MCP server · source category: Security

jamesdfinance-dev/lazaretto-mcp

Check whether anything you depend on is known malware, before an agent installs it. checklockfile takes a package-lock.json, yar…

Check whether anything you depend on is known malware, before an agent installs it. checklockfile takes a package-lock.json, yarn.lock or pnpm-lock.yaml and matches every pinned version against published malicious-package advisories in one call, free and with no API key, catching compromised releases like chalk@5.6.1 while leaving their clean releases alone. scanartifact adds deterministic behavioral analysis (no LLM in the serving path) for credential theft, exfiltration, obfuscation, prompt injection and install-time droppers, with the file, line and evidence that triggered it; verdicts are SHA-256-bound so you can re-verify what landed on disk. Paid scans settle at $0.03 USDC…

Open documentation ↗

Record

Type
MCP server
Category
Security & Identity
Authentication
API key
Pricing
Free

Fields are reproduced from the source registry as-is. “Unknown” means the source did not describe the field — it is not an inference. See the methodology for how records are collected and normalised.

Browse all Security & Identity MCP servers.