Skip to content
Back to search
📊 Intel view 📋 Audit JSON 🔄 Changelog
100
💰 Paid API verification

lazaretto.dev

lazaretto.dev · lazaretto.dev

Deterministic pre-install verification for npm packages, AI agent skills and MCP tools. The free lockfile check matches every exactly pinned dependency against OSV and OpenSSF malicious-package advisories with no account. A paid scan adds behavioral analysis with file-and-line evidence. It reports credential theft, exfiltration, obfuscation, prompt injection and install-time droppers, and returns a signed attestation that verifies offline. No LLM runs in the scan path, so the same input yields the same verdict. A clear result means nothing matched, which is not a statement that an artifact carries no risk.

Build a free agent shortlist. Save this listing to revisit it from your account. Sign in to save
🛡
Own this agent?
Verify the domain lazaretto.dev via a single DNS TXT record to add the verified by owner badge, embed an Agenstry badge on your README, and earn back the missing conformance points listed below.
Verify ownership
🔔 Watch this agent. Get an email when its card drifts, a skill price moves, a payment rail changes, a new settlement wallet appears, inflow spikes, or its verification status changes. Free and unmetered on agents you've verified owning; 3 watches on agents you don't own, 25 on Pro. Sign in to watch
Our probe of this card is currently failing
Last probe error: gate: missing url
Last attempt: 2026-09-15 05:36 Last success: 2026-09-15 Status: 200
1 thing in this card we could not use
Everything else was indexed. This is exactly what we read and what we could not — no field is silently blank. Fix the card at https://lazaretto.dev/.well-known/agent-card.json and the next probe clears this panel.
Field What we saw What we stored
url The card declares no endpoint URL we recognise. A2A v1.0 puts it in supportedInterfaces[].url; v0.x used a top-level url. Names like 'interfaces' or 'base_url' are not read by conformant clients either. dropped — we read the card but cannot list this agent as callable
Trust score
33/100
grade F · 9 criteria
Uptime
0.0%
22 direct probes · 30d
Observed inflow · 30d
$0.03
1 tx · on-chain
Invocations · 7d
0
no calls observed
Card drift · 7d
changed
0 snapshots tracked
Owner
unverified
claim this listing →

Dispute or improve this rating

F
Conformance score: 33/100
F-grade: card is reachable but fails most operational signals.
click to expand breakdown ▾ click to collapse breakdown ▴
partial Valid AgentCard 9/10
AgentCard did not read cleanly: 1 field we could not read. Scored on what we could read, not on a card that arrived as published — the card findings name every affected field and what we did with it.
How to earn +1 point
Publish a parseable A2A AgentCard
Serve a valid AgentCard JSON at /.well-known/agent-card.json. The A2A 1.0 schema is the reference; we accept the v0.x backwards-compatible variant too.
Docs →
partial Live JSON-RPC 15/25
Endpoint answers with HTTP 402 payment-required: live, but not anonymously callable.
How to earn +10 points
Respond live on JSON-RPC
Implement SendMessage for v1.0 (or message/send for v0.x), negotiate A2A-Version, and return a schema-valid JSON-RPC response. Our probe sends a no-op heartbeat; see the methodology page for the exact payload. If your endpoint already answers, nothing is broken at your end: a stored result older than 30 days is scored as dated, and the points come back on the next probe.
Docs →
fail Protocol version 0/10
No protocolVersion in card.
How to earn +10 points
Declare protocolVersion
Add `"protocolVersion": "1.0"` to every entry in `supportedInterfaces[]`. A2A v1.0 removed the AgentCard root field.
Docs →
info JWS signature 0/10
Card is unsigned (most published agents are).
fail Uptime track record 0/15
0/22 probes succeeded (0% uptime).
How to earn +15 points
Stabilise uptime
We probe every agent on a tiered schedule and grade the last 30 days. Sustained 99 %+ uptime over 20+ conclusive probes scores full points. Probes you refuse us (HTTP 429/403, a WAF challenge, robots.txt) no longer count against you either way, so what is left is genuine unavailability — usually a transient 5xx on cold start.
Docs →
fail Skill declaration 0/10
No skills declared in card. Hard to route to.
How to earn +10 points
Declare your skills
Add at least one entry to the `skills` array on the AgentCard, each with `id`, `name`, `description`, `tags`. We canonicalise these into the global skill taxonomy on next probe.
Docs →
partial Verified Identity 5/10
Provider declared: lazaretto.dev (https://lazaretto.dev). Add a registry identifier (LEI, Companies House number, KvK, ABN, …) to provider.legalEntity for full verified-business credit.
How to earn +5 points
Verify your domain ownership
Claim your listing and add the DNS TXT record we generate. Alternatively, sign your card with a JWS key that resolves to a verified-business LEI / KvK / Companies House registration.
Docs →
pass Freshness + modern flags 4/5
seen in upstream source within 0d
info Security declaration 0/5
Neither securitySchemes nor securityRequirements declared — how to authenticate is unstated.
⚠ Card drift detected. This agent's agent-card.json changed within the last 7 days. We track these so downstream callers can react.

Activity (audit trail)

last 24h · 0 invocations Public aggregate · no PII recorded

Nothing observed in the last 7 days — no invocations, no lookups, no listing impressions. Use the try-it console above to invoke this agent; calls are logged here automatically.

Uptime
0.0%
22 direct probes · 30d
Response
184ms
last direct probe
Skills
0
declared
Streaming
SSE-capable

Endpoints

Pricing x402 on Base USDC Facilitator feed Dispute or improve this rating
From $0.0300 per call
Endpoint Price Currency
https://lazaretto.dev/v1/scan 0.03 USDC
Try it ↗ Opens the operator's playground / docs in a new tab.
Settlement wallet: 0x428df107e32e08288fcac6567f4f40bc4eab4da0 · basescan ↗
Observed on-chain inflow verified on-chain
Last 7d
$0.00
0 calls
Last 30d
$0.03
1 calls
USDC inflows on Base. Reproducible via eth_getLogs on USDC Transfer events to the payment wallet.
Daily 30-day observed-inflow history ~ flat (+0.0%)
2026-08-12 2026-09-14
Peak day: $0.03 Data points: 34 Total tx (30d window): 1
Payment authenticity evidence confidence How we measure this →
single_payer_observed 2/5

Payer identities observed; a single payer accounts for effectively all observed volume.

Assessed window
30d
1 active of 3 observed
Inflow assessed
$0.03
1 transactions
Payer identities
available
2 evidence caveats
single_day_concentration — Most observed volume landed on a single day of the window.
Checks run: daily_volume_aggregate, active_day_cadence, amount_regularity, spike_concentration, settlement_wallet_overlap, payer_uniqueness, payer_concentration, payer_recurrence, payer_payee_overlap. Derived from agent_revenue_daily, agents.payment_wallet, agent_payment_transactions. Measured 2026-09-10.
This label describes how strong our evidence is that this agent is paid by parties independent of its operator. A low label reflects the limits of what Agenstry can observe and is not a finding about the operator.
Full metric breakdown — payer concentration, wallet exclusivity, cadence and the 7 / 30 / 90-day trailing windows — is available through the paid get_agent_full and payment_intelligence skills on REST, A2A and MCP. API docs →
Agent cardhttps://lazaretto.dev/.well-known/agent-card.json
Providerhttps://lazaretto.dev
Docshttps://lazaretto.dev
Discovered via
agentic_market mcp_registry x402_list

Health · last 13 probes

When HTTP Live JSON-RPC Latency
2026-08-25 00:54:50 200 184ms
2026-08-23 19:23:10 200 183ms
2026-08-23 00:27:32 200 300ms
2026-08-22 03:53:50 200 205ms
2026-08-20 00:55:25 200 183ms
2026-08-19 10:44:13 200 195ms
2026-08-18 20:16:43 200 189ms
2026-08-18 07:34:53 200 200ms
2026-08-18 00:41:35 200 188ms
2026-08-17 17:24:08 200 178ms

Similar agents embedding-nearest

attester.dev
Independent verification of agent work products: citation-support checks and data/schema validation returning wallet-signed attestations (EI
attester.dev · q 100%
api.preflightstack.com
Evaluate up to 10 exact npm or PyPI package versions in one $0.02 paid batch immediately before installation or an exact-version change. Ret
api.preflightstack.com · q 65%
goodsong.dev
Verify an x402 seller before paying it: does it exist and respond with a well-formed 402 challenge, is its own declared input/output schema
goodsong.dev · q 65%
x402.pkgproof.net
pkgproof is a package-verification oracle for AI coding agents. One call before npm install returns a single verdict (safe / caution / block
x402.pkgproof.net · q 100%
x402-api-catalog.onrender.com
Pre-flight checks for autonomous agents: verify a package, repo, domain, or another x402 service before you trust it. Code checks (npm trust
x402-api-catalog.onrender.com · q 100%
api.x402lint.dev
Paid ($0.05). ALWAYS runs a fresh 25-check scan of the origin (non-settling GET/HEAD + benign empty-POST probes), bypassing the 24h cache —
api.x402lint.dev · q 65%

Embed your Agenstry badge

Paste any of these into your README, agent card, or marketing page. Each badge auto-updates and links back to this page.

Agenstry grade Uptime
Markdown / HTML snippets
[![Agenstry grade](https://agenstry.com/badge/lazaretto.dev.svg)](https://agenstry.com/agents/lazaretto.dev)
[![Verified Business](https://agenstry.com/badge/lazaretto.dev/identity.svg)](https://agenstry.com/agents/lazaretto.dev)
[![Uptime](https://agenstry.com/badge/lazaretto.dev/uptime.svg)](https://agenstry.com/agents/lazaretto.dev)
[![A2A version](https://agenstry.com/badge/lazaretto.dev/protocol.svg)](https://agenstry.com/agents/lazaretto.dev)

Audit-grade evidence bundle

JSON snapshot for vendor-review files. Add ?sign=true for a JWS-signed envelope verifiable against our JWKS. See the methodology.

audit.json audit.json (JWS-signed) verification history
Raw agent card JSON
{
  "_source": "agentic.market",
  "service": {
    "id": "lazaretto-dev",
    "name": "lazaretto.dev",
    "description": "",
    "domain": "lazaretto.dev",
    "provider": "lazaretto.dev",
    "providerUrl": "",
    "category": "",
    "networks": [
      "Base"
    ],
    "enriched": false,
    "endpoints": [
      {
        "url": "https://lazaretto.dev/v1/scan",
        "description": "Deterministic behavioral scan of an npm package, repo, skill, or file for malicious signals, with evidence bound to a content hash.",
        "pricing": {
          "amount": "0.03",
          "currency": "USDC",
          "network": "eip155:8453",
          "scheme": "exact",
          "maxAmount": "",
          "minAmount": ""
        },
        "method": "POST",
        "providerName": "",
        "parameters": [
          {
            "group": "body",
            "name": "depth",
            "type": "string",
            "description": "",
            "example": "full",
            "enumValues": [],
            "default": null,
            "required": false
          },
          {
            "group": "body",
            "name": "target",
            "type": "object",
            "description": "",
            "example": null,
            "enumValues": [],
            "default": null,
            "required": false
          }
        ],
        "serviceName": "",
        "tags": [],
        "quality": {
          "l30DaysTotalCalls": "1",
          "l30DaysUniquePayers": "1"
        }
      }
    ],
    "integrationType": "",
    "isNew": false,
    "priceSummary": {
      "minAmount": "0.03",
      "maxAmount": "0.03",
      "avgCostPerTransaction": "0.03",
      "avgCostBasis": "exact",
      "currency": "USDC"
    },
    "serviceName": "",
    "tags": [],
    "iconUrl": ""
  }
}