Field-by-field comparison
Compare the evidence before choosing an MCP.
Each signal stays separate, missing facts remain visible, and the column order follows your selection.
| Evidence field | Citra (PDF Reader MCP)Watchlist candidate | Excel MCP ServerMCP100 Selected |
|---|---|---|
| Task fit | ||
| Best for |
|
|
| Not ideal for |
|
|
| Avoid when |
|
|
| Provenance | ||
| Provenance details | First-party MCP SylphxAI · Publisher source ↗ | Community implementation Haris Musa · Publisher source ↗ |
| Maintenance | ||
| Maintenance details | Repo: Aug 8, 2026 Package: Aug 7, 2026 | Repo: Apr 12, 2026 Package: Apr 12, 2026 |
| Popularity evidence | ||
| GitHub stars | 891 GitHub stars · checked 2026-08-14T18:46:26.000Z | 4,108 GitHub stars · checked 2026-08-14T18:46:26.000Z |
| External adoption evidence |
|
|
| Client coverage | ||
| Client coverage details | Claude Code✓ Local stdio Claude Desktop✓ Local stdio Codex✓ Local stdio VS Code✓ Local stdio Cursor✓ Local stdio OpenCode✓ Local stdio | Claude Code✓ Local stdio Claude Desktop✓ Local stdio Codex✓ Local stdio VS Code✓ Local stdio Cursor✓ Local stdio OpenCode✓ Local stdio |
| Client coverage note | Local stdio runs on your computer. Streamable HTTP connects to a remotely hosted MCP server. | |
| Access and data | ||
| Authentication | Default stdio needs no service credential. Optional HTTP mode supports MCP_API_KEY and binds loopback by default; configured HTTP or OpenAI-compatible visual providers may use their own headers or API key, while local command providers do not inherently require one. | Local stdio has no separate service authentication. Remote MCP authentication is not documented, so remote listeners must remain network-restricted. |
| Cost | The MIT-licensed local server has no documented usage fee. Pricing for any operator-selected external OCR, visual, network, or client provider is outside the Citra documentation and remains provider-specific. | The MIT-licensed local server lists no usage fee; normal hosting, client, model, and network costs may apply. |
| Permissions | The tools read PDF paths and URLs available to the process. Directory allowlists can restrict local reach; URL handling blocks private addresses by default unless the operator overrides it. | The server can read, create, modify, format, chart, and delete workbook content. Remote modes confine relative paths to EXCEL_FILES_PATH in the patched release. |
| Data handling | Default stdio processing is local. Optional OCR or visual providers may receive rendered content according to their configuration, and URL inputs are fetched from their source. | Workbook paths and spreadsheet content are processed by the server and returned to the connected client as required by tool calls; publisher telemetry and retention are not documented. |
| Limitations | ||
| Tradeoffs |
|
|
| Risk context | Use stdio, configure explicit allowed PDF directories, retain private-IP URL blocking, require an API key before any non-loopback HTTP deployment, and review native artifacts before installation. | Versions through 0.1.7 have a critical path-traversal vulnerability. Use 0.1.8 or later, prefer stdio, restrict workbook paths, avoid public remote listeners, and keep recoverable backups. |
| Evidence date | ||
| Editorial review | 2026-08-14 | 2026-08-13 |
| Candidate evidence | 2026-08-14T18:46:26.000Z | 2026-08-14T18:46:26.000Z |
Popularity, maintenance, fit, permissions, and client support are independent evidence fields.
Read the evidence method →