# jamesdfinance-dev/lazaretto-mcp [Health: Active]

**Category:** 🔒 Security  
**Repository:** https://github.com/jamesdfinance-dev/lazaretto-mcp  
**GitHub Stars:** 0  
**Views:** 0  
**Installs:** 0  
**Upvotes:** 0  
**Directory Page:** https://allmcps.com/mcp/jamesdfinance-dev-lazaretto-mcp

## Description
Check whether anything you depend on is known malware, before an agent installs it. checklockfile takes a package-lock.json, yarn.lock or pnpm-lock.yaml and matches every pinned version against published malicious-package advisories in one call, free and with no API key, catching compromised releases like chalk@5.6.1 while leaving their clean releases alone. scanartifact adds deterministic behavioral analysis (no LLM in the serving path) for credential theft, exfiltration, obfuscation, prompt injection and install-time droppers, with the file, line and evidence that triggered it; verdicts are SHA-256-bound so you can re-verify what landed on disk. Paid scans settle at $0.03 USDC on Base (x402) or prepaid credits. npx lazaretto-mcp

## Tools
Capabilities this server exposes over MCP:

- **known_bad_lookup**
- **scan_artifact**

## Claude Desktop Quick Installation
Remote MCP endpoint (confidence: high). Install path detected from listing signals. Add as a URL/SSE server in your client:

```json
"mcpServers": {
  "lazaretto-mcp": {
    "url": "https://modelcontextprotocol.io"
  }
}
```

## Documentation & README

# lazaretto-mcp

An [MCP](https://modelcontextprotocol.io) server that lets an agent verify a
skill, tool, or package before it installs it. It is a thin front end for the
[Lazaretto](https://lazaretto.dev) API. It ships no detection logic and does
nothing but make HTTPS requests, so it is easy to audit.

## Tools

### `check_lockfile` (free, no API key)

Checks every exactly-pinned dependency in your lockfile against published
malicious-package advisories. Reads `package-lock.json`, `yarn.lock`, or
`pnpm-lock.yaml` from the working directory, so the agent never has to paste a
lockfile through its context. One call covers the whole tree.

An empty `malicious` list is an all-clear only when `unverified` is also empty.


- **`known_bad_lookup`**: free, no key. Is a sha256 content hash a known-bad
  artifact? Exact-hash match against an indicator store refreshed daily.
- **`scan_artifact`**: fetches a target (npm package, GitHub repo, ClawHub
  skill, raw URL, or inline text) without running it and returns a deterministic
  verdict (`malicious`, `flagged`, `clear`, `error`) with evidence. A full scan
  needs prepaid credits (set an `X-API-Key` header). Buy them at
  https://lazaretto.dev/#pricing.

Reports are signals with evidence, not a warranty. `clear` means no known-bad
match and no rule fired. It is not a statement about risk.

## Use it (hosted, zero install)

The server is hosted at `https://lazaretto.dev/mcp`. Add it to any MCP client
that supports remote (Streamable HTTP) servers. Nothing to install, no local
process.

```json
{
  "mcpServers": {
    "lazaretto": {
      "url": "https://lazaretto.dev/mcp",
      "headers": {
        "X-API-Key": "your-prepaid-key (optional; known_bad_lookup is free)"
      }
    }
  }
}
```

`known_bad_lookup` works with no key. `scan_artifact` needs credits: buy a bundle
at https://lazaretto.dev/#pricing (an agent can also do this itself over x402 at
`POST https://lazaretto.dev/v1/credits/topup`).

## Self-host the stdio server (optional)

If you would rather run it locally over stdio instead of the hosted URL:

```bash
git clone https://github.com/jamesdfinance-dev/lazaretto-mcp
cd lazaretto-mcp && npm install
LAZARETTO_API_KEY=your-key node index.mjs
```

`LAZARETTO_BASE_URL` overrides the API host (default `https://lazaretto.dev`).

## License

MIT. The Lazaretto service and its detection engine are separate and proprietary.

