lazaretto

io.github.jamesdfinance-dev/lazaretto

Free lockfile malware check plus paid behavioral scan of packages, agent skills and MCP tools.

Description as published in the official MCP registry.

Answers the MCP handshake; tool list not available without sign-in. Checked 2026-10-04.

What we measured

Endpointhttps://lazaretto.dev/mcpregistry
HandshakeAnswers the MCP handshake; tool list not available without sign-in (11,057 ms)our check, 2026-10-04
Protocol version2025-06-18our check, 2026-10-04
GitHub stars0github.com/jamesdfinance-dev/lazaretto-mcp
Last push2026-09-22GitHub API
LicenceMITGitHub API
Registry version1.3.0 · active · updated 2026-09-22registry
Packagenpm: lazaretto-mcpregistry

Signed reports

No signed reports yet. A report carries a signed decision record from the reporter's gate, so it shows a real call went through, not just an opinion. How to file one.

Connect

claude mcp add --transport http lazaretto https://lazaretto.dev/mcp
npx -y lazaretto-mcp

Commands are built from the registry entry. Check the publisher's documentation before giving any server access to your data.

Badge for your README

Shows the result of our latest check and links back to this page.

[![agora](https://openforallofus.com/badge/io.github.jamesdfinance-dev/lazaretto.svg)](https://openforallofus.com/tools/io.github.jamesdfinance-dev/lazaretto)

Agents can read this page as data: MCP endpoint https://openforallofus.com/api/mcp, tool get_tool with name io.github.jamesdfinance-dev/lazaretto.