Field-by-field comparison
Compare the evidence before choosing an MCP.
Each signal stays separate, missing facts remain visible, and the column order follows your selection.
| Evidence field | JADX-AI-MCP (Part of Zin MCP Suite)MCP100 Selected | elevenlabsMCP100 Selected |
|---|---|---|
| Task fit | ||
| Best for |
|
|
| Not ideal for |
|
|
| Avoid when |
|
|
| Provenance | ||
| Provenance details | Community implementation github:zinja-coder · Publisher source ↗ | First-party MCP ecosystem:elevenlabs · Publisher source ↗ |
| Maintenance | ||
| Maintenance details | Repo: Aug 6, 2026 Package: Not documented | Repo: Aug 14, 2026 Package: Not documented |
| Popularity evidence | ||
| GitHub stars | 2,664 GitHub stars · checked 2026-08-14T18:46:26.000Z | 1,522 GitHub stars · checked 2026-08-14T18:46:26.000Z |
| External adoption evidence |
|
|
| Client coverage | ||
| Client coverage details | Claude Code✓ Local stdio Claude Desktop✓ Local stdio Codex✓ Local stdio VS Code✓ Local stdio Cursor✓ Local stdio OpenCode✓ Local stdio | Not documented |
| Client coverage note | Local stdio runs on your computer. Streamable HTTP connects to a remotely hosted MCP server. | |
| Access and data | ||
| Authentication | The documented default is stdio with the HTTP endpoints on 127.0.0.1. The publisher explicitly warns that binding the MCP server to 0.0.0.0 or another non-localhost address exposes plain HTTP with no authentication or TLS, allowing anyone on that network to invoke all tools. | The official server uses a configured ElevenLabs API key. |
| Cost | The publisher distributes the project under the Apache License 2.0 and lists no MCP server usage fee. JADX, local compute, the selected MCP client, and model-provider costs can still apply. | The MCP integration has no separately verified MCP100 price conclusion. Publisher subscriptions, API usage, compute, storage, and AI-client charges may apply. |
| Permissions | The published tools can read decompiled code for classes and methods, smali, AndroidManifest.xml, string and resource files, cross-references, and debugger frames, threads, and variables from the project open in JADX. They can also rename classes, methods, fields, packages, and variables within the JADX analysis workspace. | ElevenLabs API-key permissions, account resources, and product quotas govern available audio operations. |
| Data handling | The publisher's architecture sends tool requests from the LLM client through the Python MCP server over HTTP to the JADX-GUI plugin, then returns source, resource, manifest, and debugger data to the connected client. The reviewed README does not document telemetry, retention, or model-training use, so those behaviors remain unknown. | Authorized service data and tool results pass through the MCP server to the connected AI client. Review the publisher and client data policies before using sensitive ai & reasoning information. |
| Limitations | ||
| Tradeoffs |
|
|
| Risk context | This server exposes sensitive reverse-engineering material and mutation tools for the APK project open in JADX. Keep both connections on 127.0.0.1 and prefer stdio; if remote access is unavoidable, use a trusted isolated network plus firewall or SSH tunnel. Treat decompiled source, resources, manifests, and debugger values as potentially confidential, and review rename operations before saving or exporting analysis artifacts. | Audio generation consumes paid quotas and voice or uploaded media may carry consent and privacy obligations. Use a test environment where practical, least-privilege credentials, narrowly enabled tools, and explicit confirmation for mutations. MCP100 did not execute third-party server code during this documentation review. |
| Evidence date | ||
| Editorial review | 2026-08-11 | 2026-07-30 |
| Candidate evidence | 2026-08-14T18:46:26.000Z | 2026-08-14T18:46:26.000Z |
Popularity, maintenance, fit, permissions, and client support are independent evidence fields.
Read the evidence method →