Side-by-side comparison of two Model Context Protocol servers — install paths, tools, quality signals, and directory engagement so you can pick the right one for Claude, Cursor, and other MCP clients.
Post-quantum readiness for AI coding agents: scan code for quantum-vulnerable cryptography (RSA/ECDH/ECDSA/DH), explain the harvest-now-decrypt-later exposure, get NIST ML-KEM/ML-DSA/SLH-DSA (and hybrid) migration guidance, verify fixes, and check dependencies. Content-based/advisory tools only. Run local (npx @quantakrypto/mcp) or the hosted OAuth endpoint at mcp.quantakrypto.com.
Pre-install guardian for npm packages with static code analysis, supply-chain attack detection, vulnerability audit (npm + GitHub Advisory Database), AI hallucination guard, and CycloneDX 1.6 SBOM generation with VEX. 28 MCP tools. Zero runtime dependencies — the SBOM serializer is implemented natively against the public CycloneDX schema.
Quality signal
45/100 (Fair)
53/100 (Fair)
Install path
npx · high
npx · high
Engagement
0 0 0 9
1 0 0 15
Tools
Not listed yet
Pre-install package guardian with allow/warn/block decisionsStatic code analysis and vulnerability audit using npm and GitHub advisoriesAI hallucination guard to detect typosquats and fake packagesRemediation planner grouping vulnerabilities by dependency parentsCycloneDX 1.6 SBOM generation with VEX supportSARIF v2.1.0 output compatible with GitHub Code Scanning