Catch hallucinated, squatted, unpublished, or vulnerable dependencies — grades the packages in your lockfiles against the live registry + OSV.
Account-free MCP server: catch AI-hallucinated packages and hardcoded secrets before you commit. Exposes the free pre_flight_check tool over stdio.
Catch AI-hallucinated (slopsquatted) npm imports in generated code BEFORE npm install. Scans a code block, flags imports of packages that don't exist on npm (the name an LLM invented and attackers register with malware) plus fresh lookalike squats. MCP se
A firewall between AI coding agents and dangerous actions. Blocks hallucinated packages, leaked secrets, destructive commands, and test-subversion.