← Back to directory
COMPARE UP TO 4 SERVERS

Compare MCP servers

Compare scores, permissions, risks, and fit in one decision-focused table.

DimensionDarknet MCP ServerFull-spectrum dark web and threat intelligence for AI agentsHevy MCPManage your Hevy workout data from AI assistants via MCP.Firecrawl MCP ServerFirecrawl's official MCP server for web search, scraping, and structured extraction for AI agents
FMRS51 / 100 · D77 / 100 · B75 / 100 · B
Reliability9 / 2012 / 2013 / 20
Security and permissions5 / 2016 / 2012 / 20
Maintenance11 / 2016 / 2016 / 20
Documentation14 / 2018 / 2017 / 20
Setup experience12 / 2015 / 2017 / 20
Best for
  • Authorized security assessment, incident response and threat intelligence teams
  • AI agent workflows that need multi-source intelligence correlated in a single conversation
  • Analysts wanting ransomware and breach listing data without configuring API keys
  • Users already running the companion security MCP servers (hackbrowser-mcp, cve-mcp, osint-mcp-server, etc.)
  • Hevy PRO users who want AI assistants to directly access their workout data
  • People who prefer using MCP clients like Claude, Cursor, Codex for fitness tracking
  • Anyone needing summaries and insights from their training data
  • Scenarios needing clean, structured web context fed to an AI assistant
  • Users already on the Firecrawl platform who want to call its scraping capability directly via MCP
Not for
  • Users performing intelligence gathering on third-party targets without authorization
  • Users who expect every tool to work out of the box (several require paid or requested API keys)
  • Users needing Ethereum or Monero blockchain data (Bitcoin only)
  • Users needing officially supported Windows operation (only macOS / Linux are tested)
  • Users without a Hevy PRO subscription (API key required)
  • Users who want to use the server without an API key
  • Those needing delete workflows (Hevy API does not expose delete endpoints)
  • Simple static-page scraping where you don't want to depend on a third-party API and incur call costs
  • Sites that explicitly disallow automated access (robots.txt)
Required permissions
  • Read third-party API keys from environment variables (HIBP, IntelligenceX, OTX, AbuseIPDB, abuse.ch, Pulsedive, Hudson Rock, Vulners, Hybrid Analysis, PhishTank)
  • Communicate with a local Tor daemon over the local SOCKS5 port (default 127.0.0.1:9050)
  • Make outbound HTTPS requests to 16 external data sources
  • Install locally and run a process over stdio via npx / Bun
  • Requires HEVY_API_KEY environment variable for Hevy API authentication
  • Can create, update, and replace workouts, routines, folders, templates, and body measurements via tools
  • Read operations can fetch workouts, routines, folders, templates, history, and user info
  • Requires a Firecrawl API key to call; cost and quota are governed by the Firecrawl account
  • firecrawl_agent/firecrawl_interact perform automated browser interaction, which may trigger login or form-submission flows on the target site
Risks and side effects
  • Dark web intelligence gathering is legally and compliance sensitive — proper authorization is essential
  • Tor .onion tools leak DNS if attribution is not routed through the proxy; the project mitigates this with socks5h but users should verify their proxy setup
  • API keys live in plain environment variables and could leak into logs or config files
  • Tor-dependent tools are unavailable without a local Tor daemon
  • Free tiers have low rate limits, so bulk queries may be throttled
  • Upstream sources (e.g. ransomware.live, RansomLook, PhishTank) depend on scraping frequency, so data may lag or be incomplete
  • All content returned by external sources is untrusted input and should not be executed as instructions
  • API key can be misused if leaked; do not expose in URLs, logs, or screenshots
  • Create operations may produce duplicates on retry; update operations replace existing records
  • The server sends data to the Hevy API and may send telemetry to external services unless disabled
  • Bulk crawl/map tools can generate significant request volume against a target site — respect the site's rate limits and terms of service
  • firecrawl_agent's interactive action chain is longer — define task boundaries clearly before running it to avoid accidentally triggering actions on a sensitive site
Supported clientsClaude Code, Claude Desktop, Cursor, WindsurfClaude Desktop, Cursor, Codex, Google AntigravityClaude Desktop, VS Code, Cursor, Windsurf, Zed, Amp
Tools662611