Depguard vs Codeinspectus — MCP Server Comparison | AllMCPs
Side-by-Side Model Context Protocol Comparison
Depguard vs Codeinspectus
In-depth architectural comparison of the Depguard and Codeinspectus MCP servers. Compare execution transports, security boundaries, tool capabilities, quality scores, and ready-to-paste client installation snippets for Claude, Cursor, Windsurf, and VS Code.
At a Glance & Executive Verdict
Depguard
Security · Local stdio
Quality: 51/100 (Good) | Auth: No auth required
Codeinspectus
Security · Local stdio
Quality: 63/100 (Good) | Auth: API Key required
Verdict Summary: Choose Depguard if you need specialized Security tools running via a local process. Choose Codeinspectus if your workspace requires Security integration with local subprocess execution. Both servers can be configured concurrently in your client's mcpServers manifest.
Which MCP Server Should You Choose?
Choose Depguard when:
You need dedicated capabilities in the Security domain.
You prefer local stdio subprocess transport architecture.
Your security boundary fits: No auth required (Free / Open Source).
Primary tools included: Pre-install package verification and audit, Static code analysis and dead-dependency detection, Vulnerability audit using npm and GitHub Advisory databases.
Pre-install guardian for npm packages with static code analysis, supply-chain attack detection, vulnerability audit (npm + GitHub Advisory Database), AI hallucination guard, and CycloneDX 1.6 SBOM generation with VEX. 28 MCP tools. Zero runtime dependencies — the SBOM serializer is implemented natively against the public CycloneDX schema.
Local-first, zero-egress security scanner for AI-generated / "vibe-coded" JS/TS. Bundles Opengrep, Gitleaks & Trivy behind one CWE-keyed schema and adds AI-code-specific checks (client-side secret exposure, Supabase RLS, prompt-injection & LLM-output XSS sinks). No account, no telemetry.
Category & Scope
Tools & Capabilities Breakdown
Depguard Tools (6)
Pre-install package verification and audit
Static code analysis and dead-dependency detection
Vulnerability audit using npm and GitHub Advisory databases
AI hallucination guard to detect typosquats and fake packages
CycloneDX 1.6 SBOM generation with VEX support
SARIF v2.1.0 output for GitHub Code Scanning integration
Codeinspectus Tools (6)
Ready-to-Paste Client Configurations
Paste either (or both) of these JSON server blocks into your client config file (e.g. claude_desktop_config.json or ~/.cursor/mcp.json).
Depguard is categorized under Security and uses a local stdio subprocess. In contrast, Codeinspectus belongs to Security using local stdio subprocess. Select Depguard when you need capabilities focused on security and Codeinspectus when you require tools for security.
Full local scan of a path (engines + AI checks). Returns CWE-keyed findings, detected technologies, exact native-pack and Pub dependency coverage, remediations, framework tags, and three-state repository evidence for supported runtime controls.
codeinspectus_rescan
Re-scan after fixes; diffs vs a prior scan → resolved / remaining / introduced, with fresh technology and pack coverage.
codeinspectus_compliance_report
Per-framework **code-level control coverage** (not certification).
codeinspectus_explain_finding
Deep explanation + full remediation for one finding.
codeinspectus_generate_sbom
CycloneDX/SPDX SBOM using Trivy plus native Pub inventory/fallback (written to the managed dir by default, or a path you choose).
codeinspectus_list_rules
Active detectors, native-pack inventory/rule ownership, engine versions, detection-DB + Trivy/Pub DB provenance and freshness, and structured machine setup/repair state.