Side-by-side comparison of two Model Context Protocol servers — install paths, tools, quality signals, and directory engagement so you can pick the right one for Claude, Cursor, and other MCP clients.
vet-mcp checks open source packages—like those suggested by AI coding tools—for vulnerabilities and malicious code. It supports npm and PyPI, and runs locally via Docker or as a standalone binary for fast, automated vetting.
Transparent Go proxy that intercepts, signs, rate-limits, redacts, and audits all MCP JSON-RPC tool calls without modifying client or server.
Quality signal
52/100 (Fair)
51/100 (Fair)
Install path
Remote · high
npx · high
Engagement
3 0 0 1,096
2 0 0 7
Tools
Real-time malicious package detection via SafeDep CloudVulnerability analysis based on dependency usage evidencePolicy-as-code enforcement with CEL expressionsSupports npm, PyPI, Maven, Go, Ruby, Rust, PHP ecosystemsScans container images and SBOMsOutputs actionable reports in multiple formats
Transparent proxy for MCP JSON-RPC trafficSigned audit trail generationPayload redaction of sensitive dataAllow/deny policy enforcementPer-tool rate limitingLocal read-only dashboard and Prometheus metrics