Skip to the card

Card 506 of 9902026-10-06 issue

Observed arrival · 2026-10-06

MCPsight’s decoy-credential test

mcpsight.dev Visit website
Editorial interest 84/100 Selection signal · not a rating of the site

An open-source scanner checks MCP servers for security risks, runs local servers in a sandbox, and can fail a build when a server changes.

Landing page captured for the 2026-10-06 issue.
For
Developers reviewing MCP servers in local configs or CI
Worth noticing
Each finding has a stable rule ID, severity, and fix; grades use a published rubric readers can recompute by hand.

Field notes

The homepage gives findings a stable rule ID, severity, and suggested fix, and says its grading rubric can be recomputed by hand. Its sample report assigns a critical grade to a server that reads decoy credential files; the listed checks also include OSV.dev vulnerability data, install scripts, and token costs. The page says scans can run offline and that local servers are refused if a sandbox is unavailable.

Observed signals

Read the marks

Editorial observations of this landing page, not a rating.

○OpenPublic substance visible
✦PrettyNotable craft visible
●ProPolished or operationally mature
◎NicheUnusually specific use

One card from the complete issue

Original Bugs Included

353,261 arrived 1,000 judged 990 catalogued Enter the complete issue
mcpsight.dev

Landing page observed 2026-10-06. The live site may have changed.