Side-by-side comparison of two Model Context Protocol servers โ install paths, tools, quality signals, and directory engagement so you can pick the right one for Claude, Cursor, and other MCP clients.
Runtime governance for MCP tool calls. Blocks prompt injection and capability abuse before tool results reach your agent.
Check whether anything you depend on is known malware, before an agent installs it. checklockfile takes a package-lock.json, yarn.lock or pnpm-lock.yaml and matches every pinned version against published malicious-package advisories in one call, free and with no API key, catching compromised releases like chalk@5.6.1 while leaving their clean releases alone. scanartifact adds deterministic behavioral analysis (no LLM in the serving path) for credential theft, exfiltration, obfuscation, prompt injection and install-time droppers, with the file, line and evidence that triggered it; verdicts are SHA-256-bound so you can re-verify what landed on disk. Paid scans settle at $0.03 USDC on Base (x402) or prepaid credits. npx lazaretto-mcp
Quality signal
47/100 (Fair)
51/100 (Fair)
Install path
uvx ยท high
Remote ยท high
Engagement
4 0 0 2
1 0 0 0
Tools
Runtime governance proxy for MCP tool callsMultiple policy modes (balanced, browser_agent, finance_agent, rag_assistant, strict)Blocks prompt injection and capability abuseSupports integration with various MCP serversAvailable as a Python package and CLI tool