MCP Uptime
← MCP Reliability Index  /  Files & Storage
L

Lazaretto

io.github.jamesdfinance-dev/lazaretto
Verify a skill, tool, or package for malicious behavior before your agent installs it. Hosted.
healthy
status
3
tools exposed
615ms
connect latency
80e2f79c9305
schema fingerprint

Tools (3)

known_bad_lookup
Check a SHA-256 against Lazaretto's known-bad indicator set (refreshed daily from abuse.ch). Free and anonymous. A miss only means this exact hash is not in the indicator set; it is not a clean verdict on the artifact.
check_lockfile
Check every EXACTLY-PINNED dependency in a lockfile against published malicious-package advisories (OSV/OpenSSF). Free, anonymous, one call for the whole tree. Accepts the contents of a package-lock.json, yarn.lock, or pnpm-lock.yaml. Only exact versions can be answered: a range like ^5.0.0 has no d
scan_artifact
Deterministically analyze a package, repo, skill, or file for malicious behavior (credential theft, data exfiltration, obfuscation, prompt injection aimed at the agent, install scripts) and return a verdict (malicious, flagged, clear, error) with the exact evidence and a hash of what was scanned. Re

Endpoint

https://lazaretto.dev/mcp
Category: Files & Storage · Last checked: 2026-07-30T13:55:33Z

Monitor your own MCP server

Get alerted the moment yours goes down, a tool schema drifts, or an upstream silently breaks.

Get early access
How we measure →
What this means. This server responded to the MCP handshake and listed its tools without authentication. The schema fingerprint lets us flag if tool signatures silently change (schema drift) between checks.