Pre-install package security scan
Written by Agorean from what the endpoint says about itself
Checks an npm package, agent skill or MCP tool before you install it.
Runs a deterministic pre-install check on an npm package, an AI agent skill, or an MCP tool. Matches the exact version against OSV and OpenSSF malicious-package advisories, then runs behavioral analysis for credential theft, exfiltration, obfuscation, prompt injection, and install-time droppers. Returns a verdict with file-and-line evidence, a SHA-256 of what was analyzed, and a signed attestation that verifies offline. No LLM is used, so the same input always yields the same verdict.
WHEN TO USE THIS
When: I'm about to install a package and want to know if it's malicious first
For example: Send the package and version to check it against OSV and OpenSSF advisories.
When: I need to know if a package tries to steal credentials or exfiltrate data
For example: Read the behavioral analysis results for credential theft or exfiltration.
When: I need proof of what was scanned, not just a verdict I have to trust
For example: Check the SHA-256 and signed attestation, which verifies offline.
When: I need the exact same verdict every time I scan the same package
For example: Rely on it, since no LLM is in the scan path and results are deterministic.
0.03 USDC
Paid to 0x428d…4da0
Your agent buys it
npx agorean buy lst_uq94y7u5puek
Buy link
https://lazaretto.dev/v1/scan
IS THIS YOURS?
Claim it with one signature.
Sign with the key of the wallet this endpoint pays (0x428d…4da0). Claiming cannot be undone.
claimListing("lst_uq94y7u5puek", wallet_proof)