← Back to directory
COMPARE UP TO 4 SERVERS

Compare MCP servers

Compare scores, permissions, risks, and fit in one decision-focused table.

DimensionRLM Tools BSL MCP ServerToken-efficient analysis MCP server for 1C (BSL) codebasesContext7Upstash's official server providing up-to-date third-party library docs for AI coding assistantsNPM Sentinel MCP ServerAI-powered NPM package analysis MCP server
FMRS60 / 100 · C80 / 100 · B79 / 100 · B
Reliability10 / 2014 / 2012 / 20
Security and permissions9 / 2016 / 2016 / 20
Maintenance12 / 2017 / 2018 / 20
Documentation16 / 2015 / 2018 / 20
Setup experience13 / 2018 / 2015 / 20
Best for
  • 1C:Enterprise projects with CF, EDT, or MDO source formats
  • Large configurations with 20K+ files that cannot fit into a single session context
  • Deterministic codebase questions, e.g. finding an HTTP service and its methods or how a document posting routine works
  • Teams that want to save context and tokens and avoid maintaining RAG infrastructure
  • Developers using fast-moving frameworks/libraries worried about the AI suggesting stale code
  • Scenarios wanting zero-config documentation lookup
  • Developers auditing NPM dependencies within AI workflows
  • Teams performing supply chain security assessments
  • Users of Claude Desktop, Cursor, or VS Code
Not for
  • Scenarios needing a complete dependency graph of all configuration objects (requires a pre-indexed RAG/graph MCP)
  • Semantic/embedding search over object descriptions
  • Vague, non-deterministic questions like 'how does budgeting work in ERP' or 'how do cellular warehouses work in UT', which need full RAG or a strong model to turn them into strict queries
  • Treating it as an official 1C product: it is not maintained by 1C
  • Looking up internal/private codebase documentation (Context7 targets publicly published open-source libraries)
  • Cases needing very high coverage of obscure, niche libraries (coverage depends on what Context7's platform has indexed)
  • Projects outside the NPM ecosystem (e.g., pure Python/Go)
  • Environments without network access to deps.dev, OSV.dev, and the npm registry
  • Scenarios requiring maintenance by an official upstream vendor
Required permissions
  • Read 1C source directories (BSL files, XML/MDO descriptions, metadata)
  • Write and manage SQLite index files on the host
  • Read and modify the projects.json registry next to the server directory (mutating operations require a password)
  • Execute agent-submitted Python scripts inside a sandbox
  • Optional access to an LLM endpoint (OpenAI-compatible OpenRouter, Ollama, vLLM, or the Anthropic API), only when llm_query is configured
  • Optional use of Git on the host to read the source repository (enables git_search)
  • Usable without an API key (subject to a free-tier rate limit); CONTEXT7_API_KEY is an optional credential for higher quota
  • Read-only documentation lookup — no code execution or local filesystem access involved
  • Network access to the NPM registry and external services (deps.dev, OSV.dev, OpenSSF, npms.io, GitHub)
  • Read access to workspace lockfiles (pnpm-lock.yaml, package-lock., yarn.lock) for cache invalidation
Risks and side effects
  • Agent-submitted Python scripts are executed in a sandbox whose real strength determines the host's exposure surface
  • A .git directory in the sources automatically enables git grep full-text search over all files, which may surface 'raw' XML/MDO and text content developers did not expect to expose
  • When llm_query is configured, script content or code fragments may be sent to an external LLM endpoint
  • The registry password protects mutating operations to stop the AI acting without confirmation, but it is not strong encryption or isolation
  • Indexing is slow on HDDs or network shares, and indexes persist code content read from disk
  • The free tier has limited quota — high-frequency use may hit rate limits
  • Documentation content comes from Context7's platform index, so its accuracy and freshness depend on that platform's crawl cadence
  • Third-party READMEs and changelogs are untrusted external content; they are wrapped in tags with _meta flags but should still be handled cautiously
  • Depends on availability and accuracy of external services
  • Batch requests are capped at 25 packages to prevent registry enumeration; larger sets require batching
  • Third-party open source project, not officially maintained by NPM or Anthropic
Supported clientsClaude Code, Kilo Code, Roo Code, CursorClaude Code, VS Code, Cursor, Cline, AmpClaude Desktop, VS Code, Cursor, Smithery.ai
Tools6219