verify_dependencies
Verify that every external dependency in code or diffs exists on PyPI or npm, catching hallucinated package names and slopsquatting supply-chain risks.
Instructions
Verify that every external dependency introduced by code or a diff actually exists on its public registry - the mechanical half of gate G4 (Dependency Honesty). LLMs hallucinate package names and attackers register them (slopsquatting), so a missing registry entry is both an incompleteness defect and a supply-chain risk. Extracts imports (Python via AST incl. importlib/import literals; JS/TS via import/require specifiers), classifies stdlib/Node built-ins/first-party-in-diff/excluded locally, then checks the rest against PyPI (PEP 503) and the npm registry. NETWORK NOTICE: this is the only tool here that touches the network - package names and nothing else are sent over HTTPS, bounded (50 packages/call, 10s timeout, 3 attempts). Verdicts: FAIL = something does not exist (hallucinated/misspelled); REVIEW = unverifiable (offline/registry errors - never silently passed); PASS = everything resolves. Existence only: version pinning and integrity stay with the reviewer.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| code | No | Source text to extract imports from (requires 'language'). | |
| diff | No | Unified diff; imports are extracted from added lines of Python/JS/TS files with new-file line numbers. Exactly one of 'code' and 'diff'. | |
| exclude | No | fnmatch globs for package names that must never be sent to a registry (private/internal packages). | |
| language | No | Language of 'code'. |