Side-by-side comparison of two Model Context Protocol servers — install paths, tools, quality signals, and directory engagement so you can pick the right one for Claude, Cursor, and other MCP clients.
Pre-install guardian for npm packages with static code analysis, supply-chain attack detection, vulnerability audit (npm + GitHub Advisory Database), AI hallucination guard, and CycloneDX 1.6 SBOM generation with VEX. 28 MCP tools. Zero runtime dependencies — the SBOM serializer is implemented natively against the public CycloneDX schema.
Transparent Go proxy that intercepts, signs, rate-limits, redacts, and audits all MCP JSON-RPC tool calls without modifying client or server.
Quality signal
53/100 (Fair)
49/100 (Fair)
Install path
npx · high
npx · high
Engagement
0 0 0 15
0 0 0 7
Tools
Pre-install package guardian with allow/warn/block decisionsStatic code analysis and vulnerability audit using npm and GitHub advisoriesAI hallucination guard to detect typosquats and fake packagesRemediation planner grouping vulnerabilities by dependency parentsCycloneDX 1.6 SBOM generation with VEX supportSARIF v2.1.0 output compatible with GitHub Code Scanning
Transparent proxy for MCP JSON-RPC trafficSigned audit trail generationPayload redaction of sensitive dataAllow/deny policy enforcementPer-tool rate limitingLocal read-only dashboard and Prometheus metrics