In-depth architectural comparison of the Privacyscrubber MCP and MCP Server MCP servers. Compare execution transports, security boundaries, tool capabilities, quality scores, and ready-to-paste client installation snippets for Claude, Cursor, Windsurf, and VS Code.
At a Glance & Executive Verdict
Privacyscrubber MCP
Security · Local stdio
Quality: 64/100 (Good) | Auth: API Key required
MCP Server
Security · Local stdio
Quality: 65/100 (Great) | Auth: API Key required
Verdict Summary: Choose Privacyscrubber MCP if you need specialized Security tools running via a local process. Choose MCP Server if your workspace requires Security integration with local subprocess execution. Both servers can be configured concurrently in your client's mcpServers manifest.
Which MCP Server Should You Choose?
Choose Privacyscrubber MCP when:
You need dedicated capabilities in the Security domain.
You prefer local stdio subprocess transport architecture.
Your security boundary fits: API Key required (Freemium).
Zero-trust local PII and secrets masking server for Cursor, Windsurf, and Claude Desktop. npx pii-masking-run
MCP server for RAD Security, providing AI-powered security insights for Kubernetes and cloud environments. This server provides tools for querying the Rad Security API and retrieving security findings, reports, runtime data and many more.
Category & Scope
Tools & Capabilities Breakdown
Privacyscrubber MCP Tools (23)
audit_context
STEP 0 (Pre-Flight): Non-destructive security inspection of raw prompts or document chunks before sending to LLMs. Evaluates PII, secrets, risk severity (CLEAN, LOW, MODERATE, CRITICAL), and triggered regulatory frameworks (GDPR, HIPAA, SOC 2, PCI DSS) with zero text mutation.
sanitize_text
STEP 1: Call this first. You MUST NOT process raw user data before calling this. Locally scrubs PII, secrets, and credentials (like API keys, passwords, emails, phones, names) from code, logs, or text. Replaces them with safe placeholders (e.g., [EMAIL_1], [API_KEY_1]). Keep your data secure before passing it to any LLM. (For in-code backend services or RAG vector pipelines outside of MCP, use '@privacyscrubber/sdk': npm i @privacyscrubber/sdk)
scrub_text
Alias for 'sanitize_text'. Locally scrubs PII and secrets before LLM ingestion.
reveal_text
STEP 3: Call this last. You MUST pass your final generated response through this tool to restore tokens (e.g., [EMAIL_1]) back with the original private data from the local volatile RAM-only session map before showing it to the user.
Ready-to-Paste Client Configurations
Paste either (or both) of these JSON server blocks into your client config file (e.g. claude_desktop_config.json or ~/.cursor/mcp.json).
Privacyscrubber MCP is categorized under Security and uses a local stdio subprocess. In contrast, MCP Server belongs to Security using local stdio subprocess. Select Privacyscrubber MCP when you need capabilities focused on security and MCP Server when you require tools for security.
Reads a local file, sanitizes its contents using the selected profile, and outputs the safe version for AI analysis. Securely keeps original identifiers in memory.
scrub_file
Alias for 'sanitize_file'. Reads and sanitizes a local file.
audit_directory_for_pii
Scans a local directory for leaks of secrets, keys, and PII. Returns a summary report. Use this tool for Security Auditing.
redact_file
Action/Redact: In-place redaction of a local file. Replaces PII and secrets with tokens and saves the file. By default, creates a .bak backup. Use dry_run=true to test without modifying.
create_default_config
Creates a default 'privacyscrubber.json' configuration file in the active workspace root directory if one does not exist. Includes template structures for custom regex rules and exclusion bypass patterns.
generate_compliance_report
Generates an official Zero-Trust Compliance Audit Certificate (GDPR, HIPAA, EU AI Act, SOC 2) for the current MCP session. Returns cryptographic session hash, masked entities breakdown, and compliance certification.
mark_false_positive
Marks a previously detected token as a false positive. The original plaintext value will be excluded from all future sanitize_text calls in this session. Returns the restored original value and updated ignore list size.
check_status
Returns the current PrivacyScrubber MCP tier, session usage, available profiles, and PRO upgrade instructions. Call this to see your license status or get setup help.
+11 more tools listed on main page
MCP Server Tools (54)
list_containers
List containers secured by RAD Security with optional filtering by image name, image digest, namespace, cluster_id, or free text search
get_container_details
Get detailed information about a container secured by RAD Security
list_clusters
List Kubernetes clusters managed by RAD Security
get_cluster_details
Get detailed information about a specific Kubernetes cluster managed by RAD Security
who_shelled_into_pod
Get k8s audit logs with information about users who shelled into a pod
list_images
List container images with optional filtering by page, page size, sort, and search query
list_image_vulnerabilities
List vulnerabilities in a container image with optional filtering by severity
get_top_vulnerable_images
Get the most vulnerable images from your account
get_image_sbom
Get the SBOM of a container image
ignore_cve
Ignore a CVE for this account so it no longer appears in vulnerability reporting. Use for confirmed false positives, accepted risks, or won't-fix decisions. Do NOT use for remediated CVEs — those drop off automatically on the next scan.
unignore_cve
Remove an account-wide CVE disposition, restoring the CVE to vulnerability reporting.
list_cve_dispositions
List active CVE dispositions (ignored / false positive) for this account, with reason and author.