Field-by-field comparison
Compare the evidence before choosing an MCP.
Each signal stays separate, missing facts remain visible, and the column order follows your selection.
| Evidence field | CVE MCP ServerMCP100 Selected | semgrepMCP100 Selected |
|---|---|---|
| Task fit | ||
| Best for |
|
|
| Not ideal for |
|
|
| Avoid when |
|
|
| Provenance | ||
| Provenance details | Community implementation github:mukul975 · Publisher source ↗ | First-party MCP ecosystem:semgrep · Publisher source ↗ |
| Maintenance | ||
| Maintenance details | Repo: Aug 5, 2026 Package: Not documented | Repo: Aug 14, 2026 Package: Not documented |
| Popularity evidence | ||
| GitHub stars | 1,132 GitHub stars · checked 2026-08-14T18:46:26.000Z | 16,224 GitHub stars · checked 2026-08-14T18:46:26.000Z |
| External adoption evidence |
|
|
| Client coverage | ||
| Client coverage details | Claude Code✓ Local stdio Claude Desktop✓ Local stdio Codex✓ Local stdio VS Code✓ Local stdio Cursor✓ Local stdio OpenCode✓ Local stdio | Claude Code✓ Local stdio Claude Desktop✓ Local stdio Codex✓ Local stdio VS Code✓ Local stdio Cursor✓ Local stdio OpenCode✓ Local stdio |
| Client coverage note | Local stdio runs on your computer. Streamable HTTP connects to a remotely hosted MCP server. | |
| Access and data | ||
| Authentication | Optional provider API keys are supplied through environment variables, while many sources work without keys. MCP HTTP client authentication is not documented. | Local scanning needs no remote credential; platform features use Semgrep authentication. |
| Cost | The open-source server lists many free or no-key sources. Optional provider APIs can impose separate charges or limits; no complete service price is documented. | The MCP integration has no separately verified MCP100 price conclusion. Publisher subscriptions, API usage, compute, storage, and AI-client charges may apply. |
| Permissions | Queries CVE, IP, domain, hash, package, malware, threat-intelligence, and code-search providers; maintains local cache and audit data. URLScan submission is the documented write-like exception. | Local filesystem scope and optional Semgrep AppSec Platform token permissions define accessible code and findings. |
| Data handling | CVE IDs, IPs, hashes, domains, and package names can be sent to external APIs, and responses are cached in local SQLite. The publisher says API keys and response payloads are excluded from audit logs; no telemetry and no inbound ports are documented. | Authorized service data and tool results pass through the MCP server to the connected AI client. Review the publisher and client data policies before using sensitive security & testing information. |
| Limitations | ||
| Tradeoffs |
|
|
| Risk context | Broad external intelligence fan-out sends queried indicators off-host; URLScan can submit URLs, and HTTP mode can expose a service endpoint. Keep queries non-sensitive where possible, preserve the documented private-IP blocking, and restrict HTTP exposure. | Scanning shares source-derived findings with the MCP client and may consume substantial local resources. Use a test environment where practical, least-privilege credentials, narrowly enabled tools, and explicit confirmation for mutations. MCP100 did not execute third-party server code during this documentation review. |
| Evidence date | ||
| Editorial review | 2026-08-11 | 2026-07-30 |
| Candidate evidence | 2026-08-14T18:46:26.000Z | 2026-08-14T18:46:26.000Z |
Popularity, maintenance, fit, permissions, and client support are independent evidence fields.
Read the evidence method →