Skip to content

JSON report has pattern: null and finding: null for MCP analyzer findings (RP1, LP3), so JSON consumers can't tell what matched #640

Description

@JayOfTheKeyboard

For findings from the MCP analyzers, the JSON output has pattern: null, finding: null and code_snippet: null, and it does not serialize message. The terminal and SARIF output do show the message, e.g. MCP server referenced without pinned version: 'npx @modelcontextprotocol/server-filesystem'. So in JSON, the only thing identifying what triggered RP1 is the generic explanation.

Repro: a SKILL.md containing npx @modelcontextprotocol/server-filesystem /tmp in a bash block, scanned with --format json. Both RP1 issues have pattern and finding null.

Looks like the MCP analyzers build Finding with message and matched_text but not pattern/finding, and RP1/LP3 have no entry in PATTERN_NAMES. Possibly related to #304, which reports null finding on the LLM path.

Activity

  1. rng1995 commented on Sep 28, 2026

    @rng1995
    Collaborator

    Implementation is in progress in PR #641, which fills the MCP rug-pull and least-privilege finding metadata and adds JSON-report regressions for RP1 and LP3. The PR is open and has not merged, so this issue remains open.

  2. rng1995 commented on Oct 4, 2026

    @rng1995
    Collaborator

    Resolution update: PR #641 has merged, preserving match details for MCP rug-pull and least-privilege findings in JSON reports, with sanitization retained. The MCP/report-sanitizer regressions pass on current main. This supersedes the earlier pending status; this issue was automatically closed by the merge.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions