← Back to directory
COMPARE UP TO 4 SERVERS

Compare MCP servers

Compare scores, permissions, risks, and fit in one decision-focused table.

DimensionCodeInspectus MCP ServerLocal-first MCP security scanner for AI-generated appsContext7Upstash's official server providing up-to-date third-party library docs for AI coding assistantsNPM Sentinel MCP ServerAI-powered NPM package analysis MCP server
FMRS75 / 100 · B80 / 100 · B79 / 100 · B
Reliability11 / 2014 / 2012 / 20
Security and permissions18 / 2016 / 2016 / 20
Maintenance13 / 2017 / 2018 / 20
Documentation19 / 2015 / 2018 / 20
Setup experience14 / 2018 / 2015 / 20
Best for
  • Security-conscious developers building apps with AI agents like Claude Code, Cursor, or Codex
  • Individuals and small teams who want fully offline, local code scanning with no source upload
  • Teams mapping CWE-keyed findings to code-visible compliance controls
  • Developers using fast-moving frameworks/libraries worried about the AI suggesting stale code
  • Scenarios wanting zero-config documentation lookup
  • Developers auditing NPM dependencies within AI workflows
  • Teams performing supply chain security assessments
  • Users of Claude Desktop, Cursor, or VS Code
Not for
  • Teams seeking full compliance certification or runtime security proof (the tool explicitly does neither)
  • Deep audits requiring cross-file/whole-program dataflow or runtime mobile testing
  • Restricted environments that cannot run Node.js ≥22 or install cosign and engine binaries
  • Essential Eight assessments (only ~1 of 8 mitigations is code-evidenced)
  • Looking up internal/private codebase documentation (Context7 targets publicly published open-source libraries)
  • Cases needing very high coverage of obscure, niche libraries (coverage depends on what Context7's platform has indexed)
  • Projects outside the NPM ecosystem (e.g., pure Python/Go)
  • Environments without network access to deps.dev, OSV.dev, and the npm registry
  • Scenarios requiring maintenance by an official upstream vendor
Required permissions
  • Reads project source and repository files (read-only; never edits or deletes your code)
  • Stores engine data and scan history under ~/.codeinspectus
  • Optionally writes one SBOM file (managed directory by default, or a chosen path)
  • Runs SHA-verified Opengrep/Gitleaks/Trivy binaries as local subprocesses
  • Reads git state for a git-safety recommendation; git operations require user approval and the tool never runs them itself
  • Usable without an API key (subject to a free-tier rate limit); CONTEXT7_API_KEY is an optional credential for higher quota
  • Read-only documentation lookup — no code execution or local filesystem access involved
  • Network access to the NPM registry and external services (deps.dev, OSV.dev, OpenSSF, npms.io, GitHub)
  • Read access to workspace lockfiles (pnpm-lock.yaml, package-lock., yarn.lock) for cache invalidation
Risks and side effects
  • Prompt-injection detection is heuristic and immature; findings are worded "potential …" at medium confidence
  • Fixes are applied by your AI agent and need human review; the tool only reports and never edits code
  • Native rule coverage is deliberately narrow (mostly intrafile analysis); do not infer broader coverage than executed packs report
  • Compliance mappings are AI-drafted and maintainer-reviewed with 0 of 96 community-verified — not an audit
  • Engine binaries carry supply-chain risk, mitigated via SHA pinning, though setup/repair still downloads over the network
  • The free tier has limited quota — high-frequency use may hit rate limits
  • Documentation content comes from Context7's platform index, so its accuracy and freshness depend on that platform's crawl cadence
  • Third-party READMEs and changelogs are untrusted external content; they are wrapped in tags with _meta flags but should still be handled cautiously
  • Depends on availability and accuracy of external services
  • Batch requests are capped at 25 packages to prevent registry enumeration; larger sets require batching
  • Third-party open source project, not officially maintained by NPM or Anthropic
Supported clientsClaude Code, Cursor, VS Code, Codex, Windsurf, Cline, AiderClaude Code, VS Code, Cursor, Cline, AmpClaude Desktop, VS Code, Cursor, Smithery.ai
Tools6219