Skip to main content
AllMCPs
BrowseBestCategoriesStackCompareToolsGuidesBlog
Log in Submit MCP

Stay in the loop

Get new MCP servers and top picks in your inbox.

AllMCPs

The open directory for discovering and installing Model Context Protocol servers.

AllMCPs on GitHub (opens in a new tab)
Launched onTiny Startupstinystartups.com
Explore
  • Browse servers
  • Best MCP servers
  • Categories
  • MCP clients
  • Agent prompts
  • Stack Builder
  • Compare servers
  • Random discovery New
  • Submit a server
  • Pricing & Boost Boost
Learn
  • Guides hub
  • What is MCP?
  • Install guide
  • Build an MCP server
  • Deploy an MCP server
  • Security guide
  • Troubleshooting
  • MCP for SEO & AEO
  • Protocol versioning
  • Transports: stdio vs HTTP
  • State of MCP (stats)
  • Blog & updates
Tools
  • All developer tools
  • Config generator
  • Config validator
  • Config auditor
  • MCP playground
  • Token calculator
  • OpenAPI → MCP
  • Badge generator
For agents
  • REST API docs
  • Trust & traffic Live
  • Remote MCP server SSE ↗ (opens in a new tab)
  • llms.txt ↗ (opens in a new tab)
  • Catalog JSON ↗ (opens in a new tab)
Company
  • About
  • Advertise Sponsor
  • Contact
  • GitHub ↗ (opens in a new tab)
  • Terms
  • Privacy
AllMCPs VerifiedAllMCPs VerifiedFeatured on Nick LaunchesFeatured on Nick LaunchesLaunch Llama NewsletterLaunch Llama NewsletterVerified DR - allmcps.comVerified DR - allmcps.comFeatured on SaaSGrowFeatured on SaaSGrowFeatured on Twelve ToolsFeatured on Twelve ToolsFeatured on Saaspa.geFeatured on Saaspa.geFeatured on Findly.toolsFeatured on Findly.toolsFeatured on Startup FameFeatured on Startup FameFeatured on LaunchKiwiFeatured on LaunchKiwiFeatured on ScrollLaunchFeatured on ScrollLaunchFeatured on DailyPingsFeatured on DailyPingsFazier badgeFazier badgeFeatured on NewTool.siteFeatured on NewTool.siteFeatured on saasfame.comFeatured on saasfame.comDR Checker - Domain RatingDR Checker - Domain RatingListed on Turbo0Listed on Turbo0Launched on LaunchBoard - Product Launch PlatformLaunched on LaunchBoard - Product Launch PlatformList on SimilarlabsList on Similarlabshttps://codetrendy.comhttps://codetrendy.comListed on DevTool.ioFeatured on BuildlistFeatured on BuildlistLaunched on Tiny StartupsFeatured on ShowMeBestAIFeatured on ShowMeBestAIFind us on LaunchZoneFind us on LaunchZoneAllMCPs VerifiedAllMCPs VerifiedFeatured on Nick LaunchesFeatured on Nick LaunchesLaunch Llama NewsletterLaunch Llama NewsletterVerified DR - allmcps.comVerified DR - allmcps.comFeatured on SaaSGrowFeatured on SaaSGrowFeatured on Twelve ToolsFeatured on Twelve ToolsFeatured on Saaspa.geFeatured on Saaspa.geFeatured on Findly.toolsFeatured on Findly.toolsFeatured on Startup FameFeatured on Startup FameFeatured on LaunchKiwiFeatured on LaunchKiwiFeatured on ScrollLaunchFeatured on ScrollLaunchFeatured on DailyPingsFeatured on DailyPingsFazier badgeFazier badgeFeatured on NewTool.siteFeatured on NewTool.siteFeatured on saasfame.comFeatured on saasfame.comDR Checker - Domain RatingDR Checker - Domain RatingListed on Turbo0Listed on Turbo0Launched on LaunchBoard - Product Launch PlatformLaunched on LaunchBoard - Product Launch PlatformList on SimilarlabsList on Similarlabshttps://codetrendy.comhttps://codetrendy.comListed on DevTool.ioFeatured on BuildlistFeatured on BuildlistLaunched on Tiny StartupsFeatured on ShowMeBestAIFeatured on ShowMeBestAIFind us on LaunchZoneFind us on LaunchZone
© 2026 Jackalope Digital LLC. All rights reserved.
  1. Home
  2. Browse
  3. Vulnfeed MCP
  4. vs Sast MCP Server
Side-by-Side Model Context Protocol Comparison

Vulnfeed MCP vs Sast MCP Server

In-depth architectural comparison of the Vulnfeed MCP and Sast MCP Server MCP servers. Compare execution transports, security boundaries, tool capabilities, quality scores, and ready-to-paste client installation snippets for Claude, Cursor, Windsurf, and VS Code.

At a Glance & Executive Verdict

Vulnfeed MCP
Security · Local stdio
Quality: 56/100 (Good) | Auth: API Key required
Sast MCP Server
Security · Local stdio
Quality: 57/100 (Good) | Auth: API Key required
Verdict Summary: Choose Vulnfeed MCP if you need specialized Security tools running via a local process. Choose Sast MCP Server if your workspace requires Security integration with local subprocess execution. Both servers can be configured concurrently in your client's mcpServers manifest.

Which MCP Server Should You Choose?

Vulnfeed MCP logo

Choose Vulnfeed MCP when:

  • You need dedicated capabilities in the Security domain.
  • You prefer local stdio subprocess transport architecture.
  • Your security boundary fits: API Key required (Freemium).
  • You have access to required keys: VULNFEED_API_KEY.
  • Primary tools included: scan_project, scan_lockfile, check_package.
Explore Vulnfeed MCP Details
Sast MCP Server logo

Choose Sast MCP Server when:

  • You need dedicated capabilities in the Security domain.
  • You prefer local stdio subprocess transport architecture.
  • Your security boundary fits: API Key required (Free / Open Source).
  • You have access to required keys: DEFECTDOJO_URL, GITHUB_TOKEN, JIRA_URL, JIRA_EMAIL, JIRA_API_TOKEN.
  • Primary tools included: scan_vulnerabilities, ignore_vulnerability, unignore_vulnerability.

Feature & Specification Comparison

Specification
Vulnfeed MCP logo
Vulnfeed MCP
infai-tech
Security
Sast MCP Server logo
Sast MCP Server
Skyrxin
Security
SummaryDependency vulnerability scanner with EPSS exploit probability scoring. Scans lockfiles (npm, pip, Go, Cargo, Ruby, Composer, Gradle, NuGet, Mix), prioritizes by real-world exploit likelihood, recommends fix versions. 9 MCP tools for scanning, monitoring, and alerting. Free tier + x402 micropayments. pip install vulnfeed-mcpSAST/DAST server exposing 11 security scanners (Bandit, Semgrep, Trivy, CodeQL, Checkov, Gitleaks, OSV-Scanner, Grype, OWASP ZAP, and more) with closed-loop remediation (scan→patch→re-scan→verify), SARIF/SBOM/VEX export, compliance reporting, and CI integrations (GitHub Advanced Security, DefectDojo, Slack, Jira).
Category & Scope

Tools & Capabilities Breakdown

Vulnfeed MCP Tools (9)

scan_project
Auto-detect and scan all lockfiles in a directory
scan_lockfile
Scan a specific lockfile
check_package
Check a single package for vulnerabilities
lookup_cve
Detailed CVE info with EPSS + fix versions
monitor_project
Register for continuous monitoring
check_alerts
New vulns since last scan

Ready-to-Paste Client Configurations

Paste either (or both) of these JSON server blocks into your client config file (e.g. claude_desktop_config.json or ~/.cursor/mcp.json).

Vulnfeed MCP Configuration
mcpServers (Claude Desktop / Cursor)
{
  "mcpServers": {
    "infai-tech-vulnfeed-mcp": {
      "command": "uvx",
      "args": [
        "vulnfeed-mcp"
      ],
      "env": {
        "VULNFEED_API_KEY": "YOUR_VULNFEED_API_KEY_HERE"
      }
    }
  }
}
Sast MCP Server Configuration
mcpServers (Claude Desktop / Cursor)
{
  "mcpServers": {
    "skyrxin-sast-mcp-server": {
      "command": "uvx",
      "args": [
        "sast-mcp-server"
      ],
      "env": {
        "DEFECTDOJO_URL": "YOUR_DEFECTDOJO_URL_HERE",
        "GITHUB_TOKEN": "YOUR_GITHUB_TOKEN_HERE",
        "JIRA_URL": "YOUR_JIRA_URL_HERE",
        "JIRA_EMAIL": "YOUR_JIRA_EMAIL_HERE",
        "JIRA_API_TOKEN": "YOUR_JIRA_API_TOKEN_HERE"
      }
    }
  }
}

Frequently Asked Questions

Vulnfeed MCP is categorized under Security and uses a local stdio subprocess. In contrast, Sast MCP Server belongs to Security using local stdio subprocess. Select Vulnfeed MCP when you need capabilities focused on security and Sast MCP Server when you require tools for security.

More alternatives to Vulnfeed MCPMore alternatives to Sast MCP ServerSecurity category hub

Related MCP Server Comparisons

Popular comparisons with Vulnfeed MCP

  • Osv Ui logoVulnfeed MCP vs Osv Ui
  • Depscope logoVulnfeed MCP vs Depscope
  • Agent Bom logoVulnfeed MCP vs Agent Bom
  • Mobb Vibe Shield MCP logoVulnfeed MCP vs Mobb Vibe Shield MCP

Popular comparisons with Sast MCP Server

Explore Sast MCP Server Details
Security
Security
Quality signal56/100 (Good)57/100 (Good)
Transport ProtocolLocal Subprocess (stdio)Local Subprocess (stdio)
Auth RequirementAPI Key requiredAPI Key required
Pricing ModelFreemiumFree / Open Source
Required Env Vars
VULNFEED_API_KEY
DEFECTDOJO_URLGITHUB_TOKENJIRA_URLJIRA_EMAILJIRA_API_TOKEN
Compatible Clients
Claude DesktopCursorWindsurfClineVS Code
Claude DesktopCursorWindsurfClineVS Code
Install path signaluvx · highuvx · high
Engagement & Health 2 views 0 copies 0 upvotes 1 stars 2 views 0 copies 0 upvotes 3 stars
Verified / OfficialCommunity ListingCommunity Listing
Open full listingView Vulnfeed MCP ListingView Sast MCP Server Listing
update_deps
Update snapshot after upgrading packages
list_monitored
See all monitored projects
unmonitor_project
Remove from monitoring

Sast MCP Server Tools (27)

scan_vulnerabilities
Scan a target directory for security vulnerabilities using a SAST tool.
ignore_vulnerability
Ignore a specific vulnerability finding so it won't appear in future scans.
unignore_vulnerability
Remove a vulnerability from the ignore list so it appears in future scans again.
list_scanners
List all available SAST scanners, their status, and supported languages. Returns information about each scanner including whether it is installed and ready to use, what languages it supports, and how to install it.
list_ignored_vulnerabilities
List all currently ignored vulnerability findings for a project.
scan_git_history
Scan the entire git history for leaked secrets and credentials using Gitleaks. Traditional SAST only scans the current state of files. This tool deeply analyzes the `.git` directory to find API keys, passwords, and tokens that were committed in the past but may still be valid.
run_active_scan
Run an active dynamic scan (DAST) using OWASP ZAP. Unlike SAST which only looks at code, this orchestrates spinning up the application via Docker Compose, waiting for it to be ready, and then running a ZAP dynamic baseline scan against the running instance.
export_sarif
Run a SAST scan and export results in SARIF 2.1.0 format for CI/CD integration. SARIF is the industry standard format consumed by GitHub Code Scanning, GitLab SAST, Azure DevOps, and other CI/CD platforms.
scan_all
Scan with ALL installed scanners in parallel, returning deduplicated results. Automatically detects which scanners are installed, runs them concurrently, and deduplicates findings across scanners using content-based hashing. This is the recommended tool for comprehensive security scanning.
scan_image
Scan a container image for vulnerabilities and secrets. Pulls and analyzes a container image reference (e.g. `nginx:1.25`, `ghcr.io/org/app@sha256:...`) with Trivy or Grype, returning the same normalized findings as a source scan.
save_baseline
Run a scan and save the results as a named baseline for future comparison.
compare_baseline
Compare current scan results against a saved baseline. Shows new vulnerabilities, fixed vulnerabilities, and severity trends.
+15 more tools listed on main page
Guardvibe logo
Sast MCP Server vs Guardvibe
  • Mobb Vibe Shield MCP logoSast MCP Server vs Mobb Vibe Shield MCP
  • Codeinspectus logoSast MCP Server vs Codeinspectus
  • Gia MCP Server logoSast MCP Server vs Gia MCP Server