This is interesting. How does it compare with some open source tools that claim to do something similar, say mcp-scan?
So with the mix of static and dynamic analysis, MCP protocol conformance, supply chain vulnerability analysis, and MCP specific risk factors we curate a relevant risk score allowing you decide if the usage of a given MCP server is introducing unnecessary risk or not.