npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

pi-dependency-guard

v0.1.1

Published

Hallucination detector & package security audit extension for Pi Coding Agent

Readme


🛡️ Overview

pi-dependency-guard prevents AI hallucinations and supply-chain vulnerabilities from entering your project through Pi Coding Agent.

LLMs commonly hallucinate non-existent package names when writing import statements or proposing installation commands (e.g. npm i fast-auth-helper-ai). Attackers actively exploit this via package hallucination typosquatting, registering fabricated names on npm and PyPI with malicious payloads.

pi-dependency-guard intercepts install commands and validates every dependency against the official registries in real time before execution.

┌─────────────────┐       proposes install       ┌────────────────────────┐
│                 │ ───────────────────────────> │                        │
│    Pi Agent     │                              │  pi-dependency-guard   │
│                 │ <─────────────────────────── │                        │
└─────────────────┘        risk evaluation       └───────────┬────────────┘
                                                             │
                                          queries registry   │
                                                             ▼
                                                 ┌────────────────────────┐
                                                 │   npm / PyPI API       │
                                                 │ (404 -> Hallucinated)  │
                                                 └────────────────────────┘

✨ Features

  • 🚫 Zero Hallucinations: Instantly flags non-existent packages as CRITICAL risk.
  • 🌐 Direct Registry Verification: Hits official registry.npmjs.org and pypi.org endpoints without middlemen.
  • Age & Download Analysis: Warns on packages newer than 7 days or with fewer than 100 monthly downloads.
  • Multi-Ecosystem Parsing: Detects packages in npm install, pnpm add, yarn add, and pip install.
  • 🤖 Agent Self-Audit Tool (audit_package): Enables Pi to self-verify library existence before generating code.

🚀 Installation

Via Pi Package Registry (Recommended)

pi install npm:pi-dependency-guard

Direct from GitHub

pi install git:https://github.com/lleontor705/pi-dependency-guard.git

From Local Source

git clone https://github.com/lleontor705/pi-dependency-guard.git
cd pi-dependency-guard
npm install && npm run build
pi install ./

📖 Usage & Commands

Slash Commands

| Command | Description | | :--- | :--- | | /guard check npm <pkg> | Queries the npm registry for release date, version, and monthly downloads. | | /guard check pypi <pkg> | Queries PyPI for Python packages. | | /guard scan <command> | Parses an entire command (e.g., npm i express lodash-es) and audits all packages. |

Agent Autonomous Tool (audit_package)

Pi uses this tool before proposing any unfamiliar library:

{
  "packageName": "express-jwt-easy",
  "ecosystem": "npm"
}

Response:

{
  "packageName": "express-jwt-easy",
  "ecosystem": "npm",
  "exists": false,
  "isHallucinated": true,
  "riskLevel": "CRITICAL",
  "reasons": [
    "Package \"express-jwt-easy\" does NOT exist in the official npm registry (Hallucination detected)."
  ]
}

Pi immediately halts the hallucinated suggestion and proposes a real package like express-jwt.


🏗️ Architecture & Development

# Clone
git clone https://github.com/lleontor705/pi-dependency-guard.git
cd pi-dependency-guard

# Install & Build
npm install
npm run build

📄 License

MIT © Luis Leon