MCP serverio.github.jamesdfinance-dev/lazaretto
Free lockfile malware check plus paid behavioral scan of packages, agent skills and MCP tools.
Overview
Score?
UNRATED 0.641
of what a free look can see, on 29 looks
Looks
35
last 14 hr ago
Tools
9
changed 9 days ago
More info
URL
lazaretto.dev/mcp
streamable-http
Says it is
lazaretto 1.0.0
protocol 2025-06-18
In the record since
32 days ago
Among servers18,413 with a card
0median 0.606 · this server 0.641 · highest on record 0.8561
Toolsfrom sha256:637e17057f…08f9ab · +0 −0 9 days ago
| Tool | Schema |
|---|---|
| check_lockfile Check EXACTLY-PINNED npm dependencies against published malicious-package advisories (OSV/OpenSSF). Free, anonymous, one call for the whole set. Give EITHER `lockfile`, the full te |
input · output |
| check_mcp_tools Check tool definitions you ALREADY HOLD, with no network call to anyone. Most MCP servers run locally over stdio and have no endpoint that can be reached, so this is the only way t |
input · output |
| find_attestation Ask whether anyone has already attested an artifact, BEFORE you install it or pay to scan it. Free and anonymous. Give a package identity like "[email protected]", an MCP server endpoint |
input · output |
| get_free_key Get a free developer key for the metered tools on this server, without leaving this session. No payment, no account, no card. The key holds a small daily allowance that refills eve |
input · output |
| known_bad_lookup Check a SHA-256 against Lazaretto's known-bad indicator set (refreshed daily from abuse.ch). Free and anonymous. A miss only means this exact hash is not in the indicator set; it i |
input · output |
| scan_artifact Deterministically analyze a package, repo, skill, or file for malicious behavior (credential theft, data exfiltration, obfuscation, prompt injection aimed at the agent, install scr |
input · output |
| scan_lockfile_deep Behaviorally scan the exactly-pinned dependencies in a lockfile, not just their identities: reads the code of each package and screens for credential theft, exfiltration, obfuscati |
input · output |
| scan_mcp_server Check an MCP server BEFORE you connect to it. Asks the server to introduce itself and list its tools, then analyzes the text it hands an agent: tool names, descriptions, parameter |
input · output |
| verify_attestation Verify a Lazaretto scan attestation that another agent (or a README, or a lockfile) handed you, WITHOUT re-scanning or paying. Free and anonymous. Returns whether the signature is |
input · output |
Verify it yourself
npx teppi-check https://lazaretto.dev/mcpcurl -s https://api.teppi.xyz/v1/trust/mcp/mcs_01M1FZ2FW7ECWJD8DG9712WMF0