Side-by-side comparison of two Model Context Protocol servers — install paths, tools, quality signals, and directory engagement so you can pick the right one for Claude, Cursor, and other MCP clients.
Check whether anything you depend on is known malware, before an agent installs it. checklockfile takes a package-lock.json, yarn.lock or pnpm-lock.yaml and matches every pinned version against published malicious-package advisories in one call, free and with no API key, catching compromised releases like chalk@5.6.1 while leaving their clean releases alone. scanartifact adds deterministic behavioral analysis (no LLM in the serving path) for credential theft, exfiltration, obfuscation, prompt injection and install-time droppers, with the file, line and evidence that triggered it; verdicts are SHA-256-bound so you can re-verify what landed on disk. Paid scans settle at $0.03 USDC on Base (x402) or prepaid credits. npx lazaretto-mcp
Dead code detection, security scanning, and code quality analysis for Python, TypeScript, and Go. 98% recall with fewer false positives than Vulture. Includes AI-powered remediation.
Quality signal
51/100 (Fair)
51/100 (Fair)
Install path
Remote · high
uvx · high
Engagement
0 0 0 0
4 0 0 499
Tools
known_bad_lookupscan_artifact
Dead code detection with high recall and low false positivesSecurity scanning including dangerous data flows and secretsQuality analysis covering complexity, nesting, and duplicationAI-powered remediation suggestions and defect checksLocal and CI/CD usage with GitHub Actions supportSupport for multiple languages including Python, TypeScript, Go, Java, and more