Comparison
cve-mcp-server vs garak
Verdict
Pick cve-mcp-server if cve-mcp-server offers production-grade integration of Claude with diverse cybersecurity APIs and tools; pick garak if lLM Vulnerability Scanner.
Markdown twin · cve-mcp-server alternatives · garak alternatives
GraphCanon updated 2w
vs
Trust & integrity
| Signal | cve-mcp-server | garak |
|---|---|---|
| Maintenance | Active (10d since push) As of 3w · github_public_v1 | Very active (0d since push) As of 2w · github_public_v1 |
| Provenance | Not a fork · Personal account As of 3w · github_public_v1 | Not a fork · Organization account As of 2w · github_public_v1 |
| OSV dependency advisories | No lockfile (source not queried) As of 1mo · osv@v1 | Published findings As of 1mo · osv@v1 |
| deps.dev advisories | Not queried deps.dev@v1 | Not queried deps.dev@v1 |
| OpenSSF Scorecard | Not queried openssf-scorecard@v1 | Not queried openssf-scorecard@v1 |
Tagline
- cve-mcp-server
- Production-grade MCP server providing Claude access to multiple cybersecurity tools and APIs
- garak
- LLM vulnerability scanner
Stars
- cve-mcp-server
- 1.1k
- garak
- 8.7k
Forks
- cve-mcp-server
- 179
- garak
- 1.1k
Open issues
- cve-mcp-server
- 10
- garak
- 374
Language
- cve-mcp-server
- Python
- garak
- Python
Adopt for
- cve-mcp-server
- cve-mcp-server offers production-grade integration of Claude with diverse cybersecurity APIs and tools.
- garak
- LLM Vulnerability Scanner
Persona
- cve-mcp-server
- -
- garak
- -
Runtime
- cve-mcp-server
- -
- garak
- -
License
- cve-mcp-server
- Apache-2.0
- garak
- Apache-2.0
Last pushed
- cve-mcp-server
- Jul 16, 2026
- garak
- Aug 4, 2026
Categories
- cve-mcp-server
- Data & Retrieval, Evaluation & Observability
- garak
- Evaluation & Observability
Trust and health
Maintenance
- cve-mcp-server
- Active (82%)
- garak
- Very active (96%)
Days since push
- cve-mcp-server
- 10d
- garak
- 0d
Open issues (now)
- cve-mcp-server
- 10
- garak
- 374
Owner type
- cve-mcp-server
- User
- garak
- Organization
OSV dependency advisories
- cve-mcp-server
- No lockfile (source not queried)
- garak
- Published findings
Full report
- cve-mcp-server
- Trust report
- garak
- Trust report
Shared compatibility
- Python · cve-mcp-server: Python runtime · garak: Python runtime
Choose cve-mcp-server if…
- This tool needs to be hosted and run on your own infrastructure.
- Requirements: cve-mcp-server requires a Python environment.; Proper API keys for accessing various security tools and APIs are necessary..
- Tags unique to cve-mcp-server: cisa-kev, claude-ai, cve, cybersecurity.
- Also covers Data & Retrieval.
- cve-mcp-server ships Docker support for self-hosted deployment.
- Use cve-mcp-server when you need to provide comprehensive threat intelligence and vulnerability management capabilities to the LLM 'Claude', leveraging 27 security intelligence tools.
When NOT to use cve-mcp-server
- Avoid cve-mcp-server if your application does not require integration with the specific set of cybersecurity tools it provides or if a different LLM is preferred.
- Do not use this tool if you need to integrate only one or two security APIs; its strength lies in its extensive library of integrations, which might be overkill for smaller scale projects.
Choose garak if…
- Tags unique to garak: ai, llm-evaluation, security-scanners, vulnerability-assessment.
- When needing to assess the security and reliability of language models specifically using a tool developed by NVIDIA.
- More GitHub stars (8.7k vs 1.1k) - visibility, not fit.
When NOT to use garak
- When the targeted model is not supported by 'garak', such as some specialized API-based generators that need specific configurations beyond setting environment variables.
- If real-time updates are necessary, as the PyPI version of garak might lag behind the development version available on GitHub.
Explore
Sources
Every stat on this page traces to a dated GitHub sync, license file, enrichment field, or trust scan.
- GitHub stars (mukul975/cve-mcp-server) · observed Jul 27, 2026
- GitHub forks (mukul975/cve-mcp-server) · observed Jul 27, 2026
- Last push (mukul975/cve-mcp-server) · observed Jul 16, 2026
- License file (Apache-2.0) · observed Jul 27, 2026
- Decision facts (enrichment) · observed Jul 16, 2026
- Trust scan (lockfile / OSV) · observed Jul 11, 2026
- GitHub stars (NVIDIA/garak) · observed Aug 5, 2026
- GitHub forks (NVIDIA/garak) · observed Aug 5, 2026
- Last push (NVIDIA/garak) · observed Aug 4, 2026
- License file (Apache-2.0) · observed Aug 5, 2026
- Decision facts (enrichment) · observed Jul 17, 2026
- Trust scan (lockfile / OSV) · observed Jul 11, 2026
GitHub stars on cards: cve-mcp-server 1.1k · garak 8.7k (synced Jul 27, 2026).
Common questions
- What is the difference between cve-mcp-server and garak?
- cve-mcp-server: Production-grade MCP server providing Claude access to multiple cybersecurity tools and APIs. garak: LLM vulnerability scanner. See the comparison table for live GitHub stats and shared categories.
- When should I choose cve-mcp-server over garak?
- Choose cve-mcp-server over garak when This tool needs to be hosted and run on your own infrastructure; Requirements: cve-mcp-server requires a Python environment.; Proper API keys for accessing various security tools and APIs are necessary.; Tags unique to cve-mcp-server: cisa-kev, claude-ai, cve, cybersecurity; Also covers Data & Retrieval; cve-mcp-server ships Docker support for self-hosted deployment; Use cve-mcp-server when you need to provide comprehensive threat intelligence and vulnerability management capabilities to the LLM 'Claude', leveraging 27 security intelligence tools.
- When should I choose garak over cve-mcp-server?
- Choose garak over cve-mcp-server when Tags unique to garak: ai, llm-evaluation, security-scanners, vulnerability-assessment; When needing to assess the security and reliability of language models specifically using a tool developed by NVIDIA; More GitHub stars (8.7k vs 1.1k) - visibility, not fit.
- When should I avoid cve-mcp-server?
- Avoid cve-mcp-server if your application does not require integration with the specific set of cybersecurity tools it provides or if a different LLM is preferred. Do not use this tool if you need to integrate only one or two security APIs; its strength lies in its extensive library of integrations, which might be overkill for smaller scale projects.
- When should I avoid garak?
- When the targeted model is not supported by 'garak', such as some specialized API-based generators that need specific configurations beyond setting environment variables. If real-time updates are necessary, as the PyPI version of garak might lag behind the development version available on GitHub.
- Is cve-mcp-server or garak more popular on GitHub?
- garak has more GitHub stars (8,696 vs 1,096). Stars measure visibility, not whether either tool fits your constraints.
- Are cve-mcp-server and garak open source?
- Yes - both are open-source projects on GitHub (cve-mcp-server: Apache-2.0, garak: Apache-2.0).
- Where can I find alternatives to cve-mcp-server or garak?
- GraphCanon lists graph-backed alternatives at cve-mcp-server alternatives and garak alternatives (cve-mcp-server markdown twin, garak markdown twin), ranked by typed relationship edges rather than popularity votes.
- Is there a machine-readable version of this comparison?
- Yes. The markdown twin at this comparison mirrors this page for agents and LLM crawlers, with the same stats table and FAQ answers.
- Which is better maintained, cve-mcp-server or garak?
- cve-mcp-server: Active. garak: Very active. Compare maintenance labels, days since push, and release cadence in the trust section below - stars alone do not measure maintenance.
- Where are the full trust reports for cve-mcp-server and garak?
- GraphCanon publishes per-repo trust reports with dated maintenance, provenance, and scan summaries: cve-mcp-server trust report; garak trust report.