lazaretto-mcp
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@lazaretto-mcpCheck if npm package 'left-pad' is malicious"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
lazaretto-mcp
An MCP server that lets an agent verify a skill, tool, or package before it installs it. It is a thin front end for the Lazaretto API. It ships no detection logic and does nothing but make HTTPS requests, so it is easy to audit.
Tools
check_lockfile (free, no API key)
Checks every exactly-pinned dependency in your lockfile against published
malicious-package advisories. Reads package-lock.json, yarn.lock, or
pnpm-lock.yaml from the working directory, so the agent never has to paste a
lockfile through its context. One call covers the whole tree.
An empty malicious list is an all-clear only when unverified is also empty.
known_bad_lookup: free, no key. Is a sha256 content hash a known-bad artifact? Exact-hash match against an indicator store refreshed daily.scan_artifact: fetches a target (npm package, GitHub repo, ClawHub skill, raw URL, or inline text) without running it and returns a deterministic verdict (malicious,flagged,clear,error) with evidence. A full scan needs prepaid credits (set anX-API-Keyheader). Buy them at https://lazaretto.dev/#pricing.
Reports are signals with evidence, not a warranty. clear means no known-bad
match and no rule fired. It is not a statement about risk.
Related MCP server: Outfit
Use it (hosted, zero install)
The server is hosted at https://lazaretto.dev/mcp. Add it to any MCP client
that supports remote (Streamable HTTP) servers. Nothing to install, no local
process.
{
"mcpServers": {
"lazaretto": {
"url": "https://lazaretto.dev/mcp",
"headers": {
"X-API-Key": "your-prepaid-key (optional; known_bad_lookup is free)"
}
}
}
}known_bad_lookup works with no key. scan_artifact needs credits: buy a bundle
at https://lazaretto.dev/#pricing (an agent can also do this itself over x402 at
POST https://lazaretto.dev/v1/credits/topup).
Self-host the stdio server (optional)
If you would rather run it locally over stdio instead of the hosted URL:
git clone https://github.com/jamesdfinance-dev/lazaretto-mcp
cd lazaretto-mcp && npm install
LAZARETTO_API_KEY=your-key node index.mjsLAZARETTO_BASE_URL overrides the API host (default https://lazaretto.dev).
License
MIT. The Lazaretto service and its detection engine are separate and proprietary.
Maintenance
Related MCP Servers
- Alicense-qualityBmaintenanceMCP server for managing AI agent skills with pre-flight compatibility checks, ensuring missing dependencies are detected before execution.Last updated94MIT

Outfitofficial
Alicense-qualityAmaintenanceAn MCP server that enforces agent persona permissions by acting as a gateway, scoping tool access and denying unauthorized capabilities.Last updated286MIT- Alicense-qualityAmaintenanceAn MCP server that lets AI agents search, view, install, and validate skills from the skillhub registry through tool calls.Last updatedMIT

KYA-OS MCP Serverofficial
Flicense-qualityCmaintenanceA ready-to-deploy MCP server with in-process agent verification via KYA-OS Checkpoint, enabling secure tool access for verified agents.Last updated1
Related MCP Connectors
An MCP Server that provides identity verification and anti-fraud tools for AI agents via deepidv.
The MCP server for Azure DevOps, bringing the power of Azure DevOps directly to your agents.
MCP server for AI agents to plan, verify, and deploy Cloudflare-native apps.
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/jamesdfinance-dev/lazaretto-mcp'
If you have feedback or need assistance with the MCP directory API, please join our Discord server