Security scanner MCP server for AI coding agents. Prompt injection firewall, package hallucination detection (4.3M+ packages), 1000+ vulnerability rules with AST & taint analysis, auto-fix.
-
Updated
Sep 3, 2026 - JavaScript
Security scanner MCP server for AI coding agents. Prompt injection firewall, package hallucination detection (4.3M+ packages), 1000+ vulnerability rules with AST & taint analysis, auto-fix.
Detect slopsquatting and AI-hallucinated package names before install. npm, PyPI, crates.io. 1% false positives, 7/7 threat recall.
Investigating how often LLMs recommend non-existent packages, enabling slopsquatting supply-chain attacks.
Do the package names that LLMs invent actually get claimed? Code, data, and preprint for a registration census of AI-hallucinated packages (slopsquatting).
AI code reviewer that catches hallucinations in AI‑generated code: deprecated APIs, non‑existent packages, security anti‑patterns, and unnecessary complexity. Runs as CLI, VS Code extension, or in CI. Static analysis is free; AI‑powered checks cost pennies.
To associate your repository with the package-hallucination topic, visit your repo's landing page and select "manage topics."