Side-by-side comparison of two Model Context Protocol servers — install paths, tools, quality signals, and directory engagement so you can pick the right one for Claude, Cursor, and other MCP clients.
Pre-install guardian for npm packages with static code analysis, supply-chain attack detection, vulnerability audit (npm + GitHub Advisory Database), AI hallucination guard, and CycloneDX 1.6 SBOM generation with VEX. 28 MCP tools. Zero runtime dependencies — the SBOM serializer is implemented natively against the public CycloneDX schema.
vet-mcp checks open source packages—like those suggested by AI coding tools—for vulnerabilities and malicious code. It supports npm and PyPI, and runs locally via Docker or as a standalone binary for fast, automated vetting.
Quality signal
53/100 (Fair)
52/100 (Fair)
Install path
npx · high
Remote · high
Engagement
1 0 0 15
3 0 0 1,096
Tools
Pre-install package guardian with allow/warn/block decisionsStatic code analysis and vulnerability audit using npm and GitHub advisoriesAI hallucination guard to detect typosquats and fake packagesRemediation planner grouping vulnerabilities by dependency parentsCycloneDX 1.6 SBOM generation with VEX supportSARIF v2.1.0 output compatible with GitHub Code Scanning
Real-time malicious package detection via SafeDep CloudVulnerability analysis based on dependency usage evidencePolicy-as-code enforcement with CEL expressionsSupports npm, PyPI, Maven, Go, Ruby, Rust, PHP ecosystemsScans container images and SBOMsOutputs actionable reports in multiple formats