ExactGround logo

Stop AI coding agents from installing packages that don't exist

ExactGround is a free, open-source guard for Claude Code, Codex, Gemini CLI and Cursor. It checks every npm/pnpm/yarn/bun/npx and pip/uv/poetry install, and every new dependency written into a manifest, against the public npm registry and PyPI before the command runs. It blocks hallucinated package names (the root of slopsquatting), versions that were never published, young look-alikes of popular packages and npm security placeholders.

GitHub (MIT)Hosted MCP API

$ npx -y github:alidaram99/exactground check pypi:requests pypi:reqeusts react@99.0.0
OK      pypi:requests
BLOCK   pypi:reqeusts — "reqeusts" does not exist on PyPI; did you mean "requests"? (it is 1 edit away)
BLOCK   react@99.0.0 — version 99.0.0 of "react" was never published (latest is 19.3.0)

Why

A USENIX Security 2025 study generated 2.23 million code samples with 16 models: 19.7% referenced at least one package that does not exist, and 43% of invented names reappeared on every rerun of the same prompt (paper). Attackers register those names (slopsquatting). Coding agents run installs without a human reading the name, and a rule in CLAUDE.md is text the model may ignore. A hook runs every time.

Install in your agent

AgentHowHook
Claude Codeclaude plugin marketplace add alidaram99/exactground
claude plugin install exactground@exactground-marketplace
PreToolUse on Bash, Write, Edit, MultiEdit
Codexcodex plugin marketplace add alidaram99/exactground --ref v0.1.0 then trust it in /hooksPreToolUse on Bash and apply_patch
Gemini CLIexactground init gemini --writeBeforeTool
Cursorexactground init cursor --writebeforeShellExecution

Version-exact API checks (MCP)

Real packages are also used wrongly: useActionState in a React 18 project, numpy.asfarray after NumPy 2.0 removed it. The hosted ExactGround API reads the published package (npm .d.ts via the TypeScript compiler, Python wheels parsed statically, never executed) and answers per symbol. check_symbols $0.002/symbol · check_packages $0.0005/package · check_diff $0.01/diff.

claude mcp add --transport http exactground https://dropin-apis--exactground-api.apify.actor/mcp \
  --header "Authorization: Bearer $APIFY_TOKEN"

FAQ

How do I stop Claude Code from installing hallucinated npm or PyPI packages?

Install the free ExactGround Claude Code plugin: run claude plugin marketplace add alidaram99/exactground and claude plugin install exactground@exactground-marketplace. Its PreToolUse hook checks every install command and every package.json, requirements.txt or pyproject.toml edit against the npm registry and PyPI, and denies the tool call when a package name does not exist.

What is slopsquatting?

Slopsquatting is registering a package name that AI models hallucinate, so that agents or developers who trust the suggestion install the attacker's code. A USENIX Security 2025 study found that 19.7% of 2.23 million AI-generated code samples referenced at least one package that does not exist, and 43% of invented names recurred on every rerun.

Does ExactGround work with Codex, Gemini CLI and Cursor?

Yes. Codex uses a PreToolUse hook on Bash and apply_patch, Gemini CLI a BeforeTool hook, and Cursor a beforeShellExecution hook. Run exactground init <agent> --write in your project.

How do I check that a function exists in the exact version of a package?

Use the hosted ExactGround API, an MCP server at https://dropin-apis--exactground-api.apify.actor/mcp. Its check_symbols tool reads npm type declarations with the TypeScript compiler and Python wheels statically, and answers exists true, false or null for a symbol in a specific version. It costs $0.002 per symbol.

Is ExactGround free?

The local guard (CLI and agent hooks) is free and MIT-licensed. Only the hosted version-exact API is paid per check through Apify.

Is an agent hook a security boundary?

No. Hooks are guardrails: vendors document that they can time out or be bypassed. ExactGround fails open on registry outages unless strict mode is on. Keep lockfiles, CI checks and an install-time scanner as well.

MIT · Not affiliated with npm, PyPI, Anthropic, OpenAI, Google or Cursor · llms.txt