Skip to main content
AllMCPs
BrowseBestCategoriesStackCompareToolsGuidesBlog
Log in Submit MCP

Stay in the loop

Get new MCP servers and top picks in your inbox.

AllMCPs

The open directory for discovering and installing Model Context Protocol servers.

AllMCPs on GitHub (opens in a new tab)
Launched onTiny Startupstinystartups.com
Explore
  • Browse servers
  • Best MCP servers
  • Categories
  • MCP clients
  • Agent prompts
  • Stack Builder
  • Compare servers
  • Random discovery New
  • Submit a server
  • Pricing & Boost Boost
Learn
  • Guides hub
  • What is MCP?
  • Install guide
  • Build an MCP server
  • Deploy an MCP server
  • Security guide
  • Troubleshooting
  • MCP for SEO & AEO
  • Protocol versioning
  • Transports: stdio vs HTTP
  • State of MCP (stats)
  • Blog & updates
Tools
  • All developer tools
  • Config generator
  • Config validator
  • Config auditor
  • MCP playground
  • Token calculator
  • OpenAPI → MCP
  • Badge generator
For agents
  • REST API docs
  • Trust & traffic Live
  • Remote MCP server SSE ↗ (opens in a new tab)
  • llms.txt ↗ (opens in a new tab)
  • Catalog JSON ↗ (opens in a new tab)
Company
  • About
  • Advertise Sponsor
  • Contact
  • GitHub ↗ (opens in a new tab)
  • Terms
  • Privacy
AllMCPs VerifiedAllMCPs VerifiedFeatured on Nick LaunchesFeatured on Nick LaunchesLaunch Llama NewsletterLaunch Llama NewsletterVerified DR - allmcps.comVerified DR - allmcps.comFeatured on SaaSGrowFeatured on SaaSGrowFeatured on Twelve ToolsFeatured on Twelve ToolsFeatured on Saaspa.geFeatured on Saaspa.geFeatured on Findly.toolsFeatured on Findly.toolsFeatured on Startup FameFeatured on Startup FameFeatured on LaunchKiwiFeatured on LaunchKiwiFeatured on ScrollLaunchFeatured on ScrollLaunchFeatured on DailyPingsFeatured on DailyPingsFazier badgeFazier badgeFeatured on NewTool.siteFeatured on NewTool.siteFeatured on saasfame.comFeatured on saasfame.comDR Checker - Domain RatingDR Checker - Domain RatingListed on Turbo0Listed on Turbo0Launched on LaunchBoard - Product Launch PlatformLaunched on LaunchBoard - Product Launch PlatformList on SimilarlabsList on Similarlabshttps://codetrendy.comhttps://codetrendy.comListed on DevTool.ioFeatured on BuildlistFeatured on BuildlistLaunched on Tiny StartupsFeatured on ShowMeBestAIFeatured on ShowMeBestAIFind us on LaunchZoneFind us on LaunchZoneAllMCPs VerifiedAllMCPs VerifiedFeatured on Nick LaunchesFeatured on Nick LaunchesLaunch Llama NewsletterLaunch Llama NewsletterVerified DR - allmcps.comVerified DR - allmcps.comFeatured on SaaSGrowFeatured on SaaSGrowFeatured on Twelve ToolsFeatured on Twelve ToolsFeatured on Saaspa.geFeatured on Saaspa.geFeatured on Findly.toolsFeatured on Findly.toolsFeatured on Startup FameFeatured on Startup FameFeatured on LaunchKiwiFeatured on LaunchKiwiFeatured on ScrollLaunchFeatured on ScrollLaunchFeatured on DailyPingsFeatured on DailyPingsFazier badgeFazier badgeFeatured on NewTool.siteFeatured on NewTool.siteFeatured on saasfame.comFeatured on saasfame.comDR Checker - Domain RatingDR Checker - Domain RatingListed on Turbo0Listed on Turbo0Launched on LaunchBoard - Product Launch PlatformLaunched on LaunchBoard - Product Launch PlatformList on SimilarlabsList on Similarlabshttps://codetrendy.comhttps://codetrendy.comListed on DevTool.ioFeatured on BuildlistFeatured on BuildlistLaunched on Tiny StartupsFeatured on ShowMeBestAIFeatured on ShowMeBestAIFind us on LaunchZoneFind us on LaunchZone
© 2026 Jackalope Digital LLC. All rights reserved.
  1. Home
  2. Browse
  3. Sast MCP Server
  4. vs Agentforge Trust MCP
Side-by-Side Model Context Protocol Comparison

Sast MCP Server vs Agentforge Trust MCP

In-depth architectural comparison of the Sast MCP Server and Agentforge Trust MCP MCP servers. Compare execution transports, security boundaries, tool capabilities, quality scores, and ready-to-paste client installation snippets for Claude, Cursor, Windsurf, and VS Code.

At a Glance & Executive Verdict

Sast MCP Server
Security · Local stdio
Quality: 57/100 (Good) | Auth: API Key required
Agentforge Trust MCP
Security · Local stdio
Quality: 55/100 (Good) | Auth: API Key required
Verdict Summary: Choose Sast MCP Server if you need specialized Security tools running via a local process. Choose Agentforge Trust MCP if your workspace requires Security integration with local subprocess execution. Both servers can be configured concurrently in your client's mcpServers manifest.

Which MCP Server Should You Choose?

Sast MCP Server logo

Choose Sast MCP Server when:

  • You need dedicated capabilities in the Security domain.
  • You prefer local stdio subprocess transport architecture.
  • Your security boundary fits: API Key required (Free / Open Source).
  • You have access to required keys: DEFECTDOJO_URL, GITHUB_TOKEN, JIRA_URL, JIRA_EMAIL, JIRA_API_TOKEN.
  • Primary tools included: scan_vulnerabilities, ignore_vulnerability, unignore_vulnerability.
Explore Sast MCP Server Details
Agentforge Trust MCP logo

Choose Agentforge Trust MCP when:

  • You need dedicated capabilities in the Security domain.
  • You prefer local stdio subprocess transport architecture.
  • Your security boundary fits: API Key required (Freemium).
  • Primary tools included: check_trust, evaluate_policy, list_trusted.

Feature & Specification Comparison

Specification
Sast MCP Server logo
Sast MCP Server
Skyrxin
Security
Agentforge Trust MCP logo
Agentforge Trust MCP
KOVY
Security
SummarySAST/DAST server exposing 11 security scanners (Bandit, Semgrep, Trivy, CodeQL, Checkov, Gitleaks, OSV-Scanner, Grype, OWASP ZAP, and more) with closed-loop remediation (scan→patch→re-scan→verify), SARIF/SBOM/VEX export, compliance reporting, and CI integrations (GitHub Advanced Security, DefectDojo, Slack, Jira).Query the AgentForge Trust Score (0-100 across five dimensions: security, code health, behavioral audit, community trust, EU compliance) for any MCP server before connecting. Exposes checktrust, evaluatepolicy, listtrusted, and recommend tools. 3,600+ servers audited, free public API.
Category & Scope

Tools & Capabilities Breakdown

Sast MCP Server Tools (27)

scan_vulnerabilities
Scan a target directory for security vulnerabilities using a SAST tool.
ignore_vulnerability
Ignore a specific vulnerability finding so it won't appear in future scans.
unignore_vulnerability
Remove a vulnerability from the ignore list so it appears in future scans again.
list_scanners
List all available SAST scanners, their status, and supported languages. Returns information about each scanner including whether it is installed and ready to use, what languages it supports, and how to install it.
list_ignored_vulnerabilities
List all currently ignored vulnerability findings for a project.

Ready-to-Paste Client Configurations

Paste either (or both) of these JSON server blocks into your client config file (e.g. claude_desktop_config.json or ~/.cursor/mcp.json).

Sast MCP Server Configuration
mcpServers (Claude Desktop / Cursor)
{
  "mcpServers": {
    "skyrxin-sast-mcp-server": {
      "command": "uvx",
      "args": [
        "sast-mcp-server"
      ],
      "env": {
        "DEFECTDOJO_URL": "YOUR_DEFECTDOJO_URL_HERE",
        "GITHUB_TOKEN": "YOUR_GITHUB_TOKEN_HERE",
        "JIRA_URL": "YOUR_JIRA_URL_HERE",
        "JIRA_EMAIL": "YOUR_JIRA_EMAIL_HERE",
        "JIRA_API_TOKEN": "YOUR_JIRA_API_TOKEN_HERE"
      }
    }
  }
}
Agentforge Trust MCP Configuration
mcpServers (Claude Desktop / Cursor)
{
  "mcpServers": {
    "kovy-agentforge-trust-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "agentforge-trust-mcp@latest"
      ]
    }
  }
}

Frequently Asked Questions

Sast MCP Server is categorized under Security and uses a local stdio subprocess. In contrast, Agentforge Trust MCP belongs to Security using local stdio subprocess. Select Sast MCP Server when you need capabilities focused on security and Agentforge Trust MCP when you require tools for security.

More alternatives to Sast MCP ServerMore alternatives to Agentforge Trust MCPSecurity category hubCanonical compare URL

Related MCP Server Comparisons

Popular comparisons with Sast MCP Server

  • Guardvibe logoSast MCP Server vs Guardvibe
  • Mobb Vibe Shield MCP logoSast MCP Server vs Mobb Vibe Shield MCP
  • Codeinspectus logoSast MCP Server vs Codeinspectus
  • Vulnfeed MCP logoSast MCP Server vs Vulnfeed MCP

Popular comparisons with Agentforge Trust MCP

Explore Agentforge Trust MCP Details
Security
Security
Quality signal57/100 (Good)55/100 (Good)
Transport ProtocolLocal Subprocess (stdio)Local Subprocess (stdio)
Auth RequirementAPI Key requiredAPI Key required
Pricing ModelFree / Open SourceFreemium
Required Env Vars
DEFECTDOJO_URLGITHUB_TOKENJIRA_URLJIRA_EMAILJIRA_API_TOKEN
None required
Compatible Clients
Claude DesktopCursorWindsurfClineVS Code
Claude DesktopCursorWindsurfClineVS Code
Install path signaluvx · highnpx · high
Engagement & Health 2 views 0 copies 0 upvotes 3 stars 2 views 0 copies 0 upvotes 1 stars
Verified / OfficialCommunity ListingCommunity Listing
Open full listingView Sast MCP Server ListingView Agentforge Trust MCP Listing
scan_git_history
Scan the entire git history for leaked secrets and credentials using Gitleaks. Traditional SAST only scans the current state of files. This tool deeply analyzes the `.git` directory to find API keys, passwords, and tokens that were committed in the past but may still be valid.
run_active_scan
Run an active dynamic scan (DAST) using OWASP ZAP. Unlike SAST which only looks at code, this orchestrates spinning up the application via Docker Compose, waiting for it to be ready, and then running a ZAP dynamic baseline scan against the running instance.
export_sarif
Run a SAST scan and export results in SARIF 2.1.0 format for CI/CD integration. SARIF is the industry standard format consumed by GitHub Code Scanning, GitLab SAST, Azure DevOps, and other CI/CD platforms.
scan_all
Scan with ALL installed scanners in parallel, returning deduplicated results. Automatically detects which scanners are installed, runs them concurrently, and deduplicates findings across scanners using content-based hashing. This is the recommended tool for comprehensive security scanning.
scan_image
Scan a container image for vulnerabilities and secrets. Pulls and analyzes a container image reference (e.g. `nginx:1.25`, `ghcr.io/org/app@sha256:...`) with Trivy or Grype, returning the same normalized findings as a source scan.
save_baseline
Run a scan and save the results as a named baseline for future comparison.
compare_baseline
Compare current scan results against a saved baseline. Shows new vulnerabilities, fixed vulnerabilities, and severity trends.
+15 more tools listed on main page

Agentforge Trust MCP Tools (8)

check_trust
Fetch the AgentForge Trust Score for an MCP server. Returns the overall score (0-100), per-dimension breakdown (code_health, security_scan, behavioral_audit, community_trust, eu_compliance), and badges. Use before connecting to any MCP server.
evaluate_policy
Check whether a server passes a trust policy. Returns allowed:true/false plus individual check results. Example policy: {min_overall: 70, required_badges: ['actively_maintained']}. Use this to gate agent decisions like 'should I use this server for financial data?'.
list_trusted
Search AgentForge catalog for servers matching a category and minimum trust threshold. Returns up to 25 results sorted by trust score.
recommend
Given a natural-language use case, recommend MCP servers filtered by trust. Example: 'I need to validate Czech VAT IDs and convert ISDOC invoices'. Uses AgentForge semantic search + trust filter.
discover
Browse the AgentForge catalog of MCP servers. Supports full-text search, semantic search, and category filtering. No authentication required. Use this when you need to find servers offering a specific capability (e.g. 'GitHub PR automation', 'EU VAT validation'). Returns server metadata, tool counts, pricing tier, and trust scores. Each result carries TWO trust fields: `audit_score` (0-100, dynamic from the AgentForge audit pipeline — AUTHORITATIVE for policy gating, may be null if not yet audited) and `trust_score` (0-10, legacy community rating — for display fallback only). Always prefer audit_score when present; treat null audit_score as 'audit pending'.
broadcast_search
Search ACROSS multiple MCP servers in a single call. Returns relevant tools per server, sorted by relevance. Replaces N sequential discover+capabilities calls. Requires AGENTFORGE_API_KEY (set in env or call register_agent first). Use this when an agent needs to fan out a query like 'find me anything that can parse DICOM medical images' across the catalog.
call_tool
Invoke any tool on any MCP server in the AgentForge catalog. AgentForge proxies the call, applies rate limits, billing (per-call or wallet credits), and returns the result. Requires AGENTFORGE_API_KEY. Use this to actually USE a server's capability after discovery, e.g. call_tool(server='github-pro', tool='create_pr', input={...}).
register_agent
Self-register this agent with AgentForge. Returns an af_agent_* API key that unlocks broadcast_search and call_tool. Run once at agent startup, store the key in env as AGENTFORGE_API_KEY. No auth required for registration. Idempotent on slug — running twice produces a uniqued slug.
Agentgraph logo
Agentforge Trust MCP vs Agentgraph
  • Agentward logoAgentforge Trust MCP vs Agentward
  • Agntor MCP logoAgentforge Trust MCP vs Agntor MCP
  • MCP Audit logoAgentforge Trust MCP vs MCP Audit