Sast MCP Server vs Osv Ui — MCP Server Comparison | AllMCPs
Side-by-Side Model Context Protocol Comparison
Sast MCP Server vs Osv Ui
In-depth architectural comparison of the Sast MCP Server and Osv Ui MCP servers. Compare execution transports, security boundaries, tool capabilities, quality scores, and ready-to-paste client installation snippets for Claude, Cursor, Windsurf, and VS Code.
At a Glance & Executive Verdict
Sast MCP Server
Security · Local stdio
Quality: 57/100 (Good) | Auth: API Key required
Osv Ui
Security · Local stdio
Quality: 60/100 (Good) | Auth: No auth required
Verdict Summary: Choose Sast MCP Server if you need specialized Security tools running via a local process. Choose Osv Ui if your workspace requires Security integration with local subprocess execution. Both servers can be configured concurrently in your client's mcpServers manifest.
Which MCP Server Should You Choose?
Choose Sast MCP Server when:
You need dedicated capabilities in the Security domain.
You prefer local stdio subprocess transport architecture.
Your security boundary fits: API Key required (Free / Open Source).
You have access to required keys: DEFECTDOJO_URL, GITHUB_TOKEN, JIRA_URL, JIRA_EMAIL, JIRA_API_TOKEN.
SAST/DAST server exposing 11 security scanners (Bandit, Semgrep, Trivy, CodeQL, Checkov, Gitleaks, OSV-Scanner, Grype, OWASP ZAP, and more) with closed-loop remediation (scan→patch→re-scan→verify), SARIF/SBOM/VEX export, compliance reporting, and CI integrations (GitHub Advanced Security, DefectDojo, Slack, Jira).
Visual CVE audit dashboard for npm, Python, Go, and Rust. Scan from Claude/Cursor, opens a browser UI for human review (human-in-the-loop), applies fixes with explicit confirmation. Powered by OSV.dev.
Category & Scope
Tools & Capabilities Breakdown
Sast MCP Server Tools (27)
scan_vulnerabilities
Scan a target directory for security vulnerabilities using a SAST tool.
ignore_vulnerability
Ignore a specific vulnerability finding so it won't appear in future scans.
unignore_vulnerability
Remove a vulnerability from the ignore list so it appears in future scans again.
list_scanners
List all available SAST scanners, their status, and supported languages.
Returns information about each scanner including whether it is installed
and ready to use, what languages it supports, and how to install it.
list_ignored_vulnerabilities
List all currently ignored vulnerability findings for a project.
Ready-to-Paste Client Configurations
Paste either (or both) of these JSON server blocks into your client config file (e.g. claude_desktop_config.json or ~/.cursor/mcp.json).
Sast MCP Server is categorized under Security and uses a local stdio subprocess. In contrast, Osv Ui belongs to Security using local stdio subprocess. Select Sast MCP Server when you need capabilities focused on security and Osv Ui when you require tools for security.
Scan the entire git history for leaked secrets and credentials using Gitleaks.
Traditional SAST only scans the current state of files. This tool deeply
analyzes the `.git` directory to find API keys, passwords, and tokens
that were committed in the past but may still be valid.
run_active_scan
Run an active dynamic scan (DAST) using OWASP ZAP.
Unlike SAST which only looks at code, this orchestrates spinning up the
application via Docker Compose, waiting for it to be ready, and then
running a ZAP dynamic baseline scan against the running instance.
export_sarif
Run a SAST scan and export results in SARIF 2.1.0 format for CI/CD integration.
SARIF is the industry standard format consumed by GitHub Code Scanning,
GitLab SAST, Azure DevOps, and other CI/CD platforms.
scan_all
Scan with ALL installed scanners in parallel, returning deduplicated results.
Automatically detects which scanners are installed, runs them concurrently,
and deduplicates findings across scanners using content-based hashing.
This is the recommended tool for comprehensive security scanning.
scan_image
Scan a container image for vulnerabilities and secrets.
Pulls and analyzes a container image reference (e.g. `nginx:1.25`,
`ghcr.io/org/app@sha256:...`) with Trivy or Grype, returning the same
normalized findings as a source scan.
save_baseline
Run a scan and save the results as a named baseline for future comparison.
compare_baseline
Compare current scan results against a saved baseline.
Shows new vulnerabilities, fixed vulnerabilities, and severity trends.
+15 more tools listed on main page
Osv Ui Tools (4)
scan_project
Scan a project directory for CVE vulnerabilities. Automatically detects npm, Python, Go, Rust, Java/Maven, PHP/Composer, and Ruby/Bundler manifests. Queries live CVE data from OSV.dev. Returns structured vulnerability report with severity counts, risk score, and fix recommendations. Use this as the first step before open_dashboard or apply_fixes.
open_dashboard
Launch the osv-ui visual dashboard in the browser for human review. This is the HUMAN-IN-THE-LOOP step — always offer this before applying fixes. The dashboard shows full CVE details, severity charts, and the upgrade guide. Returns the dashboard URL. If already running for this path, returns existing URL.
get_fix_commands
Get the safe upgrade commands for vulnerable packages WITHOUT executing them. Use this to show the user what will be changed before calling apply_fixes. Returns a list of commands grouped by ecosystem (npm, pip, go, cargo, Maven, Composer, Bundler).
apply_fixes
Execute package upgrade commands to fix CVEs. IMPORTANT: This is a DESTRUCTIVE action that modifies package files. ALWAYS call get_fix_commands first and confirm with the user before calling this. Returns the command output for each fix applied.