io.github.julian-martin89/pkg-oracle

pkg-oracle — Dependency Trust Oracle

Blocks typosquatted or hallucinated npm/PyPI packages before an AI agent installs them.

1.0.1
Version
remote
Transport
1
Tools

Security review

Review passed

Reviewed Jan 1, 2000.

  • tools: 1 tools scanned
  • metadata: scanned

No findings.

Tools (1)

  • verify_package

    Dependency Trust Oracle. Call this BEFORE writing any package into a manifest (package.json, requirements.txt, pyproject.toml, Cargo.toml, ...). It checks whether the package actually exists on its registry, cross-references OSV.dev for known CVEs, pulls the package's OpenSSF Scorecard via deps.dev, and runs a Levenshtein-distance typosquat/slopsquat check against a curated list of popular packages combined with the package's publish age. Returns a synthetic verdict: ALLOW (no issues found), WARN (proceed with caution — read the findings before installing), or BLOCK (do not install — likely a hallucinated package name, an active typosquat, or a known critical/high-severity vulnerability). Always call this before running an install command for a package you have not already verified in this session. First 5 calls per caller are free; after that this tool requires x402 payment (USDC on Base) and will return a payment-required error with the amount and address to pay.