Lazaretto MCP Server
by jamesdfinance-devio.github.jamesdfinance-dev/lazarettov1.3.0
Check lockfiles against malicious-package advisories and scan artifacts for credential theft, exfiltration, obfuscation, prompt injection and droppers.
context tax
queued
security
queued
cold start
queued
freshness
Active17d ago
Install Lazaretto MCP server
Install in Claude Code
claude mcp add lazaretto -e LAZARETTO_API_KEY='<lazaretto-api-key>' -- npx -y lazaretto-mcpInstall in Cursor
{
"mcpServers": {
"lazaretto": {
"command": "npx",
"args": [
"-y",
"lazaretto-mcp"
],
"env": {
"LAZARETTO_API_KEY": "<lazaretto-api-key>"
}
}
}
}Add to ~/.cursor/mcp.json (global) or .cursor/mcp.json (project).
Install in Claude Desktop
{
"mcpServers": {
"lazaretto": {
"command": "npx",
"args": [
"-y",
"lazaretto-mcp"
],
"env": {
"LAZARETTO_API_KEY": "<lazaretto-api-key>"
}
}
}
}Settings → Developer → Edit Config (claude_desktop_config.json), then restart.
Install in VS Code
{
"servers": {
"lazaretto": {
"type": "stdio",
"command": "npx",
"args": [
"-y",
"lazaretto-mcp"
],
"env": {
"LAZARETTO_API_KEY": "<lazaretto-api-key>"
}
}
}
}Add to .vscode/mcp.json in your workspace.
Install in Windsurf
{
"mcpServers": {
"lazaretto": {
"command": "npx",
"args": [
"-y",
"lazaretto-mcp"
],
"env": {
"LAZARETTO_API_KEY": "<lazaretto-api-key>"
}
}
}
}Add to ~/.codeium/windsurf/mcp_config.json.
Configuration
| Variable | Required | Secret | Description |
|---|---|---|---|
| LAZARETTO_API_KEY | — | yes | Optional. A Lazaretto key holding scan credits, used only by the paid tools. The free tools work without it. Buy credits at https://lazaretto.dev/buy. |
Remote endpoints
- streamable-http
https://lazaretto.dev/mcp
Freshness
Active — last maintenance signal 17d ago. The newest of the signals below sets the band.
Last commit (default branch)
2026-09-22 · 17d ago · GitHub
Latest release
2026-07-22 · 3mo ago · GitHub · v1.1.0
Package published
no data · npm/PyPI
Registry entry updated
2026-09-22 · 17d ago · official registry · v1.3.0
FAQ
›How do I install the Lazaretto MCP server in Claude Code?
Run: claude mcp add lazaretto -e LAZARETTO_API_KEY='<lazaretto-api-key>' -- npx -y lazaretto-mcp. For Cursor, VS Code, Claude Desktop and Windsurf, use the install tabs above.
›Does Lazaretto require an API key?
Yes. It expects LAZARETTO_API_KEY, of which 1 is a secret.
›Can I use Lazaretto as a remote (hosted) MCP server?
Yes — it offers both a hosted endpoint and a local stdio package.
›Is Lazaretto in the official MCP registry?
Yes, as io.github.jamesdfinance-dev/lazaretto.
Alternatives to Lazaretto
Other security MCP servers.