{"slug":"lazaretto-dev-v1-scan-056e7f","title":"Deterministic pre-install verification for npm packages, AI agent skills and MCP","host":"lazaretto.dev","method":"POST","resource":"https://lazaretto.dev/v1/scan","category":"other","description":"Deterministic pre-install verification for npm packages, AI agent skills and MCP tools. Matches the exact version against OSV and OpenSSF malicious-package advisories, then runs behavioral analysis for credential theft, exfiltration, obfuscation, prompt injection and install-time droppers, returning","price_listed":0.03,"price_asked":0.03,"state":"answering","state_label":"Answering","checks_7d":1,"answered_7d":1,"latency_ms_median":397,"reported_calls_30d":2,"reported_payers_30d":2,"networks":["eip155:8453"],"badge":"unverified","paid_checks_7d":0,"paid_ok_7d":0,"example_input":{"body":{"depth":"full","target":{"ref":"left-pad@1.3.0","type":"npm_package"}},"bodyType":"json","method":"POST","type":"http"},"output_schema":{"$schema":"https://json-schema.org/draft/2020-12/schema","properties":{"input":{"additionalProperties":false,"properties":{"body":{"properties":{"depth":{"enum":["lookup","full"],"type":"string"},"target":{"properties":{"content":{"type":"string"},"ref":{"type":"string"},"type":{"enum":["inline","raw_url","npm_package","github_repo","clawhub_skill"],"type":"string"}},"required":["type"],"type":"object"}},"required":["target"]},"bodyType":{"enum":["json","form-data","text"],"type":"string"},"method":{"enum":["POST","PUT","PATCH"],"type":"string"},"type":{"const":"http","type":"string"}},"required":["type","method","bodyType","body"],"type":"object"},"output":{"properties":{"example":{"type":"object"},"type":{"type":"string"}},"required":["type"],"type":"object"}},"required":["input"],"type":"object"},"history":[{"day":"2026-09-24","reachable":true,"status":402,"valid_402":true,"asked_usdc":0.03,"price_match":true,"latency_ms":397,"error":null}],"description_full":"Deterministic pre-install verification for npm packages, AI agent skills and MCP tools. Matches the exact version against OSV and OpenSSF malicious-package advisories, then runs behavioral analysis for credential theft, exfiltration, obfuscation, prompt injection and install-time droppers, returning a verdict with file-and-line evidence, a SHA-256 of what was analyzed, and a signed attestation that verifies offline. No LLM in the scan path, so the same input yields the same verdict.","last_updated":"2026-09-17T06:16:11.431Z","schemes":["exact"]}