Guides

Package guard

Check packages before an agent installs them — hallucinated names, malicious packages, known vulnerabilities and typosquats — via MCP, REST or a Claude Code hook.

Coding agents sometimes invent package names. Attackers watch for those names and register them ("slopsquatting"), so the next agent that hallucinates the same name installs malware. The package guard checks every package before it is installed.

What is checked

CheckSourceVerdict
The package exists in the registrydeps.dev, then the registry itself for brand-new packagesmissing → block
The requested version was publisheddeps.dev / registrymissing → block
Malicious-package report (MAL-…)OSVblock
Known vulnerabilities in that version, with the fixed versionOSV (GHSA, PyPA, Go, RustSec…)warn
Deprecated or yankeddeps.dev / crates.iowarn
First published less than 30 days agodeps.dev / registrywarn
Fewer than 500 downloads last week (npm)api.npmjs.orgwarn
Name one or two edits away from a popular package (expres, reqeusts)CodexGuild listwarn

block means do not install. warn means tell the user why before installing. ok means nothing was found. unknown means a lookup failed. The guard never blocks because of an outage.

Ecosystems: npm, pypi, go, cargo. Only names and versions are sent.

MCP

text
codexguild_check_packages { packages: [{ name: "zod", ecosystem: "npm", version: "^3.25.0" }] }

REST

bash
curl -s -X POST https://api.codexguild.com/v1/packages/check \
  -H "Authorization: Bearer $CODEXGUILD_API_KEY" -H "content-type: application/json" \
  -d '{"packages":[{"name":"reqeusts","ecosystem":"pypi"},{"name":"lodash","ecosystem":"npm","version":"4.17.15"}]}'

Claude Code hook (automatic)

The local MCP package also contains a PreToolUse hook. It reads each Bash command before it runs and finds installs:

  • npm / pnpm / yarn / bun add
  • npx, bunx, pnpm dlx
  • pip install, uv add, uvx, poetry add, pipx
  • cargo add
  • go get

If a package is blocked, the hook denies the command and tells the agent why. If a package gets a warning, Claude Code asks you before the command runs. Lockfile installs (npm ci, npm install with no arguments) and local paths are never checked.

Add it to ~/.claude/settings.json (or the project's .claude/settings.json):

json
{
  "env": { "CODEXGUILD_API_KEY": "cgk_..." },
  "hooks": {
    "PreToolUse": [
      { "matcher": "Bash", "hooks": [{ "type": "command", "command": "npx -y @codexguild/mcp@latest guard", "timeout": 20 }] }
    ]
  }
}

If the key is missing or CodexGuild can't be reached, the hook lets the command run and prints a note.