Skip to main content
AllMCPs
BrowseBestCategoriesStackCompareToolsGuidesBlog
Log in Submit MCP

Stay in the loop

Get new MCP servers and top picks in your inbox.

AllMCPs

The open directory for discovering and installing Model Context Protocol servers.

AllMCPs on GitHub (opens in a new tab)
Launched onTiny Startupstinystartups.com
Explore
  • Browse servers
  • Best MCP servers
  • Categories
  • MCP clients
  • Agent prompts
  • Stack Builder
  • Compare servers
  • Random discovery New
  • Submit a server
  • Pricing & Boost Boost
Learn
  • Guides hub
  • What is MCP?
  • Install guide
  • Build an MCP server
  • Deploy an MCP server
  • Security guide
  • Troubleshooting
  • MCP for SEO & AEO
  • Protocol versioning
  • Transports: stdio vs HTTP
  • Blog & updates
Tools
  • All developer tools
  • Config generator
  • Config validator
  • Config auditor
  • MCP playground
  • Token calculator
  • OpenAPI โ†’ MCP
  • Badge generator
For agents
  • REST API docs
  • Trust & traffic Live
  • Remote MCP server SSE โ†— (opens in a new tab)
  • llms.txt โ†— (opens in a new tab)
  • Catalog JSON โ†— (opens in a new tab)
Company
  • About
  • Advertise Sponsor
  • Contact
  • GitHub โ†— (opens in a new tab)
  • Terms
  • Privacy
AllMCPs VerifiedAllMCPs VerifiedFeatured on Nick LaunchesFeatured on Nick LaunchesLaunch Llama NewsletterLaunch Llama NewsletterVerified DR - allmcps.comVerified DR - allmcps.comFeatured on SaaSGrowFeatured on SaaSGrowFeatured on Twelve ToolsFeatured on Twelve ToolsFeatured on Saaspa.geFeatured on Saaspa.geFeatured on Findly.toolsFeatured on Findly.toolsFeatured on Startup FameFeatured on Startup FameFeatured on LaunchKiwiFeatured on LaunchKiwiFeatured on ScrollLaunchFeatured on ScrollLaunchFeatured on DailyPingsFeatured on DailyPingsFazier badgeFazier badgeFeatured on NewTool.siteFeatured on NewTool.siteFeatured on saasfame.comFeatured on saasfame.comDR Checker - Domain RatingDR Checker - Domain RatingListed on Turbo0Listed on Turbo0Launched on LaunchBoard - Product Launch PlatformLaunched on LaunchBoard - Product Launch PlatformList on SimilarlabsList on Similarlabshttps://codetrendy.comhttps://codetrendy.comListed on DevTool.ioFeatured on BuildlistFeatured on BuildlistLaunched on Tiny StartupsFeatured on ShowMeBestAIFeatured on ShowMeBestAIFind us on LaunchZoneFind us on LaunchZoneAllMCPs VerifiedAllMCPs VerifiedFeatured on Nick LaunchesFeatured on Nick LaunchesLaunch Llama NewsletterLaunch Llama NewsletterVerified DR - allmcps.comVerified DR - allmcps.comFeatured on SaaSGrowFeatured on SaaSGrowFeatured on Twelve ToolsFeatured on Twelve ToolsFeatured on Saaspa.geFeatured on Saaspa.geFeatured on Findly.toolsFeatured on Findly.toolsFeatured on Startup FameFeatured on Startup FameFeatured on LaunchKiwiFeatured on LaunchKiwiFeatured on ScrollLaunchFeatured on ScrollLaunchFeatured on DailyPingsFeatured on DailyPingsFazier badgeFazier badgeFeatured on NewTool.siteFeatured on NewTool.siteFeatured on saasfame.comFeatured on saasfame.comDR Checker - Domain RatingDR Checker - Domain RatingListed on Turbo0Listed on Turbo0Launched on LaunchBoard - Product Launch PlatformLaunched on LaunchBoard - Product Launch PlatformList on SimilarlabsList on Similarlabshttps://codetrendy.comhttps://codetrendy.comListed on DevTool.ioFeatured on BuildlistFeatured on BuildlistLaunched on Tiny StartupsFeatured on ShowMeBestAIFeatured on ShowMeBestAIFind us on LaunchZoneFind us on LaunchZone
ยฉ 2026 Jackalope Digital LLC. All rights reserved.
  1. Home
  2. ๐Ÿ”’ Security
  3. Lazaretto MCP
Lazaretto MCP logo
Health: ActiveRecent health check succeeded.Last checked 9/21/2026, 2:32:47 AM

Lazaretto MCP

User RatingsBe the first to rate and review this MCP server!
View RepositoryVisit Website
securitymalware-detectiondependency-scanningmcp

Checks pinned dependencies and artifacts for malicious-package indicators and deterministic behavioral risks.

Quick Install

Automated & IDE Setup

Copy the AI prompt to install this server into Claude Code, Cursor, or another agent โ€” or use 1-click editor setup below.

Add to CursorAdd to VS Code
Manual Client & Custom JSON ConfigExpand JSON โ–พ

Client Config & Setup

Remote HTTP
Configure Environment Variables (API Keys, Tokens, Options):
Add required secrets below โ€” values are included directly in the generated snippet so you can copy and paste with confidence.
Quick Add:
Choose your client or environment
Target File:~/Library/Application Support/Claude/claude_desktop_config.json
claude_desktop_config.json
{
  "mcpServers": {
    "jamesdfinance-dev-lazaretto-mcp": {
      "url": "https://lazaretto.dev/mcp",
      "env": {
        "LAZARETTO_API_KEY": "YOUR_VALUE_HERE",
        "LAZARETTO_BASE_URL": "YOUR_VALUE_HERE"
      }
    }
  }
}

๐Ÿ’ก Paste the JSON block into your client's configuration file under mcpServers, then restart the application.

Install Tool Schemas (2) Directory Badge Claim listing Alternatives๐Ÿ”’ More in Security

Overview

The jamesdfinance-dev/lazaretto-mcp MCP server checks lockfiles, package artifacts, and MCP tool descriptions against Lazaretto's security analysis service. It can run as a hosted Streamable HTTP server or locally over stdio, with free checks requiring no API key and deeper scans using prepaid credits. Lockfile checks cover npm, Yarn, and pnpm formats, while artifact scans return verdicts with file, line, and evidence details. Reach for it before installing dependencies, agent skills, or MCP tools.

Use cases

โ€ขCheck pinned dependencies before installing them
โ€ขScan packages or repositories for suspicious behavior
โ€ขVerify a previously issued Lazaretto attestation
โ€ขInspect MCP tools for prompt injection or tool poisoning

Key features

โ€ขLockfile checks for npm, Yarn, and pnpm
โ€ขKnown-bad SHA-256 hash lookup
โ€ขDeterministic artifact behavioral analysis
โ€ขMCP tool and endpoint inspection
โ€ขSigned scan attestation verification
โ€ขFree checks without an API key

Capabilities & Tool Schemas (2) ~7 tokensApproximate context cost of this serverโ€™s tool schemas (~4 chars/token), before any tool is called. Actual usage depends on your client and model.Self-reported Self-reportedParsed from the repository README, not verified against a live server โ€” may be incomplete or out of date.

Inspect callable tools, capabilities, and parameters exposed to AI agents by Lazaretto MCP.

known_bad_lookup

Callable MCP tool function

scan_artifact

Callable MCP tool function

How Lazaretto MCP works

What jamesdfinance-dev/lazaretto-mcp MCP server does

The jamesdfinance-dev/lazaretto-mcp MCP server provides pre-install verification for software packages, AI agent skills, and MCP tools. Its free lockfile workflow examines exactly pinned dependencies and compares them with published malicious-package advisories from OSV and OpenSSF. It can also check whether a SHA-256 artifact hash appears in Lazaretto's known-bad indicator store.

For deeper analysis, the server can fetch npm or PyPI packages, GitHub repositories, ClawHub skills, raw URLs, or supplied text without executing the target. The resulting verdict can be malicious, flagged, clear, or error, with evidence tied to the finding. MCP-specific checks analyze tool names, descriptions, schemas, and instructions for patterns such as tool poisoning or attempts to move secrets and conversation data.

How it works

The jamesdfinance-dev/lazaretto-mcp MCP server is a thin client for the Lazaretto API. It makes HTTPS requests and does not include the detection engine itself. Lockfile checks read files from the agent's working directory, so the complete dependency file does not need to be pasted into the model context. Supported inputs include package-lock.json, npm-shrinkwrap.json, yarn.lock, and pnpm-lock.yaml.

A lockfile result is only an all-clear when both the malicious and unverified collections are empty. Artifact results include the file, line, and evidence associated with a rule match. Scan verdicts are bound to a SHA-256 subject, and signed attestations can be checked later without rescanning or paying again. A previously clear subject may be marked contradicted if it becomes known-bad.

Setup and configuration

Use the hosted endpoint at https://lazaretto.dev/mcp with an MCP client that supports remote Streamable HTTP servers. The optional X-API-Key header identifies prepaid credits for paid operations. check_lockfile, known_bad_lookup, and verify_attestation do not require a key. Artifact and MCP scans require credits, which can be purchased as a bundle or topped up through the documented x402 endpoint.

For local stdio use, clone the repository, run npm install, and start node index.mjs with LAZARETTO_API_KEY when paid operations are needed. LAZARETTO_BASE_URL can replace the default https://lazaretto.dev API host. The package also documents npx lazaretto-mcp as a one-line launch command.

Tools and capabilities

  • check_lockfile: checks pinned dependencies against malicious-package advisories.
  • known_bad_lookup: matches a SHA-256 content hash against a daily-refreshed indicator store.
  • verify_attestation: validates Lazaretto's signed scan attestation and returns its claims.
  • scan_artifact: analyzes fetched or inline targets without running them.
  • check_mcp_tools: analyzes pasted MCP tool-list JSON without contacting the server.
  • scan_mcp_server: calls only initialize and tools/list on an MCP endpoint before analyzing its exposed text.

Limitations and notes

The jamesdfinance-dev/lazaretto-mcp MCP server reports signals and evidence rather than providing a security warranty. A clear result means no known-bad match or rule fired; it is not a general statement that the target is safe. For attestation verification, the artifact you plan to run must still match claims.sub. External MCP servers that run only over stdio cannot be reached by scan_mcp_server; their tool-list JSON can instead be submitted to check_mcp_tools. The MCP package is MIT licensed, while the Lazaretto service and detection engine are separate proprietary components.

Read the full README โ†’View source on GitHub โ†’

Related MCP Servers

View all in Security View all alternatives
  • Shieldapi MCP logoShieldapi MCP

    Security intelligence for AI agents: password breach checks (900M+ HIBP hashes), email/domain/IP/URL reputation, prompt injection detection (200+ patterns), and skill supply chain scanning. Pay-per-request via x402 USDC micropayments or free demo mode, no API key needed.

    ๐Ÿ”’ Security4 views
    Compare vs Shieldapi MCP โ†’
  • Agentscore MCP Server logoAgentscore MCP Server

    MCP security trust layer. Continuously monitors 800+ MCP packages on npm for install scripts, command injection, hardcoded secrets, capability drift, and publisher posture. Ships a GitHub Action policy gate for PR-level allow/warn/block decisions with OIDC auto-provisioning. 5 MCP tools, no API key required.

    ๐Ÿ”’ Security2 views
    Compare vs Agentscore MCP Server โ†’
  • Shield logoShield

    Local guardrail proxy for AI coding agents. Wraps any MCP server (stdio or Streamable HTTP) and blocks destructive tool calls โ€” DROP TABLE, rm -rf, force-push โ€” before they execute. MCP supply-chain protection: TOFU tool-catalog pinning against rug pulls, plus tool-description and tool-result scanning for tool poisoning and prompt injection. 51 starter rules, approval gates, audit logging. Single binary, Apache-2.0.

    ๐Ÿ”’ Security4 views
    Compare vs Shield โ†’
  • Agentward logoAgentward

    Permission control plane for AI agents. MCP proxy that enforces least-privilege YAML policies on every tool call, classifies sensitive data (PII/PHI), detects dangerous skill chains, and generates compliance audit trails. Supports stdio and HTTP proxy modes.

    ๐Ÿ”’ Security4 views
    Compare vs Agentward โ†’

Adoption & maintenance

Factual signals from GitHub, npm, and our automated checks โ€” not a rating.

Last commit
1mo ago
Most recent push to the default branch.
Tools exposed
2
Callable tools this server registers over MCP.
Directory activity
3 views
Config copies, upvotes, and views on AllMCPs.

Reviews

No reviews yet โ€” be the first to share how this listing worked for you.

Frequently Asked Questions about Lazaretto MCP

Run `npx -y lazaretto-mcp`, or clone the repository, run `npm install`, and start `node index.mjs` for local stdio use.

AllMCPs Directory Badge

Full Badge Customizer

Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.

Badge Style:
Live Dynamic SVG PreviewLazaretto MCP AllMCPs Directory Badge
Markdown (GitHub README)
[![AllMCPs](https://allmcps.com/api/badge/jamesdfinance-dev-lazaretto-mcp?style=directory)](https://allmcps.com/mcp/jamesdfinance-dev-lazaretto-mcp)
HTML Embed
<a href="https://allmcps.com/mcp/jamesdfinance-dev-lazaretto-mcp"><img src="https://allmcps.com/api/badge/jamesdfinance-dev-lazaretto-mcp?style=directory" alt="Lazaretto MCP on AllMCPs" /></a>

Technical Specs & Signals

Category๐Ÿ”’Security
PricingFreemium
More technical detailsExpand โ–พ
TransportSSE (Remote)
AuthAPI key
LicenseMIT
Last updatedSep 13, 2026
Views3
Unique ViewsTotal visits recorded for this listing page on AllMCPs.
Installs0
Installs & Copy ActionsTotal times users copied install commands or configuration snippets for this server.
GitHub stars0
GitHub Star CountTotal stargazers on GitHub representing community popularity (0 stars).
Last commit1mo ago
Last Repository CommitThe most recent commit or push recorded for this server's GitHub repository.Last commit on Jul 23, 2026
55Quality signal: Good ยท 55/100How this signal is calculated โ–พ
Server availabilityNot measured

Not scored for repo-hosted servers โ€” we can't reach the running server, only its GitHub page. Hosted MCP endpoints are health-checked live.

Verified ownership10/20
Documentation & tools29/30
Adoption & activity2/15
Community engagement0/10

A guidance signal from public completeness & health data โ€” not a user rating. New listings start lower and rise as they add docs, get verified, and grow adoption. Signals we can't observe for a listing are skipped, not counted against it.

โ˜… Spotlight Slot

Feature Your MCP Server

Get maximum visibility for your server across our directory, search results, and detail pages.

Spotlight Your Server

Own this project?

This directory is pre-filled from public sources. Claim via GitHub README, site badge, or DNS TXT to unlock edit access and the Official badge โ€” proof is checked automatically, then reviewed by our team.

Free dofollow backlink: add your website and place the AllMCPs badge on it โ€” no claim needed. We detect it automatically and keep it verified as long as the badge stays live.

Claim & get free dofollow

Share & Embed

Add our SVG badge (dark/light directory styles) or embeddable widget to your site.

Explore more

More in ๐Ÿ”’ Security โ†’Best MCP servers for Security โ†’Alternatives to Lazaretto MCP โ†’Install in Claude DesktopInstall in CursorInstall in VS Code