Skip to content
mcp/skillhub

Lazaretto MCP Server

by jamesdfinance-devio.github.jamesdfinance-dev/lazarettov1.3.0

Check lockfiles against malicious-package advisories and scan artifacts for credential theft, exfiltration, obfuscation, prompt injection and droppers.

0Node.jsstdioremoteofficial registry

context tax

queued

security

queued

cold start

queued

freshness

Active17d ago

Install Lazaretto MCP server

Install in Claude Code

claude mcp add lazaretto -e LAZARETTO_API_KEY='<lazaretto-api-key>' -- npx -y lazaretto-mcp

Configuration

VariableRequiredSecretDescription
LAZARETTO_API_KEY—yesOptional. A Lazaretto key holding scan credits, used only by the paid tools. The free tools work without it. Buy credits at https://lazaretto.dev/buy.

Remote endpoints

  • streamable-httphttps://lazaretto.dev/mcp

Freshness

Active — last maintenance signal 17d ago. The newest of the signals below sets the band.

  1. Last commit (default branch)

    2026-09-22 · 17d ago · GitHub

  2. Latest release

    2026-07-22 · 3mo ago · GitHub · v1.1.0

  3. Package published

    no data · npm/PyPI

  4. Registry entry updated

    2026-09-22 · 17d ago · official registry · v1.3.0

FAQ

›How do I install the Lazaretto MCP server in Claude Code?

Run: claude mcp add lazaretto -e LAZARETTO_API_KEY='<lazaretto-api-key>' -- npx -y lazaretto-mcp. For Cursor, VS Code, Claude Desktop and Windsurf, use the install tabs above.

›Does Lazaretto require an API key?

Yes. It expects LAZARETTO_API_KEY, of which 1 is a secret.

›Can I use Lazaretto as a remote (hosted) MCP server?

Yes — it offers both a hosted endpoint and a local stdio package.

›Is Lazaretto in the official MCP registry?

Yes, as io.github.jamesdfinance-dev/lazaretto.

Alternatives to Lazaretto

Other security MCP servers.

View all