Stop AI coding agents from installing packages that do not exist
Last updated:
Check that a package exists on the registry before an AI agent installs it. Code models invent plausible package names, and attackers can register those names. ExactGround's free hook blocks installs of names that do not exist in Claude Code, Codex, Gemini CLI and Cursor, and its hosted API answers the stricter question: does this function exist in the exact version you use?
Facts on this page were checked against the linked sources and ExactGround v0.1.5 on October 4, 2026.
How often agents invent packages
- In the USENIX Security 2025 study by Spracklen et al., 16 models generated 576,000 code samples. Of the 2.23 million packages they referenced, 440,445 (19.7%) did not exist, and there were 205,474 unique invented names (paper).
- The rate was at least 5.2% for commercial models and 21.7% for open-source models.
- The names repeat. The authors re-ran 500 prompts that had produced a hallucination, 10 times each. In that sample, 43% of the hallucinated package names came back in all 10 runs, and 39% did not come back at all. Repeatable names are what make registering them with malware (slopsquatting) practical.
- Trend Micro's follow-up study of 100 web-development tasks compared reasoning-enhanced coding agents with "vibe coding" plus live MCP validation, and concluded that "neither method fully eliminates the threat" (technical brief; dataset).
A rule in CLAUDE.md or AGENTS.md saying "never invent packages" is text the model may ignore. A hook is code that runs on every install.
Exists is not the same as safe
There are four separate questions, and a registry lookup answers only the first:
| Question | Who answers it |
|---|---|
| 1. Does the name exist on npm or PyPI? | ExactGround hook (free) and check_packages |
| 2. Is it the package you meant, from the expected owner, and not a fresh look-alike? | ExactGround flags young, rarely downloaded look-alikes of popular names and npm security placeholders. Ownership and provenance need your own review or a supply-chain scanner. |
| 3. Was this exact version published? | ExactGround hook and check_packages |
| 4. Does the function or method the agent calls exist in that version? | ExactGround API check_symbols / check_diff |
A package that exists can still be malicious, or a legitimate package can be compromised. ExactGround does not scan package contents. Pair it with a malware or supply-chain scanner and your lockfile.
Try it in one line
$ npx -y github:alidaram99/exactground#v0.1.5 check pypi:requests pypi:reqeusts react@99.0.0
OK pypi:requests
BLOCK pypi:reqeusts — "reqeusts" does not exist on PyPI; did you mean "requests"? (it is 1 edit away)
BLOCK react@99.0.0 — version 99.0.0 of "react" was never published (latest is 19.3.0)Install it in your agent
- Claude Code:
claude plugin marketplace add alidaram99/exactground, thenclaude plugin install exactground@exactground-marketplace. - Codex:
codex plugin marketplace add alidaram99/exactground --ref v0.1.5, then trust the hook in/hooks. - Gemini CLI and Cursor:
exactground init gemini --writeorexactground init cursor --writein your project.
What the hook covers:
npm,pnpm,yarn,bun,npx,pip,uv,poetryandpdminstall commands it can parse.- Bare installs such as
npm install,uv syncandpoetry install, checked against the lockfile, so a dependency the agent wrote intopackage.jsonorpyproject.tomlis caught too. - Private packages: list them in
.exactground.jsonand approve that file withexactground trustin a terminal. The hook ignores a policy file that no human approved.
Commands it cannot check are denied, not waved through. That covers installs inside node -e, python -c, $(...) and eval, program names built at run time (such as & ('np'+'m')), and loops or installs whose program or package name is a variable. A loop with a literal npm, npx or pip in its body is checked like any other command. If the registry or the checker fails, the hook denies too.
Out of scope, on purpose. ExactGround is a cooperative guardrail, not a sandbox. It stops an agent that hallucinates or mistypes a name in a normal install command. An agent running as your user that deliberately obfuscates its commands can defeat any hook-based guard, including this one. Examples include writing its own scripts, or building names and paths at run time in ways no rule anticipates. For an agent you treat as adversarial, use an OS sandbox or container, or a separate OS user (SECURITY.md).
Check that an API exists in your exact version
Many hallucinations are real packages used wrongly. useActionState does not exist in React 18, and numpy.asfarray was removed in NumPy 2.0. The hosted ExactGround API answers these questions from the published package itself:
- npm:
.d.tsdeclarations, read with the TypeScript compiler. - Python: wheels, parsed statically and never executed.
The API has been live on the Apify Store since October 3, 2026. Calls need your Apify API token.
It is an MCP server billed per check:
check_symbols: $0.002 per symbol.check_packages: $0.0005 per package.check_diff: $0.01 per diff.
claude mcp add --transport http exactground https://dropin-apis--exactground-api.apify.actor/mcp --header "Authorization: Bearer $APIFY_TOKEN"FAQ
What is slopsquatting?
Slopsquatting means registering a package name that AI models tend to invent, so that agents and developers who trust the suggestion install the attacker's code.
Does a package existing on npm or PyPI mean it is safe?
No. Existence rules out invented names and versions that were never published. Whether the package is the one you meant, who owns it, and what its code does are separate checks.
Can ExactGround stop an agent that is trying to get around it?
Not reliably, and it does not claim to. It is built for agents that make mistakes, not agents that evade. Contain adversarial agents with an OS sandbox, a container or a separate user.