
Lazaretto Mcp
Check whether anything you depend on is known malware, before an agent installs it. checklockfile takes a package-lock.json, yarn.lock or pnpm-lock.yaml and matches every pinned version against published malicious-package advisories in one call, free and with no API key, catching compromised releases like chalk@5.6.1 while leaving their clean releases alone. scanartifact adds deterministic behavioral analysis (no LLM in the serving path) for credential theft, exfiltration, obfuscation, prompt injection and install-time droppers, with the file, line and evidence that triggered it; verdicts are SHA-256-bound so you can re-verify what landed on disk. Paid scans settle at $0.03 USDC on Base (x402) or prepaid credits. npx lazaretto-mcp
Quick Install
Automated & IDE SetupCopy the AI prompt to install this server into Claude Code, Cursor, or another agent โ or use 1-click editor setup below.
Manual Client & Custom JSON ConfigExpand JSON โพ
Install Config Generator
๐ก Paste into ~/Library/Application Support/Claude/claude_desktop_config.json (macOS) or %APPDATA%\Claude\claude_desktop_config.json (Windows)
Capabilities & Tool Schemas (2)Self-reported
Inspect callable tools, capabilities, and parameters exposed to AI agents by Lazaretto Mcp.
known_bad_lookupCallable MCP tool function
scan_artifactCallable MCP tool function
Documentation Overview
lazaretto-mcp
An MCP server that lets an agent verify a skill, tool, or package before it installs it. It is a thin front end for the Lazaretto API. It ships no detection logic and does nothing but make HTTPS requests, so it is easy to audit.
Tools
check_lockfile (free, no API key)
Checks every exactly-pinned dependency in your lockfile against published
malicious-package advisories. Reads package-lock.json, yarn.lock, or
pnpm-lock.yaml from the working directory, so the agent never has to paste a
lockfile through its context. One call covers the whole tree.
An empty malicious list is an all-clear only when unverified is also empty.
known_bad_lookup: free, no key. Is a sha256 content hash a known-bad artifact? Exact-hash match against an indicator store refreshed daily.scan_artifact: fetches a target (npm package, GitHub repo, ClawHub skill, raw URL, or inline text) without running it and returns a deterministic verdict (malicious,flagged,clear,error) with evidence. A full scan needs prepaid credits (set anX-API-Keyheader). Buy them at https://lazaretto.dev/#pricing.
Reports are signals with evidence, not a warranty. clear means no known-bad
match and no rule fired. It is not a statement about risk.
Use it (hosted, zero install)
The server is hosted at https://lazaretto.dev/mcp. Add it to any MCP client
that supports remote (Streamable HTTP) servers. Nothing to install, no local
process.
known_bad_lookup works with no key. scan_artifact needs credits: buy a bundle
at https://lazaretto.dev/#pricing (an agent can also do this itself over x402 at
POST https://lazaretto.dev/v1/credits/topup).
Self-host the stdio server (optional)
If you would rather run it locally over stdio instead of the hosted URL:
LAZARETTO_BASE_URL overrides the API host (default https://lazaretto.dev).
License
MIT. The Lazaretto service and its detection engine are separate and proprietary.
Related MCP Servers
View all alternativesFrequently Asked Questions about Lazaretto Mcp
How do I install the jamesdfinance-dev/lazaretto-mcp MCP server?
Add the following block to your claude_desktop_config.json under mcpServers: "mcpServers": { "lazaretto-mcp": { "command": "npx", "args": ["-y", "jamesdfinance-dev/lazaretto-mcp"] } }
What does jamesdfinance-dev/lazaretto-mcp do?
Check whether anything you depend on is known malware, before an agent installs it. checklockfile takes a package-lock.json, yarn.lock or pnpm-lock.yaml and matches every pinned version against published malicious-package advisories in one call, free and with no API key, catching compromised releases like chalk@5.6.1 while leaving their clean releases alone. scanartifact adds deterministic behavioral analysis (no LLM in the serving path) for credential theft, exfiltration, obfuscation, prompt injection and install-time droppers, with the file, line and evidence that triggered it; verdicts are SHA-256-bound so you can re-verify what landed on disk. Paid scans settle at $0.03 USDC on Base (x402) or prepaid credits. npx lazaretto-mcp
Is the jamesdfinance-dev/lazaretto-mcp MCP server free to use?
Yes. jamesdfinance-dev/lazaretto-mcp is listed on AllMCPs as a free, open Model Context Protocol server you can install into Claude Desktop, Cursor, or any MCP-compatible client.