Lazaretto
Verification ✓ VERIFIEDverified until 2026-08-19
Deterministic pre-install malware verification for npm packages, AI agent skills, and MCP tools. Behavioral scan with file-and-line evidence for 0.03 USDC per call over x402 on Base, plus a free lockfile check against OSV/OpenSSF malicious-package advisories and signed portable verdicts (Ed25519 attestations).
Pay from $0.03 to $3.00 in USDC on Base, settled onchain via the x402 protocol, no signup, no API key needed.
listed 2026-08-12 · no on-chain settlement recorded yet
ASSESSMENT
updated 2h agoEvidence-backed signals, not a single score. Click any chip for the proof. Measured values stay read-only; unknown is honest.
reliability 100%
- uptime 24h
- 100%
- uptime 7d
- 100%
- uptime 30d
- 100%
- uptime 90d
- 100%
- response p95
- 479ms
- avg response
- 479ms
- total checks
- 1
Measured on the unpaid 402 handshake, not the paid call. A service can 402 correctly and still fail after payment.
compliance A (14/14)
14 of 14 x402 conformance checks pass. Full checklist below.
price $0.03 to $3.00 (p56 in Verification)
- price (min)
- $0.03
- price (max)
- $3.00
- category percentile (min)
- p56 in Verification
- category percentile (max)
- p97 in Verification
- endpoints / prices
- 2 / 2
- model
- tiered
- stability
- 100%
risk clean
No deterministic risk flag. Risk fires only on an exact blocklist match, or a reserved-brand name with a mismatched verified payTo. Never from low uptime, a high price, or a model guess.
- domain age
- 33d
- registrar
- CloudFlare, Inc.
- hosting
- custom
- domain created
- 2026-07-10
Identity facts, not a risk score.
traction $0.00 30d · 0 buyers
- volume 30d
- $0.00
- buyers 30d
- 0
- settlements 30d
- 0
- first settlement
- ---
- last settlement
- ---
- top buyer share
- -
- trend 7d vs 30d
- -
- networks
- eip155:8453
- volume all-time
- $0
- settlements all-time
- 0
- median settlement 30d
- -
- max settlement 30d
- -
- settled via
- -
Conservative undercount: only USDC settlements via facilitators we measure are counted. A measured floor, not an estimate.
Top buyer share is a concentration signal, not part of the ranking score.
WHAT IT DOES
ai-derivedNo AI synthesis has been produced for this service yet.
ENDPOINTS
| METHOD | PATH | DESCRIPTION | PRICE | NETWORK | ASSET | 402 CHANNEL |
|---|---|---|---|---|---|---|
| POST | /v1/credits/topup | $3.00 | Base | USDC | header | |
| POST | /v1/scan | $0.03 | Base | USDC | header |
REQUEST / RESPONSE EXAMPLE
An unpaid request to POST /v1/credits/topup returns HTTP 402 with the payment terms. Settle onchain via your facilitator, then retry with the X-Payment header.
curl -i -X POST 'https://lazaretto.dev/v1/credits/topup'
// 402 response (captured by monitor) · 2 payloads · click to expand
[
{
"error": "payment required",
"accepts": [
{
"asset": "0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913",
"extra": {
"name": "USD Coin",
"version": "2"
},
"payTo": "0x428df107e32E08288fcAC6567f4F40bc4eAB4Da0",
"amount": "30000",
"scheme": "exact",
"network": "eip155:8453",
"maxTimeoutSeconds": 60
}
],
"resource": {
"url": "https://lazaretto.dev/v1/scan",
"mimeType": "application/json",
"description": "Deterministic behavioral scan of an npm package, repo, skill, or file for malicious signals, with evidence bound to a content hash."
},
"extensions": {
"bazaar": {
"info": {
"input": {
"body": {
"depth": "full",
"target": {
"ref": "[email protected]",
"type": "npm_package"
}
},
"type": "http",
"method": "POST",
"bodyType": "json"
},
"output": {
"type": "json",
"example": {
"risk": "none",
"verdict": "clear",
"confidence": "high",
"target_hash": "sha256:aa57b3ac555f3bfe2357e8a2e7ddfaa77934597887502db9ca0e660d388bf85f"
}
}
},
"schema": {
"type": "object",
"$schema": "https://json-schema.org/draft/2020-12/schema",
"required": [
"input"
],
"properties": {
"input": {
"type": "object",
"required": [
"type",
"method",
"bodyType",
"body"
],
"properties": {
"body": {
"required": [
"target"
],
"properties": {
"depth": {
"enum": [
"lookup",
"full"
],
"type": "string"
},
"target": {
"type": "object",
"required": [
"type"
],
"properties": {
"ref": {
"type": "string"
},
"type": {
"enum": [
"inline",
"raw_url",
"npm_package",
"github_repo",
"clawhub_skill"
],
"type": "string"
},
"content": {
"type": "string"
}
}
}
}
},
"type": {
"type": "string",
"const": "http"
},
"method": {
"enum": [
"POST",
"PUT",
"PATCH"
],
"type": "string"
},
"bodyType": {
"enum": [
"json",
"form-data",
"text"
],
"type": "string"
}
},
"additionalProperties": false
},
"output": {
"type": "object",
"required": [
"type"
],
"properties": {
"type": {
"type": "string"
},
"example": {
"type": "object"
}
}
}
}
}
}
},
"x402Version": 2
},
{
"error": "specify a bundle: {\"bundle\":\"starter\"|\"pro\"|\"scale\"}",
"accepts": [
{
"asset": "0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913",
"extra": {
"name": "USD Coin",
"credits": 150,
"version": "2"
},
"payTo": "0x428df107e32E08288fcAC6567f4F40bc4eAB4Da0",
"amount": "3000000",
"scheme": "exact",
"network": "eip155:8453",
"maxTimeoutSeconds": 60
}
],
"resource": {
"url": "https://lazaretto.dev/v1/credits/topup",
"mimeType": "application/json",
"description": "Lazaretto 150 scan credits"
},
"x402Version": 2
}
] OVER TIME
All charts use the 30d selector; each series spans only the dates it has data for. Every series is also served as JSON at /api/v1/services/lazaretto/price, /scores, /volume and /buyers. On-chain volume and distinct buyers are measured over the service's settlement address and are a conservative undercount (only settlements that reach a measured facilitator are counted). The on-chain series roll up hourly, so the latest day can be up to about an hour behind; distinct buyers are counted per payout address, so a service that settles to more than one address is an upper bound.
Median across 2 endpoints. Use the selector to isolate one.
checklist grew 11->14 on 2026-07-28; a step here is a metric change, not a regression
COMPLIANCE
14/14 checks pass · grade Alast 402 captured 2026-08-12 · last up 2026-08-12
- 402 payload captured
- accepts[] array present
- payTo address recoverable
- payTo at accepts[0].payTo (conformant shape)
- payTo is a valid on-chain address
- atomic price declared
- atomic price in a sane range
- asset (token) address declared
- network resolves to CAIP-2
- payment scheme declared
- served over HTTPS
- declares the current x402 version (2)
- EIP-712 domain parameters present on every EVM entry
- x402 v2 envelope delivered in the payment-required header
SITE PILLARS
- homepage reachable
- openapi doc
- pricing page
- llms.txt
- robots.txt
- terms page
recent checks (7) live · click to expand
EMBED THIS BADGE
<a href="https://x402-list.com/services/lazaretto?utm_source=badge&utm_medium=referral&utm_campaign=embed"> <img src="https://x402-list.com/badge/lazaretto.svg" alt="Lazaretto listed on x402-list" height="28"> </a>
[](https://x402-list.com/services/lazaretto?utm_source=badge&utm_medium=referral&utm_campaign=embed)
<a href="https://x402-list.com/services/lazaretto?utm_source=badge&utm_medium=referral&utm_campaign=embed"> <img src="https://x402-list.com/badge/lazaretto.svg?data=uptime" alt="Lazaretto uptime on x402-list" height="28"> </a>