pkgguard
Checks npm packages against the live registry before installation, verifying existence, age, adoption, release history, provenance, and security holds, and flagging hallucinated or slopsquatted packages.
Planned support for the same package verification on PyPI, detecting hallucinated or malicious Python packages before installation.
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@pkgguardcheck express-async-router-utils-pro before installing"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
vetpkg
Stop AI coding agents installing packages that don't exist.
Zero dependencies. Works as an MCP server, a CLI, or a library.
npx vetpkg express-async-router-utils-pro none express-async-router-utils-pro risk 100
! No package by this name exists on the registry. If an AI assistant
suggested it, it was invented.
! Closest real package is "express-async-router" — every word in the
shorter name appears in "express-async-router".
=> Do not install. The intended package was most likely "express-async-router".The problem
AI coding assistants recommend packages that do not exist about 19.7% of the time (576,000-sample study). Open-weight models average 21.7%; commercial models around 5.2%.
That alone would just be annoying. What makes it dangerous is that the hallucinations repeat. When researchers re-ran 500 prompts that had produced a fabricated package name, 43% returned the same fabricated name every single time.
A predictable hallucination is an attackable one. The attack is called slopsquatting:
A model invents a plausible package name that has never existed.
An attacker registers that exact name on npm.
The next developer — or autonomous agent — who runs the install command pulls attacker-controlled code straight into the build.
This is not hypothetical. unused-imports is the textbook case: models hallucinate it instead of the real eslint-plugin-unused-imports. react-codeshift was claimed in January 2026.
Meanwhile over 50% of organisations have already had an outage or security incident from AI-generated code using outdated or wrong APIs (Snyk). Models are trained infrequently — a model shipped this summer can be confidently wrong about a library that changed a year ago.
Related MCP server: npmguard
What vetpkg does
It answers one question, before anything gets installed:
Is this a real, established package — or did a model invent it?
It checks the live registry and scores what it finds:
Signal | Why it matters |
Existence | The package may simply not be real. |
Name similarity | Catches three distinct shapes — typos, token subsets, and reshapes. |
Age | Slopsquats are registered after the hallucination becomes common. |
Adoption | Real packages have sustained downloads; squats have almost none. |
Release history | One version, published once, never updated is a throwaway registration. |
Provenance | No linked repository means the code can't be reviewed. |
Security holds | npm seizes malicious packages; that's detected and hard-blocked. |
No single signal is proof. The giveaway is the combination — brand new, barely downloaded, published once, no repository, and named a near-miss of something popular. Real packages essentially never look like that.
Why name similarity needs three mechanisms
Edit distance alone misses the most common real-world shape:
Shape | Example | Caught by |
Typo |
| edit distance 1 |
Subset |
| edit distance is 14 — only token analysis catches this |
Reshape |
| normalisation |
The subset shape is exactly what models produce when they "simplify" a name they half-remember, and it's the shape of the documented unused-imports incident. A tool checking only edit distance will miss it.
Use it as an MCP server
This is the point. A CLI only helps if you remember to run it. An MCP server sits inside the agent's tool loop, so the check happens automatically, at the moment the agent is about to install something.
Claude Desktop / Claude Code — add to claude_desktop_config.json:
{
"mcpServers": {
"vetpkg": {
"command": "npx",
"args": ["-y", "vetpkg", "vetpkg-mcp"]
}
}
}Cursor — add to .cursor/mcp.json:
{
"mcpServers": {
"vetpkg": { "command": "npx", "args": ["-y", "vetpkg", "vetpkg-mcp"] }
}
}Two tools are exposed:
check_package— verify one packagecheck_packages— verify several at once
Then tell your agent, once: "Always check packages with vetpkg before installing them."
Use it as a CLI
# check specific packages
npx vetpkg express react lodash
# check everything in package.json
npx vetpkg scan
# production dependencies only
npx vetpkg scan --prod
# machine-readable
npx vetpkg express --jsonExits non-zero if anything is suspicious, blocked, or missing — so it works as a CI gate or a pre-install hook:
{ "scripts": { "preinstall": "vetpkg scan || true" } }Use it as a library
import { checkPackage } from 'vetpkg';
const result = await checkPackage('unused-imports');
result.verdict; // 'trusted' | 'caution' | 'suspicious' | 'blocked' | 'not_found'
result.risk; // 0–100
result.reasons; // [{ severity, text, points }]
result.recommendation; // plain-English next step
result.similar; // closest real packages, if anyFAQ
Does this replace npm audit or Socket?
No, and it isn't trying to. npm audit finds known vulnerabilities in packages you already trust. vetpkg asks whether the package should be trusted at all — whether it's real, and whether it's what you meant. Run both.
Why not just check if the package exists? Because the dangerous case is that it does exist. Once an attacker registers a hallucinated name, an existence check passes and hands you the payload. Existence is the easy half.
Will it flag legitimate new packages?
Sometimes, and deliberately. A brand-new package with no downloads is genuinely unverifiable — that's caution, not suspicious. The scoring only reaches suspicious when several independent signals agree.
Does it flag popular packages with similar names?
No. Packages with real adoption are exempt from name-similarity scoring — express is not warned about for resembling cypress. Slopsquats are by construction new and unused, so similarity only carries risk for packages that aren't established.
Does it send my dependency list anywhere? No. It queries the public npm registry directly from your machine. There is no telemetry and no account.
Which registries are supported? npm today. PyPI is next — the same attack works there, and the research covering it sampled both.
Why zero dependencies? A tool that vets your dependency tree shouldn't arrive with one.
How scoring works
Verdict | Risk | Meaning |
| 0–27 | Established, normal publication history. |
| 28–54 | Unverifiable or unusual. Look before installing. |
| 55–99 | Several signals agree. Do not install without checking. |
| 100 | Security-held by npm. Never install. |
| 100 | Does not exist. If an AI suggested it, it was invented. |
Limitations
Worth being straight about:
A determined attacker can fake the signals. Downloads can be inflated and repositories can be fabricated. This raises the cost of the attack; it does not make it impossible.
The bundled name corpus is a snapshot. A squat targeting a package that isn't in the corpus won't be caught by similarity — though the age, adoption and provenance signals still apply.
New legitimate packages score low. That's correct behaviour, not a bug, but it means low scores need judgement rather than blind obedience.
Licence
MIT
This server cannot be installed
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Servers
- AlicenseAqualityFmaintenanceActs as a security checkpoint for AI coding agents by intercepting package installations to verify existence, check against CVE databases, and block vulnerable or hallucinated dependencies before they reach your codebase. Provides seven security tools including pre-install gates, full project audits, safe version recommendations, and deep transitive dependency scanning for npm and PyPI packages.7134MIT
- AlicenseAqualityBmaintenancePre-install risk gate for npm packages. Stops AI coding agents from running malicious or lifecycle scripts run.12MIT
- FlicenseNot gradedqualityCmaintenanceGrants AI agents real-time access to the NPM registry, enabling package metadata retrieval, version checks, and dependency auditing for up-to-date code generation.213
- AlicenseNot gradedqualityCmaintenanceAudits npm packages for supply-chain attacks (typosquatting, malicious install scripts, credential exfiltration) before installation, returning a SAFE/SUSPICIOUS/DANGEROUS verdict.MIT
Related MCP Connectors
Provide AI-powered real-time analysis and intelligence on NPM packages, including security, depend…
Package intelligence for AI agents across npm, PyPI, crates.io and deps.dev. No API keys.
npm, PyPI & crates.io intel for AI agents: versions, popularity, deps, health. No API keys.
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/kiansaeidnia/vetpkg'
If you have feedback or need assistance with the MCP directory API, please join our Discord server