Side-by-side comparison of two Model Context Protocol servers — install paths, tools, quality signals, and directory engagement so you can pick the right one for Claude, Cursor, and other MCP clients.
Pre-install guardian for npm packages with static code analysis, supply-chain attack detection, vulnerability audit (npm + GitHub Advisory Database), AI hallucination guard, and CycloneDX 1.6 SBOM generation with VEX. 28 MCP tools. Zero runtime dependencies — the SBOM serializer is implemented natively against the public CycloneDX schema.
Exposes the RSigma Sigma detection-engineering toolkit to AI agents over stdio or Streamable HTTP with rsigma mcp serve. Tools to author, lint, validate, and convert Sigma detection rules, evaluate and explain detections against log events, and inspect correlation state, all backed by a native Rust engine.
Quality signal
53/100 (Fair)
48/100 (Fair)
Install path
npx · high
npx · low
Engagement
1 0 0 15
1 0 0 128
Tools
Pre-install package guardian with allow/warn/block decisionsStatic code analysis and vulnerability audit using npm and GitHub advisoriesAI hallucination guard to detect typosquats and fake packagesRemediation planner grouping vulnerabilities by dependency parentsCycloneDX 1.6 SBOM generation with VEX supportSARIF v2.1.0 output compatible with GitHub Code Scanning