Stop AI coding agents from installing packages that do not exist

Last updated:

Check that a package exists on the registry before an AI agent installs it. Code models invent plausible package names, and attackers can register those names. ExactGround's free hook blocks installs of names that do not exist in Claude Code, Codex, Gemini CLI and Cursor, and its hosted API answers the stricter question: does this function exist in the exact version you use?

Facts on this page were checked against the linked sources and ExactGround v0.1.5 on October 4, 2026.

How often agents invent packages

A rule in CLAUDE.md or AGENTS.md saying "never invent packages" is text the model may ignore. A hook is code that runs on every install.

Exists is not the same as safe

There are four separate questions, and a registry lookup answers only the first:

QuestionWho answers it
1. Does the name exist on npm or PyPI?ExactGround hook (free) and check_packages
2. Is it the package you meant, from the expected owner, and not a fresh look-alike?ExactGround flags young, rarely downloaded look-alikes of popular names and npm security placeholders. Ownership and provenance need your own review or a supply-chain scanner.
3. Was this exact version published?ExactGround hook and check_packages
4. Does the function or method the agent calls exist in that version?ExactGround API check_symbols / check_diff

A package that exists can still be malicious, or a legitimate package can be compromised. ExactGround does not scan package contents. Pair it with a malware or supply-chain scanner and your lockfile.

Try it in one line

console
$ npx -y github:alidaram99/exactground#v0.1.5 check pypi:requests pypi:reqeusts react@99.0.0
OK      pypi:requests
BLOCK   pypi:reqeusts — "reqeusts" does not exist on PyPI; did you mean "requests"? (it is 1 edit away)
BLOCK   react@99.0.0 — version 99.0.0 of "react" was never published (latest is 19.3.0)

Install it in your agent

What the hook covers:

Commands it cannot check are denied, not waved through. That covers installs inside node -e, python -c, $(...) and eval, program names built at run time (such as & ('np'+'m')), and loops or installs whose program or package name is a variable. A loop with a literal npm, npx or pip in its body is checked like any other command. If the registry or the checker fails, the hook denies too.

Out of scope, on purpose. ExactGround is a cooperative guardrail, not a sandbox. It stops an agent that hallucinates or mistypes a name in a normal install command. An agent running as your user that deliberately obfuscates its commands can defeat any hook-based guard, including this one. Examples include writing its own scripts, or building names and paths at run time in ways no rule anticipates. For an agent you treat as adversarial, use an OS sandbox or container, or a separate OS user (SECURITY.md).

Check that an API exists in your exact version

Many hallucinations are real packages used wrongly. useActionState does not exist in React 18, and numpy.asfarray was removed in NumPy 2.0. The hosted ExactGround API answers these questions from the published package itself:

The API has been live on the Apify Store since October 3, 2026. Calls need your Apify API token.

It is an MCP server billed per check:

sh
claude mcp add --transport http exactground https://dropin-apis--exactground-api.apify.actor/mcp --header "Authorization: Bearer $APIFY_TOKEN"

FAQ

What is slopsquatting?

Slopsquatting means registering a package name that AI models tend to invent, so that agents and developers who trust the suggestion install the attacker's code.

Does a package existing on npm or PyPI mean it is safe?

No. Existence rules out invented names and versions that were never published. Whether the package is the one you meant, who owns it, and what its code does are separate checks.

Can ExactGround stop an agent that is trying to get around it?

Not reliably, and it does not claim to. It is built for agents that make mistakes, not agents that evade. Contain adversarial agents with an OS sandbox, a container or a separate user.