In-depth architectural comparison of the MCP Server and Sonarqube MCP Server MCP servers. Compare execution transports, security boundaries, tool capabilities, quality scores, and ready-to-paste client installation snippets for Claude, Cursor, Windsurf, and VS Code.
At a Glance & Executive Verdict
MCP Server
Security · Local stdio
Quality: 65/100 (Great) | Auth: API Key required
Sonarqube MCP Server
Security · Remote HTTP/SSE
Quality: 59/100 (Good) | Auth: No auth required
Verdict Summary: Choose MCP Server if you need specialized Security tools running via a local process. Choose Sonarqube MCP Server if your workspace requires Security integration with remote web transport. Both servers can be configured concurrently in your client's mcpServers manifest.
Which MCP Server Should You Choose?
Choose MCP Server when:
You need dedicated capabilities in the Security domain.
You prefer local stdio subprocess transport architecture.
Your security boundary fits: API Key required (BYOK (Pay Provider Direct)).
MCP server for RAD Security, providing AI-powered security insights for Kubernetes and cloud environments. This server provides tools for querying the Rad Security API and retrieving security findings, reports, runtime data and many more.
An MCP server that enables integration with SonarQube Server or Cloud for code quality and security.
MCP Server is categorized under Security and uses a local stdio subprocess. In contrast, Sonarqube MCP Server belongs to Security using remote streaming HTTP/SSE transport. Select MCP Server when you need capabilities focused on security and Sonarqube MCP Server when you require tools for security.
List container images with optional filtering by page, page size, sort, and search query
list_image_vulnerabilities
List vulnerabilities in a container image with optional filtering by severity
get_top_vulnerable_images
Get the most vulnerable images from your account
get_image_sbom
Get the SBOM of a container image
ignore_cve
Ignore a CVE for this account so it no longer appears in vulnerability reporting. Use for confirmed false positives, accepted risks, or won't-fix decisions. Do NOT use for remediated CVEs — those drop off automatically on the next scan.
unignore_cve
Remove an account-wide CVE disposition, restoring the CVE to vulnerability reporting.
list_cve_dispositions
List active CVE dispositions (ignored / false positive) for this account, with reason and author.
+42 more tools listed on main page
Sonarqube MCP Server Tools (80)
analyze_code_snippet
Analyze file content with SonarQube analyzers to identify code quality and security issues. Always analyzes the complete file content for accuracy. Optionally filter results to a specific code snippet.
projectKey
The SonarQube project key - _Required String_ _(Ignored when `SONARQUBE_PROJECT_KEY` is defined)_
filePath
Project-relative path of the file to analyze (e.g., `src/main/java/MyClass.java`). Used when the workspace is mounted at `/app/mcp-workspace` - _String_
fileContent
Complete file content as a string. Required when workspace is not mounted - _String_
codeSnippet
Code snippet to filter issues (must match content in fileContent) - _String_
language
Language of the code (e.g., 'java', 'python', 'js', 'ts', 'tsx', 'jsx') - _String_
scope
Scope of the file: MAIN or TEST (default: MAIN) - _String_
analyze_file_list
Analyze files in the current working directory using SonarQube for IDE. This tool connects to a running SonarQube for IDE instance to perform code quality analysis on a list of files.
file_absolute_paths
List of absolute file paths to analyze - _Required String[]_
toggle_automatic_analysis
Enable or disable SonarQube for IDE automatic analysis. When enabled, SonarQube for IDE will automatically analyze files as they are modified in the working directory. When disabled, automatic analysis is turned off.
enabled
Enable or disable the automatic analysis - _Required Boolean_
run_advanced_code_analysis
Run Vortex analysis on a single file. Organization is inferred from MCP configuration (SonarQube Server uses the nil UUID placeholder).