{"$schema":"https://wellknown.network/schemas/agent-record-v1.json","schemaVersion":"1","id":"ag_4v5r9vf9sysj","handle":"lazaretto","url":"https://wellknown.network/agents/lazaretto","links":{"self":"https://wellknown.network/agents/lazaretto/record.json","html":"https://wellknown.network/agents/lazaretto","markdown":"https://wellknown.network/agents/lazaretto/record.md","api":"https://wellknown.network/api/v1/agents/lazaretto","status":"https://wellknown.network/api/v1/agents/lazaretto/status","claim":"https://wellknown.network/agents/lazaretto/claim","claimApi":"https://wellknown.network/api/v1/claims","claimDescriptor":"https://wellknown.network/agents/lazaretto/claim.json","badge":"https://wellknown.network/agents/lazaretto/badge.svg","openapi":"https://wellknown.network/openapi.json","history":"https://wellknown.network/api/v1/agents/lazaretto/history","tools":"https://wellknown.network/api/v1/agents/lazaretto/tools"},"ard":{"identifier":"urn:air:lazaretto.dev:server:lazaretto","type":"application/mcp-server-card+json"},"kind":"mcp_server","declared":{"name":"lazaretto","summary":"Checks npm packages, lockfiles, agent skills and MCP servers for malware before you install them. Free lockfile check and known-bad lookup; full behavioral scans with file-and-line evidence.","description":"Free lockfile malware check plus paid behavioral scan of packages, agent skills and MCP tools.","publisher":{"name":"jamesdfinance-dev","url":null},"homepage":"https://lazaretto.dev","repository":"https://github.com/jamesdfinance-dev/lazaretto-mcp","version":"1.2.6","license":"MIT","protocols":["mcp"],"tags":["security","supply-chain","malware","malware-detection","npm","lockfile","pnpm","yarn","dependency-scanning","mcp-security","prompt-injection","agent-skills","mcp","modelcontextprotocol","skill","verify","agent","x402","dependencies","osv","attestation"],"pricing":{"from":0.0156,"model":"freemium","currency":"USD"},"endpoints":[{"url":"https://lazaretto.dev/mcp","type":"mcp_streamable_http","auth":null,"probeable":true},{"url":"npm:lazaretto-mcp","type":"package_npm","auth":null,"probeable":false}],"skills":null,"tools":null,"extra":{"updatedAt":"2026-08-31T23:33:28.482108Z","npmKeywords":["mcp","modelcontextprotocol","security","supply-chain","malware","skill","npm","verify","agent","x402","lockfile","pnpm","dependencies","osv","attestation"],"publishedAt":"2026-08-31T23:33:28.482108Z","registryName":"io.github.jamesdfinance-dev/lazaretto","editedByOwnerAt":"2026-09-22T09:10:03.682Z"},"attribution":{"kind":"claim","name":"claim","license":"npm","pricing":"claim","repoUrl":"mcp_registry","summary":"claim","version":"mcp_registry","description":"claim","homepageUrl":"claim","publisherName":"mcp_registry"}},"derived":{"capabilities":[{"slug":"code.security-review","name":"Security Review","confidence":1,"provenance":"claimed"},{"slug":"security.scanning","name":"Security Scanning","confidence":1,"provenance":"claimed"},{"slug":"ai.evaluation","name":"Evaluation & Benchmarks","confidence":1,"provenance":"claimed"},{"slug":"dev.package-management","name":"Packages & Dependencies","confidence":1,"provenance":"declared"},{"slug":"ai.prompting","name":"Prompt Management","confidence":1,"provenance":"derived"},{"slug":"commerce.payments","name":"Payments","confidence":1,"provenance":"declared"},{"slug":"documents.ocr","name":"OCR","confidence":0.833,"provenance":"derived"},{"slug":"security.identity","name":"Identity & Access","confidence":0.525,"provenance":"derived"}],"categories":["ai","commerce","dev","documents","security"],"language":"en"},"observed":{"status":"live","statusReason":"Responded 24m ago.","lastOkAt":"2026-09-22T12:26:29.501Z","lastProbedAt":"2026-09-22T12:26:29.501Z","statusComputedAt":"2026-09-22T12:28:25.018Z","reliability30d":{"probes":59,"successRate":1,"p50Ms":169,"basis":"service","measures":{"availability":"availability","latency":"response time","tools":"tool surface observed","summary":"Checks reached the service itself."},"checks":{"total":59,"ok":59,"authBoundaryOk":0,"serviceOk":59,"note":"Counted from the observation rows for the window, checks of the server only (HTTP, A2A card, MCP initialize). ok = authBoundaryOk + serviceOk. `probes` is the sum of daily rollups and includes registry checks, so it can differ from `total`."}},"latestObservations":[{"at":"2026-09-22T12:26:29.501Z","kind":"mcp_initialize","ok":true,"httpStatus":200,"latencyMs":129,"error":null,"detail":{"tools":[{"name":"known_bad_lookup","description":"Check a SHA-256 against Lazaretto's known-bad indicator set (refreshed daily from abuse.ch). Free and anonymous. A miss only means this exact hash is not in the"},{"name":"check_lockfile","description":"Check every EXACTLY-PINNED dependency in a lockfile against published malicious-package advisories (OSV/OpenSSF). Free, anonymous, one call for the whole tree. "},{"name":"scan_artifact","description":"Deterministically analyze a package, repo, skill, or file for malicious behavior (credential theft, data exfiltration, obfuscation, prompt injection aimed at th"},{"name":"scan_lockfile_deep","description":"Behaviorally scan EVERY exactly-pinned dependency in a lockfile, not just their identities: reads the code of each package and reports credential theft, exfiltr"},{"name":"scan_mcp_server","description":"Check an MCP server BEFORE you connect to it. Asks the server to introduce itself and list its tools, then analyzes the text it hands an agent: tool names, desc"},{"name":"check_mcp_tools","description":"Check tool definitions you ALREADY HOLD, with no network call to anyone. Most MCP servers run locally over stdio and have no endpoint that can be reached, so th"},{"name":"find_attestation","description":"Ask whether anyone has already attested an artifact, BEFORE you install it or pay to scan it. Free and anonymous. Give a package identity like \"chalk@5.6.1\", an"},{"name":"verify_attestation","description":"Verify a Lazaretto scan attestation that another agent (or a README, or a lockfile) handed you, WITHOUT re-scanning or paying. Free and anonymous. Returns wheth"}],"toolCount":8,"toolsHash":"a06724177362b9c8e7d91142ef68f29fe8e9dac7b6c7a4693c47736c2dc470e3","serverName":"lazaretto","capabilities":["tools"],"serverVersion":"1.0.0","protocolVersion":"2025-06-18"}},{"at":"2026-09-22T11:26:00.988Z","kind":"mcp_initialize","ok":true,"httpStatus":200,"latencyMs":171,"error":null,"detail":{"tools":[{"name":"known_bad_lookup","description":"Check a SHA-256 against Lazaretto's known-bad indicator set (refreshed daily from abuse.ch). Free and anonymous. A miss only means this exact hash is not in the"},{"name":"check_lockfile","description":"Check every EXACTLY-PINNED dependency in a lockfile against published malicious-package advisories (OSV/OpenSSF). Free, anonymous, one call for the whole tree. "},{"name":"scan_artifact","description":"Deterministically analyze a package, repo, skill, or file for malicious behavior (credential theft, data exfiltration, obfuscation, prompt injection aimed at th"},{"name":"scan_lockfile_deep","description":"Behaviorally scan EVERY exactly-pinned dependency in a lockfile, not just their identities: reads the code of each package and reports credential theft, exfiltr"},{"name":"scan_mcp_server","description":"Check an MCP server BEFORE you connect to it. Asks the server to introduce itself and list its tools, then analyzes the text it hands an agent: tool names, desc"},{"name":"check_mcp_tools","description":"Check tool definitions you ALREADY HOLD, with no network call to anyone. Most MCP servers run locally over stdio and have no endpoint that can be reached, so th"},{"name":"find_attestation","description":"Ask whether anyone has already attested an artifact, BEFORE you install it or pay to scan it. Free and anonymous. Give a package identity like \"chalk@5.6.1\", an"},{"name":"verify_attestation","description":"Verify a Lazaretto scan attestation that another agent (or a README, or a lockfile) handed you, WITHOUT re-scanning or paying. Free and anonymous. Returns wheth"}],"toolCount":8,"toolsHash":"a06724177362b9c8e7d91142ef68f29fe8e9dac7b6c7a4693c47736c2dc470e3","serverName":"lazaretto","capabilities":["tools"],"serverVersion":"1.0.0","protocolVersion":"2025-06-18"}},{"at":"2026-09-22T10:27:23.893Z","kind":"mcp_initialize","ok":true,"httpStatus":200,"latencyMs":128,"error":null,"detail":{"tools":[{"name":"known_bad_lookup","description":"Check a SHA-256 against Lazaretto's known-bad indicator set (refreshed daily from abuse.ch). Free and anonymous. A miss only means this exact hash is not in the"},{"name":"check_lockfile","description":"Check every EXACTLY-PINNED dependency in a lockfile against published malicious-package advisories (OSV/OpenSSF). Free, anonymous, one call for the whole tree. "},{"name":"scan_artifact","description":"Deterministically analyze a package, repo, skill, or file for malicious behavior (credential theft, data exfiltration, obfuscation, prompt injection aimed at th"},{"name":"scan_lockfile_deep","description":"Behaviorally scan EVERY exactly-pinned dependency in a lockfile, not just their identities: reads the code of each package and reports credential theft, exfiltr"},{"name":"scan_mcp_server","description":"Check an MCP server BEFORE you connect to it. Asks the server to introduce itself and list its tools, then analyzes the text it hands an agent: tool names, desc"},{"name":"check_mcp_tools","description":"Check tool definitions you ALREADY HOLD, with no network call to anyone. Most MCP servers run locally over stdio and have no endpoint that can be reached, so th"},{"name":"find_attestation","description":"Ask whether anyone has already attested an artifact, BEFORE you install it or pay to scan it. Free and anonymous. Give a package identity like \"chalk@5.6.1\", an"},{"name":"verify_attestation","description":"Verify a Lazaretto scan attestation that another agent (or a README, or a lockfile) handed you, WITHOUT re-scanning or paying. Free and anonymous. Returns wheth"}],"toolCount":8,"toolsHash":"a06724177362b9c8e7d91142ef68f29fe8e9dac7b6c7a4693c47736c2dc470e3","serverName":"lazaretto","capabilities":["tools"],"serverVersion":"1.0.0","protocolVersion":"2025-06-18"}},{"at":"2026-09-22T09:27:57.172Z","kind":"mcp_initialize","ok":true,"httpStatus":200,"latencyMs":125,"error":null,"detail":{"tools":[{"name":"known_bad_lookup","description":"Check a SHA-256 against Lazaretto's known-bad indicator set (refreshed daily from abuse.ch). Free and anonymous. A miss only means this exact hash is not in the"},{"name":"check_lockfile","description":"Check every EXACTLY-PINNED dependency in a lockfile against published malicious-package advisories (OSV/OpenSSF). Free, anonymous, one call for the whole tree. "},{"name":"scan_artifact","description":"Deterministically analyze a package, repo, skill, or file for malicious behavior (credential theft, data exfiltration, obfuscation, prompt injection aimed at th"},{"name":"scan_lockfile_deep","description":"Behaviorally scan EVERY exactly-pinned dependency in a lockfile, not just their identities: reads the code of each package and reports credential theft, exfiltr"},{"name":"scan_mcp_server","description":"Check an MCP server BEFORE you connect to it. Asks the server to introduce itself and list its tools, then analyzes the text it hands an agent: tool names, desc"},{"name":"check_mcp_tools","description":"Check tool definitions you ALREADY HOLD, with no network call to anyone. Most MCP servers run locally over stdio and have no endpoint that can be reached, so th"},{"name":"find_attestation","description":"Ask whether anyone has already attested an artifact, BEFORE you install it or pay to scan it. Free and anonymous. Give a package identity like \"chalk@5.6.1\", an"},{"name":"verify_attestation","description":"Verify a Lazaretto scan attestation that another agent (or a README, or a lockfile) handed you, WITHOUT re-scanning or paying. Free and anonymous. Returns wheth"}],"toolCount":8,"toolsHash":"a06724177362b9c8e7d91142ef68f29fe8e9dac7b6c7a4693c47736c2dc470e3","serverName":"lazaretto","capabilities":["tools"],"serverVersion":"1.0.0","protocolVersion":"2025-06-18"}},{"at":"2026-09-22T02:33:58.859Z","kind":"mcp_initialize","ok":true,"httpStatus":200,"latencyMs":131,"error":null,"detail":{"tools":[{"name":"known_bad_lookup","description":"Check a SHA-256 against Lazaretto's known-bad indicator set (refreshed daily from abuse.ch). Free and anonymous. A miss only means this exact hash is not in the"},{"name":"check_lockfile","description":"Check every EXACTLY-PINNED dependency in a lockfile against published malicious-package advisories (OSV/OpenSSF). Free, anonymous, one call for the whole tree. "},{"name":"scan_artifact","description":"Deterministically analyze a package, repo, skill, or file for malicious behavior (credential theft, data exfiltration, obfuscation, prompt injection aimed at th"},{"name":"scan_lockfile_deep","description":"Behaviorally scan EVERY exactly-pinned dependency in a lockfile, not just their identities: reads the code of each package and reports credential theft, exfiltr"},{"name":"scan_mcp_server","description":"Check an MCP server BEFORE you connect to it. Asks the server to introduce itself and list its tools, then analyzes the text it hands an agent: tool names, desc"},{"name":"check_mcp_tools","description":"Check tool definitions you ALREADY HOLD, with no network call to anyone. Most MCP servers run locally over stdio and have no endpoint that can be reached, so th"},{"name":"find_attestation","description":"Ask whether anyone has already attested an artifact, BEFORE you install it or pay to scan it. Free and anonymous. Give a package identity like \"chalk@5.6.1\", an"},{"name":"verify_attestation","description":"Verify a Lazaretto scan attestation that another agent (or a README, or a lockfile) handed you, WITHOUT re-scanning or paying. Free and anonymous. Returns wheth"}],"toolCount":8,"toolsHash":"a06724177362b9c8e7d91142ef68f29fe8e9dac7b6c7a4693c47736c2dc470e3","serverName":"lazaretto","capabilities":["tools"],"serverVersion":"1.0.0","protocolVersion":"2025-06-18"}},{"at":"2026-09-21T20:27:16.414Z","kind":"mcp_initialize","ok":true,"httpStatus":200,"latencyMs":234,"error":null,"detail":{"tools":[{"name":"known_bad_lookup","description":"Check a SHA-256 against Lazaretto's known-bad indicator set (refreshed daily from abuse.ch). Free and anonymous. A miss only means this exact hash is not in the"},{"name":"check_lockfile","description":"Check every EXACTLY-PINNED dependency in a lockfile against published malicious-package advisories (OSV/OpenSSF). Free, anonymous, one call for the whole tree. "},{"name":"scan_artifact","description":"Deterministically analyze a package, repo, skill, or file for malicious behavior (credential theft, data exfiltration, obfuscation, prompt injection aimed at th"},{"name":"scan_lockfile_deep","description":"Behaviorally scan EVERY exactly-pinned dependency in a lockfile, not just their identities: reads the code of each package and reports credential theft, exfiltr"},{"name":"scan_mcp_server","description":"Check an MCP server BEFORE you connect to it. Asks the server to introduce itself and list its tools, then analyzes the text it hands an agent: tool names, desc"},{"name":"check_mcp_tools","description":"Check tool definitions you ALREADY HOLD, with no network call to anyone. Most MCP servers run locally over stdio and have no endpoint that can be reached, so th"},{"name":"find_attestation","description":"Ask whether anyone has already attested an artifact, BEFORE you install it or pay to scan it. Free and anonymous. Give a package identity like \"chalk@5.6.1\", an"},{"name":"verify_attestation","description":"Verify a Lazaretto scan attestation that another agent (or a README, or a lockfile) handed you, WITHOUT re-scanning or paying. Free and anonymous. Returns wheth"}],"toolCount":8,"toolsHash":"a06724177362b9c8e7d91142ef68f29fe8e9dac7b6c7a4693c47736c2dc470e3","serverName":"lazaretto","capabilities":["tools"],"serverVersion":"1.0.0","protocolVersion":"2025-06-18"}},{"at":"2026-09-21T12:24:42.287Z","kind":"mcp_initialize","ok":true,"httpStatus":200,"latencyMs":259,"error":null,"detail":{"tools":[{"name":"known_bad_lookup","description":"Check a SHA-256 against Lazaretto's known-bad indicator set (refreshed daily from abuse.ch). Free and anonymous. A miss only means this exact hash is not in the"},{"name":"check_lockfile","description":"Check every EXACTLY-PINNED dependency in a lockfile against published malicious-package advisories (OSV/OpenSSF). Free, anonymous, one call for the whole tree. "},{"name":"scan_artifact","description":"Deterministically analyze a package, repo, skill, or file for malicious behavior (credential theft, data exfiltration, obfuscation, prompt injection aimed at th"},{"name":"scan_lockfile_deep","description":"Behaviorally scan EVERY exactly-pinned dependency in a lockfile, not just their identities: reads the code of each package and reports credential theft, exfiltr"},{"name":"scan_mcp_server","description":"Check an MCP server BEFORE you connect to it. Asks the server to introduce itself and list its tools, then analyzes the text it hands an agent: tool names, desc"},{"name":"check_mcp_tools","description":"Check tool definitions you ALREADY HOLD, with no network call to anyone. Most MCP servers run locally over stdio and have no endpoint that can be reached, so th"},{"name":"find_attestation","description":"Ask whether anyone has already attested an artifact, BEFORE you install it or pay to scan it. Free and anonymous. Give a package identity like \"chalk@5.6.1\", an"},{"name":"verify_attestation","description":"Verify a Lazaretto scan attestation that another agent (or a README, or a lockfile) handed you, WITHOUT re-scanning or paying. Free and anonymous. Returns wheth"}],"toolCount":8,"toolsHash":"a06724177362b9c8e7d91142ef68f29fe8e9dac7b6c7a4693c47736c2dc470e3","serverName":"lazaretto","capabilities":["tools"],"serverVersion":"1.0.0","protocolVersion":"2025-06-18"}},{"at":"2026-09-21T05:23:07.831Z","kind":"mcp_initialize","ok":true,"httpStatus":200,"latencyMs":127,"error":null,"detail":{"tools":[{"name":"known_bad_lookup","description":"Check a SHA-256 against Lazaretto's known-bad indicator set (refreshed daily from abuse.ch). Free and anonymous. A miss only means this exact hash is not in the"},{"name":"check_lockfile","description":"Check every EXACTLY-PINNED dependency in a lockfile against published malicious-package advisories (OSV/OpenSSF). Free, anonymous, one call for the whole tree. "},{"name":"scan_artifact","description":"Deterministically analyze a package, repo, skill, or file for malicious behavior (credential theft, data exfiltration, obfuscation, prompt injection aimed at th"},{"name":"scan_lockfile_deep","description":"Behaviorally scan EVERY exactly-pinned dependency in a lockfile, not just their identities: reads the code of each package and reports credential theft, exfiltr"},{"name":"scan_mcp_server","description":"Check an MCP server BEFORE you connect to it. Asks the server to introduce itself and list its tools, then analyzes the text it hands an agent: tool names, desc"},{"name":"check_mcp_tools","description":"Check tool definitions you ALREADY HOLD, with no network call to anyone. Most MCP servers run locally over stdio and have no endpoint that can be reached, so th"},{"name":"find_attestation","description":"Ask whether anyone has already attested an artifact, BEFORE you install it or pay to scan it. Free and anonymous. Give a package identity like \"chalk@5.6.1\", an"},{"name":"verify_attestation","description":"Verify a Lazaretto scan attestation that another agent (or a README, or a lockfile) handed you, WITHOUT re-scanning or paying. Free and anonymous. Returns wheth"}],"toolCount":8,"toolsHash":"a06724177362b9c8e7d91142ef68f29fe8e9dac7b6c7a4693c47736c2dc470e3","serverName":"lazaretto","capabilities":["tools"],"serverVersion":"1.0.0","protocolVersion":"2025-06-18"}},{"at":"2026-09-20T22:24:51.165Z","kind":"mcp_initialize","ok":true,"httpStatus":200,"latencyMs":234,"error":null,"detail":{"tools":[{"name":"known_bad_lookup","description":"Check a SHA-256 against Lazaretto's known-bad indicator set (refreshed daily from abuse.ch). Free and anonymous. A miss only means this exact hash is not in the"},{"name":"check_lockfile","description":"Check every EXACTLY-PINNED dependency in a lockfile against published malicious-package advisories (OSV/OpenSSF). Free, anonymous, one call for the whole tree. "},{"name":"scan_artifact","description":"Deterministically analyze a package, repo, skill, or file for malicious behavior (credential theft, data exfiltration, obfuscation, prompt injection aimed at th"},{"name":"scan_lockfile_deep","description":"Behaviorally scan EVERY exactly-pinned dependency in a lockfile, not just their identities: reads the code of each package and reports credential theft, exfiltr"},{"name":"scan_mcp_server","description":"Check an MCP server BEFORE you connect to it. Asks the server to introduce itself and list its tools, then analyzes the text it hands an agent: tool names, desc"},{"name":"check_mcp_tools","description":"Check tool definitions you ALREADY HOLD, with no network call to anyone. Most MCP servers run locally over stdio and have no endpoint that can be reached, so th"},{"name":"find_attestation","description":"Ask whether anyone has already attested an artifact, BEFORE you install it or pay to scan it. Free and anonymous. Give a package identity like \"chalk@5.6.1\", an"},{"name":"verify_attestation","description":"Verify a Lazaretto scan attestation that another agent (or a README, or a lockfile) handed you, WITHOUT re-scanning or paying. Free and anonymous. Returns wheth"}],"toolCount":8,"toolsHash":"a06724177362b9c8e7d91142ef68f29fe8e9dac7b6c7a4693c47736c2dc470e3","serverName":"lazaretto","capabilities":["tools"],"serverVersion":"1.0.0","protocolVersion":"2025-06-18"}},{"at":"2026-09-20T16:22:54.889Z","kind":"mcp_initialize","ok":true,"httpStatus":200,"latencyMs":268,"error":null,"detail":{"tools":[{"name":"known_bad_lookup","description":"Check a SHA-256 against Lazaretto's known-bad indicator set (refreshed daily from abuse.ch). Free and anonymous. A miss only means this exact hash is not in the"},{"name":"check_lockfile","description":"Check every EXACTLY-PINNED dependency in a lockfile against published malicious-package advisories (OSV/OpenSSF). Free, anonymous, one call for the whole tree. "},{"name":"scan_artifact","description":"Deterministically analyze a package, repo, skill, or file for malicious behavior (credential theft, data exfiltration, obfuscation, prompt injection aimed at th"},{"name":"scan_lockfile_deep","description":"Behaviorally scan EVERY exactly-pinned dependency in a lockfile, not just their identities: reads the code of each package and reports credential theft, exfiltr"},{"name":"scan_mcp_server","description":"Check an MCP server BEFORE you connect to it. Asks the server to introduce itself and list its tools, then analyzes the text it hands an agent: tool names, desc"},{"name":"check_mcp_tools","description":"Check tool definitions you ALREADY HOLD, with no network call to anyone. Most MCP servers run locally over stdio and have no endpoint that can be reached, so th"},{"name":"find_attestation","description":"Ask whether anyone has already attested an artifact, BEFORE you install it or pay to scan it. Free and anonymous. Give a package identity like \"chalk@5.6.1\", an"},{"name":"verify_attestation","description":"Verify a Lazaretto scan attestation that another agent (or a README, or a lockfile) handed you, WITHOUT re-scanning or paying. Free and anonymous. Returns wheth"}],"toolCount":8,"toolsHash":"a06724177362b9c8e7d91142ef68f29fe8e9dac7b6c7a4693c47736c2dc470e3","serverName":"lazaretto","capabilities":["tools"],"serverVersion":"1.0.0","protocolVersion":"2025-06-18"}}],"tools":[{"name":"known_bad_lookup","description":"Check a SHA-256 against Lazaretto's known-bad indicator set (refreshed daily from abuse.ch). Free and anonymous. A miss only means this exact hash is not in the"},{"name":"check_lockfile","description":"Check every EXACTLY-PINNED dependency in a lockfile against published malicious-package advisories (OSV/OpenSSF). Free, anonymous, one call for the whole tree. "},{"name":"scan_artifact","description":"Deterministically analyze a package, repo, skill, or file for malicious behavior (credential theft, data exfiltration, obfuscation, prompt injection aimed at th"},{"name":"scan_lockfile_deep","description":"Behaviorally scan EVERY exactly-pinned dependency in a lockfile, not just their identities: reads the code of each package and reports credential theft, exfiltr"},{"name":"scan_mcp_server","description":"Check an MCP server BEFORE you connect to it. Asks the server to introduce itself and list its tools, then analyzes the text it hands an agent: tool names, desc"},{"name":"check_mcp_tools","description":"Check tool definitions you ALREADY HOLD, with no network call to anyone. Most MCP servers run locally over stdio and have no endpoint that can be reached, so th"},{"name":"find_attestation","description":"Ask whether anyone has already attested an artifact, BEFORE you install it or pay to scan it. Free and anonymous. Give a package identity like \"chalk@5.6.1\", an"},{"name":"verify_attestation","description":"Verify a Lazaretto scan attestation that another agent (or a README, or a lockfile) handed you, WITHOUT re-scanning or paying. Free and anonymous. Returns wheth"}],"package":{"name":"lazaretto-mcp","registry":"npm","observedAt":"2026-09-22T12:28:43.296Z","publishedAt":"2026-08-31T23:32:31.003Z","latestVersion":"0.5.0","weeklyDownloads":62},"toolSurface":{"id":"ts_2hxun249a28t","endpointId":"ep_88cjf4za3vvt","hash":"a06724177362b9c8e7d91142ef68f29fe8e9dac7b6c7a4693c47736c2dc470e3","toolCount":8,"serverName":"lazaretto","serverVersion":"1.0.0","protocolVersion":"2025-06-18","firstSeenAt":"2026-09-12T12:26:35.027Z","lastSeenAt":"2026-09-22T12:26:29.502Z","observations":39,"toolNames":["known_bad_lookup","check_lockfile","scan_artifact","scan_lockfile_deep","scan_mcp_server","check_mcp_tools","find_attestation","verify_attestation"],"distinctSurfaces":1},"endpointFacts":[{"id":"ep_88cjf4za3vvt","url":"https://lazaretto.dev/mcp","type":"mcp_streamable_http","factsCheckedAt":"2026-09-22T09:27:57.175Z","auth":{"observedAt":"2026-09-22T09:27:57.438Z","authRequired":false,"scheme":null,"resourceMetadata":null,"authorizationServer":null,"conformance":{"dpop":false,"rfc8414":false,"rfc9728":false,"pkceS256":false,"clientIdMetadataDocument":false,"dynamicClientRegistration":false}},"tls":{"observedAt":"2026-09-22T09:27:57.454Z","protocol":"TLSv1.3","chainValid":true,"chainError":null,"hostMatches":true,"subject":"lazaretto.dev","issuer":{"commonName":"YE2","organization":"Let's Encrypt"},"validFrom":"2026-09-09T12:02:48.000Z","validTo":"2026-12-08T12:02:47.000Z","daysToExpiry":76,"sanCount":1,"fingerprint256":"4F:99:99:B8:F0:D6:B6:1B:B5:61:40:80:5A:26:54:67:BC:69:6D:41:60:85:14:3A:EF:6A:7D:DB:1C:92:3A:C7"}}]},"verification":{"claimed":true,"claimedAt":"2026-09-22T09:03:28.009Z","proofs":[{"method":"github_owner","target":"jamesdfinance-dev","verifiedAt":"2026-09-22T09:03:28.009Z"}]},"provenance":{"sources":[{"source":"mcp_registry","key":"io.github.jamesdfinance-dev/lazaretto","url":"https://registry.modelcontextprotocol.io/v0/servers/io.github.jamesdfinance-dev%2Flazaretto","firstSeenAt":"2026-09-06T16:18:46.217Z","fetchedAt":"2026-09-21T15:20:33.646Z","normalizedAt":"2026-09-21T15:20:33.646Z"},{"source":"claim","key":"ag_4v5r9vf9sysj","url":null,"firstSeenAt":"2026-09-22T09:05:43.618Z","fetchedAt":"2026-09-22T09:10:03.682Z","normalizedAt":"2026-09-22T09:10:03.682Z"},{"source":"npm","key":"lazaretto-mcp","url":"https://www.npmjs.com/package/lazaretto-mcp","firstSeenAt":"2026-09-14T16:21:06.231Z","fetchedAt":"2026-09-18T19:20:57.518Z","normalizedAt":"2026-09-18T19:20:57.518Z"}]},"firstSeenAt":"2026-09-06T16:18:46.217Z","updatedAt":"2026-09-22T12:28:43.296Z"}