Security scanner MCP server for AI coding agents. Prompt injection firewall, package hallucination detection (4.3M+ packages), 1000+ vulnerability rules with AST & taint analysis, auto-fix.
-
Updated
Sep 30, 2026 - JavaScript
Security scanner MCP server for AI coding agents. Prompt injection firewall, package hallucination detection (4.3M+ packages), 1000+ vulnerability rules with AST & taint analysis, auto-fix.
Open-source AI package security gate that blocks slopsquatting, hallucinated dependencies, and typosquats before npm, pip, uv, or cargo install
Flag hallucinated, slopsquatted, and proxy-blocklisted malicious Go module names in your go.mod. go install, no registry signup needed.
Do the package names that LLMs invent actually get claimed? Code, data, and preprint for a registration census of AI-hallucinated packages (slopsquatting).
Investigating how often LLMs recommend non-existent packages, enabling slopsquatting supply-chain attacks.
Catch hallucinated / slopsquatted dependency names before you install them (PyPI + npm)
AI code reviewer that catches hallucinations in AI‑generated code: deprecated APIs, non‑existent packages, security anti‑patterns, and unnecessary complexity. Runs as CLI, VS Code extension, or in CI. Static analysis is free; AI‑powered checks cost pennies.
To associate your repository with the package-hallucination topic, visit your repo's landing page and select "manage topics."