnerability data, install scripts, and token costs. The page says scans can run offline and that local servers are refused if a sandbox is unavailable.
Observed signals
Read the marks
Editorial observations of this landing page, not a rating.
○OpenPublic substance visible
✦PrettyNotable craft visible
●ProPolished or operationally mature
◎NicheUnusually specific use
One card from the complete issue