
ExactGround
io.github.alidaram99v0.1.0更新于 Oct 2, 2026
Check npm/PyPI packages exist and that a function or method exists in an exact package version.
概览
在 AI 编程助手安装或导入之前,检查 npm 与 PyPI 包名、版本和符号是否存在。
- 功能
- ExactGround 会对照公开的 npm registry 与 PyPI 核实软件包的真实性。其托管的 MCP 工具包括 check_packages(确认包或指定版本是否存在)、check_symbols(确认某个函数或方法在确切版本中是否存在)以及 check_diff(检查一次变更新增的所有导入)。它还会标记相似名称、从未发布的版本以及 npm 安全占位包。
- 适用场景
- 当助手编写或执行安装命令、修改依赖时使用,可在安装前发现虚构或仿冒的包名以及从未发布的版本。它面向 Claude Code、Codex、Gemini CLI、Cursor 等编程助手。
- 运行要求
- 通过 streamable HTTP 访问的远程 MCP 端点。需要 Authorization 头,值为 Bearer Apify API 令牌。需要能访问该端点以及公开的 npm 和 PyPI registry。本地 CLI 防护需要 Node.js 20 或更高版本。
安装
在 SourceWeft 中
- 打开 控制台中的 ExactGround,将其添加到工作区。
- 为需要使用其工具的对话启用该服务。
Web executable,通过 Streamable HTTP。 远程服务在工作区中配置后即可从网页运行时运行。
其他 MCP 客户端
把它添加到你客户端的 mcpServers 配置中。
{
"mcpServers": {
"exactground": {
"type": "http",
"url": "https://dropin-apis--exactground-api.apify.actor/mcp"
}
}
}README
ExactGround: stop AI coding agents from installing packages that do not exist
ExactGround is a free, open-source guard for AI coding agents (Claude Code, Codex, Gemini CLI, Cursor). It checks every npm/pnpm/yarn/bun/npx and pip/uv/poetry/pdm/pipx install, and every new dependency written into a manifest, against the public npm registry and PyPI before the command runs. It blocks:
- package names that do not exist (hallucinated packages, the root of "slopsquatting");
- versions that were never published;
- young or little-used look-alikes of popular packages;
- npm security placeholders.
It has zero dependencies, runs locally and is MIT-licensed. An optional hosted API also answers "does this function exist in this version?".
[CI] · Website: https://alidaram99.github.io/exactground/ · Hosted API: https://apify.com/dropin-apis/exactground-api
Why this matters
- Package hallucination is common and repeatable. The USENIX Security 2025 study We Have a Package for You! generated 2.23 million code samples with 16 models. 19.7% referenced at least one package that does not exist (205,474 unique names). 43% of hallucinated names reappeared on all 10 reruns of the same prompt (paper).
- Slopsquatting turns that into an attack: someone registers the invented name with malware, and the next agent that runs
pip install <invented-name>installs it (Wikipedia; CSA research note, 2026).huggingface-cli(above) is the classic example: a name models invent for the realhuggingface_hub[cli]. - Agents install without a human looking. A rule like "don't invent packages" in
CLAUDE.mdorAGENTS.mdis text the model may ignore, especially after context compaction. A hook is code that runs every time.
Quick start
Node.js 20 or newer. No install needed:
For hooks, use a local checkout (faster, and no download on every tool call):
Add it to your coding agent
exactground init <agent> prints the exact config with absolute paths for your checkout. --write merges it into the current project and keeps your existing hooks.
Claude Code (plugin)
The plugin registers a PreToolUse hook on Bash|Write|Edit|MultiEdit.
- A blocked install is denied with the reason shown to Claude, for example: "reqeusts" does not exist on PyPI; did you mean "requests"?
- Warnings are allowed and passed to Claude as context.
Manual alternative: node ~/tools/exactground/bin/exactground.mjs init claude --write.
Codex
Install the plugin, then review and trust the hook in /hooks; Codex only runs trusted hooks. Manual alternative: exactground init codex --write writes .codex/hooks.json, with PreToolUse on Bash and apply_patch, so patches that add dependencies to package.json, requirements.txt or pyproject.toml are checked too.
Gemini CLI
exactground init gemini --write adds a BeforeTool hook for run_shell_command|write_file|replace to .gemini/settings.json.
Cursor
exactground init cursor --write adds a beforeShellExecution hook to .cursor/hooks.json. Cursor cannot block file edits before they happen, so ExactGround catches the follow-up npm install/pip install/uv sync instead: a bare install checks every manifest dependency that is not yet in the lockfile.
What it checks
Where it looks:
- direct installs;
npx/pnpm dlx/bunx/uvxruns;pip install -rfiles, including nested-r;- bare
npm install/yarn/pnpm install/uv sync/poetry install(dependencies missing from the lockfile); Write/Editofpackage.json,requirements*.txtandpyproject.toml;- Codex
apply_patch.
Commands wrapped in bash -lc "…" are unwrapped.
Configuration: optional .exactground.json at the project root:
Lookups are cached for 24 hours in ~/.cache/exactground (misses for 30 minutes, so a name registered later is noticed).
Version-exact API checks (hosted, pay per check)
Most hallucinations are real packages used wrongly: useActionState in a React 18 project, or numpy.asfarray after NumPy 2.0 removed it. The ExactGround API answers those questions from the published package itself: npm .d.ts via the TypeScript compiler, and Python wheels parsed statically, without running any code. It is an MCP server:
From the CLI: APIFY_TOKEN=… exactground api check_symbols '{"ecosystem":"pypi","package":"numpy","version":"2.1.0","symbols":["numpy.asfarray"]}'.
How it compares
These work together. ExactGround is the cheap gate in front of the install, and Socket and audits cover the security of real packages.
FAQ
How do I stop Claude Code from installing hallucinated npm or PyPI packages?
Install the ExactGround Claude Code plugin (two commands above). Its PreToolUse hook checks the package names in every Bash install command and every package.json/requirements.txt/pyproject.toml edit, and denies the tool call if a name does not exist.
What is slopsquatting?
Registering a package name that AI models hallucinate, so that agents and developers who trust the suggestion install the attacker's code. The term was coined by Seth Larson; the USENIX 2025 study measured how often models invent names.
Does ExactGround send my code anywhere?
The local guard sends only package names to the public registries (registry.npmjs.org, api.npmjs.org, pypi.org), the same requests your package manager makes. The hosted API receives only what you send to it.
Will it block my private packages?
Not if you list them in .exactground.json (allow or privateScopes). A missing name only warns when pip/uv use a custom --index-url.
Does it slow the agent down?
A check is one cached HTTP request per new package name, usually 100–400 ms, and nothing for commands that do not install anything.
Is a hook a security boundary?
No. Agent hooks are guardrails. Claude Code and Codex document that hooks can time out or be bypassed, Codex hosted tools are not hooked, and Cursor cannot block file edits before they happen. ExactGround fails open on internal errors and registry outages unless you set strict. Keep lockfiles, CI checks and an install-time scanner too.
Which ecosystems are supported?
npm (npm, pnpm, yarn, bun, npx) and PyPI (pip, uv, poetry, pdm, pipx, uvx).
Development
Popular-package lists come from npm-high-impact (MIT) and top-pypi-packages (see data/).
License
MIT. Not affiliated with npm, PyPI, Anthropic, OpenAI, Google or Cursor.
来源:README.md,提交 99c55f1
工具
0版本历史
1- v0.1.0最新Oct 2, 2026

