Field-by-field comparison
Compare the evidence before choosing an MCP.
Each signal stays separate, missing facts remain visible, and the column order follows your selection.
| Evidence field | badchars-darknet-mcp-serverWatchlist candidate | CVE MCP ServerMCP100 Selected |
|---|---|---|
| Task fit | ||
| Best for |
|
|
| Not ideal for |
|
|
| Avoid when |
|
|
| Provenance | ||
| Provenance details | Community implementation github:badchars · Publisher source ↗ | Community implementation github:mukul975 · Publisher source ↗ |
| Maintenance | ||
| Maintenance details | Repo: Aug 11, 2026 Package: Not documented | Repo: Aug 5, 2026 Package: Not documented |
| Popularity evidence | ||
| GitHub stars | 307 GitHub stars · checked 2026-08-14T18:46:26.000Z | 1,132 GitHub stars · checked 2026-08-14T18:46:26.000Z |
| External adoption evidence |
|
|
| Client coverage | ||
| Client coverage details | Claude Code✓ Local stdio Claude Desktop✓ Local stdio Codex✓ Local stdio VS Code✓ Local stdio Cursor✓ Local stdio OpenCode✓ Local stdio | Claude Code✓ Local stdio Claude Desktop✓ Local stdio Codex✓ Local stdio VS Code✓ Local stdio Cursor✓ Local stdio OpenCode✓ Local stdio |
| Client coverage note | Local stdio runs on your computer. Streamable HTTP connects to a remotely hosted MCP server. | |
| Access and data | ||
| Authentication | Provider API keys are optional environment variables for selected tools. MCP client authentication is not documented. | Optional provider API keys are supplied through environment variables, while many sources work without keys. MCP HTTP client authentication is not documented. |
| Cost | The server has no documented project price. The README lists HIBP account and paste search as requiring a paid API key at $3.50 per month; other provider costs and limits vary. | The open-source server lists many free or no-key sources. Optional provider APIs can impose separate charges or limits; no complete service price is documented. |
| Permissions | Performs OSINT and threat-intelligence lookups, clearnet and onion fetch, scrape, and search, breach and stealer-log queries, malware intelligence, and blockchain, domain, and IP checks. | Queries CVE, IP, domain, hash, package, malware, threat-intelligence, and code-search providers; maintains local cache and audit data. URLScan submission is the documented write-like exception. |
| Data handling | Queries and indicators can be sent to external providers; outputs can include breach, stealer-log, and dark-web data. The README documents Tor SOCKS5H routing, local TTL caching, and HIBP password k-anonymity with only a five-character SHA-1 prefix sent. | CVE IDs, IPs, hashes, domains, and package names can be sent to external APIs, and responses are cached in local SQLite. The publisher says API keys and response payloads are excluded from audit logs; no telemetry and no inbound ports are documented. |
| Limitations | ||
| Tradeoffs |
|
|
| Risk context | Sensitive breach, credential, malware, and dark-web intelligence crosses external providers and Tor infrastructure. Minimize submitted identifiers, protect provider keys, and handle retrieved sensitive data under an explicit retention policy. | Broad external intelligence fan-out sends queried indicators off-host; URLScan can submit URLs, and HTTP mode can expose a service endpoint. Keep queries non-sensitive where possible, preserve the documented private-IP blocking, and restrict HTTP exposure. |
| Evidence date | ||
| Editorial review | 2026-08-11 | 2026-08-11 |
| Candidate evidence | 2026-08-14T18:46:26.000Z | 2026-08-14T18:46:26.000Z |
Popularity, maintenance, fit, permissions, and client support are independent evidence fields.
Read the evidence method →