{"uid":"cap_KArrCwPD7zlq4Nkp_grsf","slug":"lazaretto-security-scanner-458a368e","name":"Lazaretto Security Scanner","description":"Deterministic behavioral scan of an npm package, repo, skill, or file for malicious signals, with evidence bound to a content hash.","url":"https://lazaretto.dev/v1/scan","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"depth":{"enum":["lookup","full"],"type":"string"},"target":{"type":"object","required":["type"],"properties":{"ref":{"type":"string"},"type":{"enum":["inline","raw_url","npm_package","github_repo","clawhub_skill"],"type":"string"},"content":{"type":"string"}}}}},"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.03","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.03/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.03","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.03","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_5GZx4vc_QgpGeqoBsIWXm","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.03","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Performs a deterministic behavioral scan of an npm package, GitHub repo, skill, or file for malicious signals, returning evidence bound to a content hash.","exampleAgentPrompt":"Do a full behavioral security scan of the npm package 'left-pad' version 1.3.0 and tell me if it contains any malicious signals or suspicious code.","exampleUseCases":[{"title":"Pre-install npm package vetting","prompt":"Before we add 'event-stream' to our project, do a full scan of that npm package and tell me if there are any malicious signals or backdoors I should know about."},{"title":"Open-source repo due diligence","prompt":"Can you run a security scan on the GitHub repo 'https://github.com/someuser/some-lib' and check whether it has any malicious behavior or suspicious code patterns?"},{"title":"Inline code snippet review","prompt":"I just got sent this script — can you do a quick lookup scan on it and tell me if it contains anything malicious before I run it?"}],"resultDescription":"Returns a deterministic behavioral scan report including identified malicious signals (if any), supporting evidence for each finding, and a content hash binding the results to the exact artifact scanned. The depth field controls whether a fast lookup or full deep analysis is performed.","failureModes":["Unresolvable target reference (invalid npm package name, private repo, or inaccessible URL) returns an error","Unsupported target type results in validation error","Content too large for inline scanning may be rejected","Network timeout when fetching raw URLs","Insufficient USDC balance causes payment failure before scan begins"],"whenToPreferThis":"Choose Lazaretto when you need deterministic, evidence-bound security scanning of code artifacts — especially npm packages, GitHub repos, or arbitrary files — before installing or executing them. Its content-hash binding makes results reproducible and auditable, which is ideal for CI/CD gates, supply chain verification, or agent-driven dependency vetting. Prefer it over generic static analysis tools when you specifically need behavioral malicious-signal detection rather than style or bug linting.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-14T12:39:08.600Z","isFirstParty":false}