From imbue
Verifies a package exists in its registry before install, defending against hallucination and slopsquatting. Use when adding, recommending, or installing a package.
How this skill is triggered — by the user, by Claude, or both
Slash command
/imbue:dependency-verificationThe summary Claude sees in its skill listing — used to decide when to auto-load this skill
> A package name the model produced is a claim, not a fact. The
A package name the model produced is a claim, not a fact. The registry is the fact. Verify before you install.
Code-generating language models recommend packages that do not
exist at a measured rate of 5.2% (commercial models) to 21.7%
(open models) across 576,000 samples (Spracklen et al. 2024,
arXiv 2406.10279). Worse, 58% of hallucinated names recur across
reruns, so an attacker can predict them, register the empty name,
and ship malware. This is "slopsquatting." A proof-of-concept
package (huggingface-cli) drew over 30,000 downloads after being
registered against a commonly hallucinated name. Package
hallucination is also inversely correlated with coding-benchmark
score, so a better model does not make this go away.
The defense is cheap: confirm the name exists in its registry
before installing or recommending it. This skill defines that
check and is enforced by the guard_package_hallucination.py
PreToolUse hook.
Apply before any of these:
pip install, uv add, npm install, pnpm add,
yarn add, cargo add, poetry add, or pdm add.pyproject.toml, requirements.txt,
package.json, or Cargo.toml.sanctum:version-updates)leyline:supply-chain-advisory)A package fails verification on either signal:
reqeusts versus requests).
This is either a typo or a deliberate impersonation. Confirm
the exact name you intend before proceeding.A name that is unknown to the bundled popular-package set but
present in the registry passes. A name that cannot be checked
because the registry is unreachable is reported as unverified,
never blocked: the guard does not fail closed on a network error.
Registry existence is the pass/fail check. Real-world usage is a separate, softer signal that builds confidence on top of it. Once a package clears the two signals above, cross-checking that it is actually used by other projects raises your confidence that the name is the established one rather than a freshly-registered impostor that happens to exist.
Useful confidence signals, none of them blocking:
Treat low usage as a prompt to look closer, never as a reason to reject on its own. New, niche, internal, and private packages are legitimately low-usage, so a missing GitHub footprint must not block an install the registry already confirmed. Use this signal to build confidence and to disambiguate between two similarly-named packages, not to gate.
imbue:proof-of-work.The guard_package_hallucination.py hook runs this check
automatically on every Bash install command. Shadow mode (warn
only) is the default; set VOW_SHADOW_MODE=0 to block
typosquat and nonexistent installs. Disable the network lookup
with IMBUE_PKG_REGISTRY_CHECK=0 to rely on the offline
typosquat signal alone. The hook is a backstop, not a substitute:
verify deliberately when you add a dependency rather than waiting
for the gate.
imbue:proof-of-work: capture the registry check as evidence.leyline:supply-chain-advisory: broader dependency supply-chain
auditing (lockfile drift, artifact integrity, bad versions).npx claudepluginhub athola/claude-night-market --plugin imbueFlags misspelled, brandjacked, and typosquatted package names across npm, PyPI, and crates.io before installation using edit-distance, keyboard-proximity, and corpus matching with typomania, OSSGadget, and pypi-scan.
Audits dependencies for supply-chain risk before install (pip/npm/go/cargo): checks typosquatting, maintainer/age, vulnerability DBs, lockfile pinning, outputs risk score and decision.
Evaluates packages, manages dependencies, and addresses supply chain security for npm/pip/cargo/bundler/Go. Use for auditing packages, reviewing lockfiles, checking vulnerabilities, comparing alternatives, assessing trustworthiness.