ExactGround is a free, open-source guard for Claude Code, Codex, Gemini CLI and Cursor. It checks every npm/pnpm/yarn/bun/npx and pip/uv/poetry install, and every new dependency written into a manifest, against the public npm registry and PyPI before the command runs. It blocks hallucinated package names (the root of slopsquatting), versions that were never published, young look-alikes of popular packages and npm security placeholders.
$ npx -y github:alidaram99/exactground check pypi:requests pypi:reqeusts react@99.0.0
OK pypi:requests
BLOCK pypi:reqeusts — "reqeusts" does not exist on PyPI; did you mean "requests"? (it is 1 edit away)
BLOCK react@99.0.0 — version 99.0.0 of "react" was never published (latest is 19.3.0)
A USENIX Security 2025 study generated 2.23 million code samples with 16 models: 19.7% referenced at least one package that does not exist, and 43% of invented names reappeared on every rerun of the same prompt (paper). Attackers register those names (slopsquatting). Coding agents run installs without a human reading the name, and a rule in CLAUDE.md is text the model may ignore. A hook runs every time.
| Agent | How | Hook |
|---|---|---|
| Claude Code | claude plugin marketplace add alidaram99/exactgroundclaude plugin install exactground@exactground-marketplace | PreToolUse on Bash, Write, Edit, MultiEdit |
| Codex | codex plugin marketplace add alidaram99/exactground --ref v0.1.0 then trust it in /hooks | PreToolUse on Bash and apply_patch |
| Gemini CLI | exactground init gemini --write | BeforeTool |
| Cursor | exactground init cursor --write | beforeShellExecution |
Real packages are also used wrongly: useActionState in a React 18 project, numpy.asfarray after NumPy 2.0 removed it. The hosted ExactGround API reads the published package (npm .d.ts via the TypeScript compiler, Python wheels parsed statically, never executed) and answers per symbol. check_symbols $0.002/symbol · check_packages $0.0005/package · check_diff $0.01/diff.
claude mcp add --transport http exactground https://dropin-apis--exactground-api.apify.actor/mcp \
--header "Authorization: Bearer $APIFY_TOKEN"
Install the free ExactGround Claude Code plugin: run claude plugin marketplace add alidaram99/exactground and claude plugin install exactground@exactground-marketplace. Its PreToolUse hook checks every install command and every package.json, requirements.txt or pyproject.toml edit against the npm registry and PyPI, and denies the tool call when a package name does not exist.
Slopsquatting is registering a package name that AI models hallucinate, so that agents or developers who trust the suggestion install the attacker's code. A USENIX Security 2025 study found that 19.7% of 2.23 million AI-generated code samples referenced at least one package that does not exist, and 43% of invented names recurred on every rerun.
Yes. Codex uses a PreToolUse hook on Bash and apply_patch, Gemini CLI a BeforeTool hook, and Cursor a beforeShellExecution hook. Run exactground init <agent> --write in your project.
Use the hosted ExactGround API, an MCP server at https://dropin-apis--exactground-api.apify.actor/mcp. Its check_symbols tool reads npm type declarations with the TypeScript compiler and Python wheels statically, and answers exists true, false or null for a symbol in a specific version. It costs $0.002 per symbol.
The local guard (CLI and agent hooks) is free and MIT-licensed. Only the hosted version-exact API is paid per check through Apify.
No. Hooks are guardrails: vendors document that they can time out or be bypassed. ExactGround fails open on registry outages unless strict mode is on. Keep lockfiles, CI checks and an install-time scanner as well.
MIT · Not affiliated with npm, PyPI, Anthropic, OpenAI, Google or Cursor · llms.txt