typosquat_check
Call before installing a package whose name you typed or recalled. Checks whether an npm or PyPI package name is a near-miss of a well-known package (typosquatting), with an edit-distance threshold scaled to name length; names of 3 characters or fewer are not fuzzy-matched. Uses a curated list of popular names, so a clean result does not prove a package is safe. It does not check that the package exists: supply_chain_check does.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| package | Yes | Package name to check for likely typosquatting of a well-known package in the given ecosystem. | |
| ecosystem | Yes | Package ecosystem, e.g. npm or PyPI. |