Complete AI Training

MCP server · Security

Lazaretto MCP server

by jamesdfinance-dev

Check your project's lockfile and packages for known malicious software before you install them.

Flow diagram: you ask your AI “Is chalk@5.6.1 safe to install?”, the Lazaretto MCP server connects it to Lazaretto, and you get back A clear answer in your chat.

Lazaretto is a helper that checks the packages your project depends on against lists of known bad software, so you can spot trouble before you install anything. It works with the lockfiles that npm, Yarn and pnpm already create, and it can also scan a package or an MCP server for suspicious behavior. It is handy for anyone who installs packages from the internet and wants a quick safety check.

What is an MCP server? The 30-second version

On its own, your AI can only chat with you. An MCP server is a small helper program that gives your AI a new skill or a connection to an app or service, and here it connects your AI to Lazaretto. Once connected, your AI can ask Lazaretto to check a lockfile or scan a package for you, and then tell you what it found. You do not need to understand how it works under the hood; you just ask in plain words.

What this MCP server does

You ask your AI to check your project's lockfile or a specific package. The AI sends that request to the Lazaretto helper. The helper talks to the Lazaretto service, which compares your packages against published lists of known malicious packages or scans the code for suspicious behavior. Then the AI tells you what it found, like a list of bad packages or a clean result. Some checks are free and some need paid credits.

Flow diagram: you ask your AI “Is chalk@5.6.1 safe to install?”, the Lazaretto MCP server connects it to Lazaretto, and you get back A clear answer in your chat. Click to zoom

What you can do with it

  • Check every pinned package in your lockfile against known malicious-package advisories
  • Look up whether a file hash is on a known-bad list
  • Find and verify signed scan reports for a package or MCP server
  • Scan a package, GitHub repo, or raw URL for credential theft, exfiltration, obfuscation, prompt injection and droppers
  • Deep-scan the code of up to 25 pinned packages in your lockfile
  • Check an MCP server's tool list for hidden instructions or secret-stealing parameters

Try asking your AI

  • “Check my package-lock.json for any known malicious packages”
  • “Is chalk@5.6.1 safe to install?”
  • “Scan this MCP server at https://example.com/mcp before I connect to it”
  • “Look up this file hash to see if it is known bad: abc123...”

What it gives back to you

You get back a clear answer in the chat. For a lockfile check, it lists any malicious packages it found and any it could not verify. For a scan, it gives a verdict like malicious, flagged, clear or error, along with evidence. For attestation checks, it confirms whether a signed report exists and whether it is still valid.

Before you start

What you need

  • An MCP client that supports remote servers (for the hosted version) or Node.js 18+ (for the local version)
  • No account or key for the free tools
  • Prepaid credits and an API key for the paid scans (buy at https://lazaretto.dev/buy)

Good to know

The paid scans cost credits, so keep an eye on your balance. A clear result means no known-bad match and no rule fired, but it is not a guarantee that a package is safe.

Install it with your AI

Add Lazaretto MCP server to your AI, no technical skills needed

You don't install anything by hand. You copy one prompt, paste it into an AI that can work on your computer, and it checks, installs and connects the server for you, asking you when it needs something.

Sign in to get the install prompt

Members get a ready-made prompt that lets the Claude desktop app check Lazaretto MCP server, install it and connect it for them, step by step. You don't need any technical skills: you copy, paste and answer a few questions. Your connected AI can also find and install any of the 4,066 MCP servers here for you.

Sign in Become a member

Who it's for

Developers, security-minded engineers, and anyone who installs npm packages or connects to MCP servers and wants a quick safety check.