In-depth architectural comparison of the HVTracker MCP and Vorim MCP Server MCP servers. Compare execution transports, security boundaries, tool capabilities, quality scores, and ready-to-paste client installation snippets for Claude, Cursor, Windsurf, and VS Code.
At a Glance & Executive Verdict
HVTracker MCP
Security · Local stdio
Quality: 63/100 (Good) | Auth: No auth required
Vorim MCP Server
Security · Local stdio
Quality: 65/100 (Great) | Auth: API Key required
Verdict Summary: Choose HVTracker MCP if you need specialized Security tools running via a local process. Choose Vorim MCP Server if your workspace requires Security integration with local subprocess execution. Both servers can be configured concurrently in your client's mcpServers manifest.
Which MCP Server Should You Choose?
Choose HVTracker MCP when:
You need dedicated capabilities in the Security domain.
You prefer local stdio subprocess transport architecture.
Your security boundary fits: No auth required (Free / Open Source).
Pre-connect trust verdict for an MCP server or AI agent.
Pass a GitHub owner/repo, GitHub URL, npm/PyPI package, display name, slug,
or MCP server URL. Unknown servers return trusted=false because HVTracker has
no independent evidence, not because harm is proven.
check_agent_trust
Get the HVTracker trust profile for a tracked AI agent or framework,
including its runtime capability surface and the URL of its Ed25519-signed
trust credential (verifiable offline).
compare_agents
Compare two tracked AI agents side by side: both trust profiles, an
evidence-based one-line verdict, and the HVTracker compare-page URL when
one is published.
search_agents
Search tracked AI agents and frameworks by name, repo, or description.
scan_stack
Bulk pre-connect trust check for a whole dependency set. Paste a
requirements.txt, package.json, MCP client config, or a newline/comma list;
each item is returned with a trust verdict plus a stack summary.
Ready-to-Paste Client Configurations
Paste either (or both) of these JSON server blocks into your client config file (e.g. claude_desktop_config.json or ~/.cursor/mcp.json).
HVTracker MCP is categorized under Security and uses a local stdio subprocess. In contrast, Vorim MCP Server belongs to Security using local stdio subprocess. Select HVTracker MCP when you need capabilities focused on security and Vorim MCP Server when you require tools for security.
List HVTracker categories with agent counts (most-populated first), so you
can then pull a category's leaderboard.
get_leaderboard
Top tracked AI agents and MCP servers by HVTrust score, optionally scoped
to one category (exact name from list_categories).
get_agent_history
90-day trust-score, grade, and rank history for one tracked agent — is it
improving or declining? Accepts the same identifiers as check_agent_trust.
Vorim MCP Server Tools (4)
vorim_ping
Check Vorim AI API health and connectivity. Returns status, version, and service health.
vorim_verify_trust
Verify an agent's identity and trust score. Public endpoint, no authentication required. Returns the trust score (0-100), trust band, status, owning organisation name and a signed attestation. Active scopes and key fingerprint are not shown publicly; the owning organisation can see them with vorim_list_permissions and vorim_get_agent.
vorim_onboard_start
Start onboarding a user who does NOT yet have a Vorim API key (device-authorization flow). Returns a user_code and an activation URL. You MUST show the human the user_code and verification_uri VERBATIM and ask them to approve in their browser. Then call vorim_onboard_check with the returned device_code to obtain the API key. No VORIM_API_KEY is required for this tool.
vorim_onboard_check
Check whether the human has approved the onboarding request from vorim_onboard_start. Pass the device_code you received. Returns the new API key once approved; otherwise returns a status (authorization_pending — wait ~5s and call again; slow_down — wait longer; access_denied; expired_token).