We don't tell you your code is safe — no honest tool can. We tell you, provably, that it was inspected, and hand you a receipt your client can verify themselves, offline, without trusting us.
When a model hallucinates a dependency, the name doesn't error — it's just unclaimed. That gap is the whole attack, and AI made it far wider. Here's the mechanism, then the history.
It looks plausible — flask-gpt-helper — so it slips past review.
The name isn't blocked. It's simply unowned — free for anyone to claim.
Now their code runs on every developer machine and CI box that resolves it.
An 11-line package unpublished, breaking builds across npm.
Typosquats that exfiltrated environment variables on install.
A maintainer handover shipped a malicious payload widely.
A hijacked release, millions of weekly downloads, shipped a stealer.
Dependency-confusion on PyPI shadowed a PyTorch nightly.
The MCP tool runs inside your agent loop and checks each proposed dependency against the real registry at generation time — before the diff, before install, before CI. The hallucinated package never enters your tree.
Works with Claude Code, Cursor and Copilot agent mode. No account, no key.
No feature here is aspirational — each maps to a check that runs in the shipped detector. Where a check can't be certain, it says so.
404 → flagged. Fails open on network error and says so — never a silent pass.
One character or one token off a real name, and lookalike glyphs.
Under 30 days old is surfaced, not blocked — your call.
postinstall hooks, missing SLSA provenance, deprecated, no source repo.
Real key shapes + Shannon entropy; doc-example keys downgraded.
Cross-file taint: is this critical actually reachable from an entry point?
A second pass explains context and marks what the static layer over-called.
Ed25519 certificate, verifiable offline, without us.
Checked before the line reaches your tree. The bad name never becomes a commit.
Where install-time scanners act. By now it's already written down.
Where SAST runs. Graneth posts a verdict here too — plus the signed receipt.
Under NIS2 and the CRA your DACH client pushes their obligations down to you. "Show me you checked" is answerable with a signed artifact; a PDF scan report isn't. The verifier is open source with zero runtime dependencies.
Which checks ran, against which commit, at which UTC instant. Signed.
That the code is secure. No scanner can sign that.
No. It means the checks we ran, ran — and names which. Proof of diligence, not a guarantee.
No — we run it. The dataset and matrix are published so you can judge it, including two failures it caught in our own product.
Complementary. They act when the package resolves; we act when the agent writes the name. Run both.
The MCP tool checks staged manifests locally. Deep scans need repo access — data-flow is on /trust.
Yes. npx -y @graneth/mcp-server — no signup, no key.
You shouldn't. Trust the signature. Everything else is just legible.