Side-by-side comparison of two Model Context Protocol servers — install paths, tools, quality signals, and directory engagement so you can pick the right one for Claude, Cursor, and other MCP clients.
Check whether anything you depend on is known malware, before an agent installs it. checklockfile takes a package-lock.json, yarn.lock or pnpm-lock.yaml and matches every pinned version against published malicious-package advisories in one call, free and with no API key, catching compromised releases like chalk@5.6.1 while leaving their clean releases alone. scanartifact adds deterministic behavioral analysis (no LLM in the serving path) for credential theft, exfiltration, obfuscation, prompt injection and install-time droppers, with the file, line and evidence that triggered it; verdicts are SHA-256-bound so you can re-verify what landed on disk. Paid scans settle at $0.03 USDC on Base (x402) or prepaid credits. npx lazaretto-mcp
vet-mcp checks open source packages—like those suggested by AI coding tools—for vulnerabilities and malicious code. It supports npm and PyPI, and runs locally via Docker or as a standalone binary for fast, automated vetting.
Quality signal
51/100 (Fair)
52/100 (Fair)
Install path
Remote · high
Remote · high
Engagement
0 0 0 0
3 0 0 1,096
Tools
known_bad_lookupscan_artifact
Real-time malicious package detection via SafeDep CloudVulnerability analysis based on dependency usage evidencePolicy-as-code enforcement with CEL expressionsSupports npm, PyPI, Maven, Go, Ruby, Rust, PHP ecosystemsScans container images and SBOMsOutputs actionable reports in multiple formats