Guides
Package guard
Check packages before an agent installs them — hallucinated names, malicious packages, known vulnerabilities and typosquats — via MCP, REST or a Claude Code hook.
Coding agents sometimes invent package names. Attackers watch for those names and register them ("slopsquatting"), so the next agent that hallucinates the same name installs malware. The package guard checks every package before it is installed.
What is checked
| Check | Source | Verdict |
|---|---|---|
| The package exists in the registry | deps.dev, then the registry itself for brand-new packages | missing → block |
| The requested version was published | deps.dev / registry | missing → block |
Malicious-package report (MAL-…) | OSV | block |
| Known vulnerabilities in that version, with the fixed version | OSV (GHSA, PyPA, Go, RustSec…) | warn |
| Deprecated or yanked | deps.dev / crates.io | warn |
| First published less than 30 days ago | deps.dev / registry | warn |
| Fewer than 500 downloads last week (npm) | api.npmjs.org | warn |
Name one or two edits away from a popular package (expres, reqeusts) | CodexGuild list | warn |
block means do not install. warn means tell the user why before installing. ok means nothing was found.
unknown means a lookup failed. The guard never blocks because of an outage.
Ecosystems: npm, pypi, go, cargo. Only names and versions are sent.
MCP
codexguild_check_packages { packages: [{ name: "zod", ecosystem: "npm", version: "^3.25.0" }] }REST
curl -s -X POST https://api.codexguild.com/v1/packages/check \
-H "Authorization: Bearer $CODEXGUILD_API_KEY" -H "content-type: application/json" \
-d '{"packages":[{"name":"reqeusts","ecosystem":"pypi"},{"name":"lodash","ecosystem":"npm","version":"4.17.15"}]}'Claude Code hook (automatic)
The local MCP package also contains a PreToolUse hook. It reads each Bash command before it runs and finds
installs:
npm/pnpm/yarn/bun addnpx,bunx,pnpm dlxpip install,uv add,uvx,poetry add,pipxcargo addgo get
If a package is blocked, the hook denies the command and tells the agent why. If a package gets a warning,
Claude Code asks you before the command runs. Lockfile installs (npm ci, npm install with no
arguments) and local paths are never checked.
Add it to ~/.claude/settings.json (or the project's .claude/settings.json):
{
"env": { "CODEXGUILD_API_KEY": "cgk_..." },
"hooks": {
"PreToolUse": [
{ "matcher": "Bash", "hooks": [{ "type": "command", "command": "npx -y @codexguild/mcp@latest guard", "timeout": 20 }] }
]
}
}If the key is missing or CodexGuild can't be reached, the hook lets the command run and prints a note.