Field-by-field comparison
Compare the evidence before choosing an MCP.
Each signal stays separate, missing facts remain visible, and the column order follows your selection.
| Evidence field | MCP InspectorMCP100 Selected | CVE MCP ServerMCP100 Selected |
|---|---|---|
| Task fit | ||
| Best for |
|
|
| Not ideal for |
|
|
| Avoid when |
|
|
| Provenance | ||
| Provenance details | First-party MCP Model Context Protocol project · Publisher source ↗ | Community implementation github:mukul975 · Publisher source ↗ |
| Maintenance | ||
| Maintenance details | Repo: Sep 11, 2026 Package: Not documented | Repo: Aug 5, 2026 Package: Not documented |
| Popularity evidence | ||
| GitHub stars | 10,862 GitHub stars · checked 2026-09-11 | 1,132 GitHub stars · checked 2026-08-14T18:46:26.000Z |
| Package downloads / 30 days | No reliable download data | 42 package downloads / 30 days · checked 2026-09-08 |
| Client coverage | ||
| Client coverage details | Not documented | Claude Code✓ Local stdio Claude Desktop✓ Local stdio Codex✓ Local stdio VS Code✓ Local stdio Cursor✓ Local stdio OpenCode✓ Local stdio |
| Client coverage note | Local stdio runs on your computer. Streamable HTTP connects to a remotely hosted MCP server. | |
| Access and data | ||
| Authentication | Inspector itself is a local developer tool; target-server authentication depends on the server and connection configuration. | Optional provider API keys are supplied through environment variables, while many sources work without keys. MCP HTTP client authentication is not documented. |
| Cost | Open-source tool; any target APIs or services may have separate costs. | The open-source server lists many free or no-key sources. Optional provider APIs can impose separate charges or limits; no complete service price is documented. |
| Permissions | It can list and invoke capabilities exposed by the target MCP server, so effective privileges are those of the connected server credentials. | Queries CVE, IP, domain, hash, package, malware, threat-intelligence, and code-search providers; maintains local cache and audit data. URLScan submission is the documented write-like exception. |
| Data handling | Inputs and outputs from the target MCP server are visible in the inspection workflow; sensitive target data may therefore appear in the UI/session. | CVE IDs, IPs, hashes, domains, and package names can be sent to external APIs, and responses are cached in local SQLite. The publisher says API keys and response payloads are excluded from audit logs; no telemetry and no inbound ports are documented. |
| Limitations | ||
| Tradeoffs |
|
|
| Risk context | High operational caution. Use test accounts or isolated environments when inspecting unknown or write-capable servers; do not assume rollback or sandboxing. | Broad external intelligence fan-out sends queried indicators off-host; URLScan can submit URLs, and HTTP mode can expose a service endpoint. Keep queries non-sensitive where possible, preserve the documented private-IP blocking, and restrict HTTP exposure. |
| Evidence date | ||
| Editorial review | 2026-09-11 | 2026-08-11 |
| Candidate evidence | 2026-09-11T00:00:00.000Z | 2026-08-14T18:46:26.000Z |
Popularity, maintenance, fit, permissions, and client support are independent evidence fields.
Read the evidence method →