← Back to directory
COMPARE UP TO 4 SERVERS

Compare MCP servers

Compare scores, permissions, risks, and fit in one decision-focused table.

DimensionAgentic Threat Hunting Framework MCP ServerMemory, structure, and agency for your threat hunting programHevy MCPManage your Hevy workout data from AI assistants via MCP.Firecrawl MCP ServerFirecrawl's official MCP server for web search, scraping, and structured extraction for AI agents
FMRS60 / 100 · C77 / 100 · B75 / 100 · B
Reliability9 / 2012 / 2013 / 20
Security and permissions13 / 2016 / 2012 / 20
Maintenance12 / 2016 / 2016 / 20
Documentation13 / 2018 / 2017 / 20
Setup experience13 / 2015 / 2017 / 20
Best for
  • Security teams wanting persistent memory and structure for threat hunting
  • Analysts using Claude Code, GitHub Copilot, or Cursor
  • Organizations wiring existing PEAK/TaHiTI processes into AI workflows
  • Hevy PRO users who want AI assistants to directly access their workout data
  • People who prefer using MCP clients like Claude, Cursor, Codex for fitness tracking
  • Anyone needing summaries and insights from their training data
  • Scenarios needing clean, structured web context fed to an AI assistant
  • Users already on the Firecrawl platform who want to call its scraping capability directly via MCP
Not for
  • Enterprises needing an authenticated multi-user remote service out of the box
  • Users expecting a replacement for their SIEM/EDR platform
  • Environments without local workspace file access
  • Users without a Hevy PRO subscription (API key required)
  • Users who want to use the server without an API key
  • Those needing delete workflows (Hevy API does not expose delete endpoints)
  • Simple static-page scraping where you don't want to depend on a third-party API and incur call costs
  • Sites that explicitly disallow automated access (robots.txt)
Required permissions
  • Read the entire ATHF workspace
  • Write/update hunt and research records
  • Some tools invoke LLM agents (at your expense)
  • Bind a local port when using sse or streamable-http transports
  • Requires HEVY_API_KEY environment variable for Hevy API authentication
  • Can create, update, and replace workouts, routines, folders, templates, and body measurements via tools
  • Read operations can fetch workouts, routines, folders, templates, history, and user info
  • Requires a Firecrawl API key to call; cost and quota are governed by the Firecrawl account
  • firecrawl_agent/firecrawl_interact perform automated browser interaction, which may trigger login or form-submission flows on the target site
Risks and side effects
  • The sse and streamable-http transports bind to 127.0.0.1 and are unauthenticated
  • Every tool reads your whole workspace, risking exposure of sensitive hunt data
  • Some tools invoke LLM agents at your expense
  • A routable interface is bound only when --host is passed, and then an authenticating proxy is required
  • API key can be misused if leaked; do not expose in URLs, logs, or screenshots
  • Create operations may produce duplicates on retry; update operations replace existing records
  • The server sends data to the Hevy API and may send telemetry to external services unless disabled
  • Bulk crawl/map tools can generate significant request volume against a target site — respect the site's rate limits and terms of service
  • firecrawl_agent's interactive action chain is longer — define task boundaries clearly before running it to avoid accidentally triggering actions on a sensitive site
Supported clientsClaude Code, GitHub Copilot, CursorClaude Desktop, Cursor, Codex, Google AntigravityClaude Desktop, VS Code, Cursor, Windsurf, Zed, Amp
Tools02611