{"_id":"@ailint/cli","_rev":"3-1cd68a35538a05afd945b4490b0a62bb","name":"@ailint/cli","dist-tags":{"latest":"0.1.2"},"versions":{"0.1.0":{"name":"@ailint/cli","version":"0.1.0","keywords":["linter","ai","hallucination","static-analysis","supply-chain","security","npm","typescript"],"author":{"name":"Lucian Fialho"},"license":"MIT","_id":"@ailint/cli@0.1.0","maintainers":[{"name":"lucianfialho","email":"lucian@metricasboss.com.br"}],"homepage":"https://ailint.dev","bugs":{"url":"https://github.com/lucianfialho/ailint/issues"},"bin":{"ailint":"dist/index.js"},"dist":{"shasum":"0662edd50c5d8ae99f9ecfd4574cfd88991a7055","tarball":"https://registry.npmjs.org/@ailint/cli/-/cli-0.1.0.tgz","fileCount":28,"integrity":"sha512-5ctPLZ9rd/TBnS2D3E9JhiMvBgpSdevrEr3k0fZxleFjwlgBUjT9XgIYnES6TsZMxL2G3mdA2vR9bSM1x87B/w==","signatures":[{"sig":"MEQCIEk0xJKOpvRPKy8hIizQXldGhcJ6OTQvpzrHxyJI3RJcAiAz81HDSZHX8V4BePlLyBXR+8QynpT9weBIFwqmRn6L/w==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":60813},"type":"module","engines":{"node":">=18"},"gitHead":"37a7a9b5d168d97505bf1e2a1246649965adf1f8","scripts":{"dev":"tsx src/index.ts","test":"vitest run","build":"tsc","prepublishOnly":"npm run build && npm test"},"_npmUser":{"name":"lucianfialho","email":"lucian@metricasboss.com.br"},"repository":{"url":"git+https://github.com/lucianfialho/ailint.git","type":"git"},"_npmVersion":"10.9.0","description":"Static linter for AI-generated code. Catches hallucinated packages, phantom APIs, and stale imports.","directories":{},"_nodeVersion":"22.12.0","dependencies":{"commander":"^13.0.0","typescript":"^5.7.0"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.0","vitest":"^3.0.0","@types/node":"^22.0.0"},"_npmOperationalInternal":{"tmp":"tmp/cli_0.1.0_1774214971972_0.5614456671626462","host":"s3://npm-registry-packages-npm-production"}},"0.1.1":{"name":"@ailint/cli","version":"0.1.1","keywords":["linter","ai","hallucination","static-analysis","supply-chain","security","npm","typescript"],"author":{"name":"Lucian Fialho"},"license":"MIT","_id":"@ailint/cli@0.1.1","maintainers":[{"name":"lucianfialho","email":"lucian@metricasboss.com.br"}],"homepage":"https://ailint.dev","bugs":{"url":"https://github.com/lucianfialho/ailint/issues"},"bin":{"ailint":"dist/index.js"},"dist":{"shasum":"301a55c6b3f3223042fbee088e1970bd7630c97a","tarball":"https://registry.npmjs.org/@ailint/cli/-/cli-0.1.1.tgz","fileCount":32,"integrity":"sha512-jtm+1ykpOkEcURtZ1X0RQc45aFIDmFuobqIvBoLH2B+N0B1MBoIvXNz3euBrI3Wchl/q1RKBvDIOy9LCJH3ZqA==","signatures":[{"sig":"MEQCIAG3DKMqaYH2ujmce6w7lyKPCEz0q6GkWazLWawX4Cn4AiBejJdPE4gmiSl0sO/U2v3i3KeCsZmxlm8SLd/PyS9D8g==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":78232},"type":"module","engines":{"node":">=18"},"gitHead":"452eae0d44db18d7ed2574c3a4e98d9a80ddfb91","scripts":{"dev":"tsx src/index.ts","test":"vitest run","build":"tsc","prepublishOnly":"npm run build && npm test"},"_npmUser":{"name":"lucianfialho","email":"lucian@metricasboss.com.br"},"repository":{"url":"git+https://github.com/lucianfialho/ailint.git","type":"git"},"_npmVersion":"10.9.0","description":"Static linter for AI-generated code. Catches hallucinated packages, phantom APIs, and stale imports.","directories":{},"_nodeVersion":"22.12.0","dependencies":{"commander":"^13.0.0","typescript":"^5.7.0"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.0","vitest":"^3.0.0","@types/node":"^22.0.0"},"_npmOperationalInternal":{"tmp":"tmp/cli_0.1.1_1774219036299_0.5851933283072925","host":"s3://npm-registry-packages-npm-production"}},"0.1.2":{"name":"@ailint/cli","version":"0.1.2","type":"module","description":"Static linter for AI-generated code. Catches hallucinated packages, phantom APIs, and stale imports.","bin":{"ailint":"dist/index.js"},"scripts":{"build":"tsc","dev":"tsx src/index.ts","test":"vitest run","prepublishOnly":"npm run build && npm test"},"engines":{"node":">=18"},"keywords":["linter","ai","hallucination","static-analysis","supply-chain","security","npm","typescript"],"author":{"name":"Lucian Fialho"},"license":"MIT","repository":{"type":"git","url":"git+https://github.com/lucianfialho/ailint.git"},"homepage":"https://ailint.dev","bugs":{"url":"https://github.com/lucianfialho/ailint/issues"},"dependencies":{"commander":"^13.0.0","typescript":"^5.7.0"},"devDependencies":{"vitest":"^3.0.0","tsx":"^4.19.0","@types/node":"^22.0.0"},"_id":"@ailint/cli@0.1.2","gitHead":"9f1f2ce3e0f4bdd4826ab2a8a29a773d5404e132","_nodeVersion":"22.12.0","_npmVersion":"10.9.0","dist":{"integrity":"sha512-Jtlb/Smpd4+UwKSrR0E3XRmuSW5eQnhJB4pu3Cm3auwRxccuiil4XkAgbpreUvBEW8etVW32Ko5hvC/pRcl+VA==","shasum":"a1aea65c2a58b302e2606aa37148f8909b8788ab","tarball":"https://registry.npmjs.org/@ailint/cli/-/cli-0.1.2.tgz","fileCount":32,"unpackedSize":78882,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCICjitNcDxLYgNyv7AThiIaq8ln+15WZxiJ91WaEYrEDVAiEA1uasH8S0QmDOSx7eLzOT4KhUxLmT5Di3VtmvSGLQmpo="}]},"_npmUser":{"name":"lucianfialho","email":"lucian@metricasboss.com.br"},"directories":{},"maintainers":[{"name":"lucianfialho","email":"lucian@metricasboss.com.br"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/cli_0.1.2_1774226678391_0.8216449421655811"},"_hasShrinkwrap":false}},"time":{"created":"2026-03-22T21:29:31.869Z","modified":"2026-03-23T00:44:38.678Z","0.1.0":"2026-03-22T21:29:32.141Z","0.1.1":"2026-03-22T22:37:16.466Z","0.1.2":"2026-03-23T00:44:38.545Z"},"bugs":{"url":"https://github.com/lucianfialho/ailint/issues"},"author":{"name":"Lucian Fialho"},"license":"MIT","homepage":"https://ailint.dev","keywords":["linter","ai","hallucination","static-analysis","supply-chain","security","npm","typescript"],"repository":{"type":"git","url":"git+https://github.com/lucianfialho/ailint.git"},"description":"Static linter for AI-generated code. Catches hallucinated packages, phantom APIs, and stale imports.","maintainers":[{"name":"lucianfialho","email":"lucian@metricasboss.com.br"}],"readme":"# ailint — static linter for AI-generated code\n\nAI coding tools hallucinate. **ailint** catches it before production.\n\n```bash\n$ npx @ailint/cli check .\n\n  src/hallucinated-packages.ts\n    ✗ fetch-retry-plus :2\n      Package \"fetch-retry-plus\" not found in lockfile or node_modules\n    ✗ next-api-helpers :3\n      Package \"next-api-helpers\" not found in lockfile or node_modules\n    ✗ react-server-hooks :4\n      Package \"react-server-hooks\" not found in lockfile or node_modules\n\n  src/phantom-apis.ts\n    ✗ zod.ZodBrand :2\n      \"ZodBrand\" is not exported by zod\n    ✗ zod.createValidator :2\n      \"createValidator\" is not exported by zod\n    ✗ commander.Router :3\n      \"Router\" is not exported by commander\n\n  6 errors (3 files, 50ms)\n  ✗ Check failed\n```\n\n## Why\n\nAI agents hallucinate at scale:\n- **21.7%** of package names suggested by open-source models don't exist on npm ([Liang et al., 2024](https://arxiv.org/abs/2406.10279))\n- **At least 5.2%** from commercial models (GPT-4, Claude) — same study\n- **58%** of hallucinations are repeatable, making them exploitable ([slopsquatting](https://www.aikido.dev/blog/agent-skills-spreading-hallucinated-npx-commands))\n- Agents use deprecated APIs from stale training data ([source](https://community.openai.com/t/my-biggest-pain-point-with-gpt-coding-outdated-libraries-apis-docs/958684))\n\nESLint checks style. TypeScript checks types. **ailint checks reality.**\n\n## Install\n\n```bash\nnpx @ailint/cli check .          # zero install\nnpm install -g @ailint/cli       # or install globally\n```\n\n## What it detects\n\n### 1. Hallucinated packages\nImports from packages that don't exist in your lockfile or node_modules.\n\n```typescript\n// AI wrote this — fetch-retry-plus doesn't exist on npm\nimport { fetchWithRetry } from 'fetch-retry-plus';\n```\n\n```\n✗ fetch-retry-plus :1\n  Package \"fetch-retry-plus\" not found in lockfile or node_modules\n```\n\n### 2. Phantom APIs\nImports of functions/classes that don't exist in the installed version.\n\n```typescript\n// AI confused zod with another library\nimport { z, ZodBrand, createValidator } from 'zod';\n```\n\n```\n✗ zod.ZodBrand :1\n  \"ZodBrand\" is not exported by zod\n✗ zod.createValidator :1\n  \"createValidator\" is not exported by zod\n```\n\n### 3. Not-installed packages\nPackages in your lockfile but missing from node_modules (needs `npm install`).\n\n```\n⚠ express :1\n  Package \"express\" is in lockfile but not installed. Run npm install.\n```\n\n## How it works\n\n100% static analysis. No LLM. No network calls (by default). No config.\n\n1. **Walks** your source files (.ts, .tsx, .js, .jsx)\n2. **Extracts** all imports via TypeScript compiler API\n3. **Checks** each package against lockfile + node_modules\n4. **Verifies** each imported symbol against the package's `.d.ts` exports\n5. **Reports** issues with file, line, package, and symbol\n\nSub-100ms on real projects. Zero dependencies beyond Node.js and TypeScript.\n\n## CI / GitHub Action\n\n```yaml\n- name: Lint AI-generated code\n  run: npx @ailint/cli check src/ --format json\n```\n\nExit code 1 on errors, 0 on clean. Use `--format json` for machine-readable output.\n\n## Options\n\n```\nailint check [dir]              Scan for AI code issues (default: .)\n\n  -f, --format <format>         pretty | json (default: pretty)\n  --online                      Check npm registry for unknown packages\n  --ignore <pattern>            Glob patterns to exclude (repeatable)\n  -q, --quiet                   Only show errors, suppress warnings\n  --no-color                    Disable colors\n```\n\n## What ailint does NOT do\n\n| Tool | Checks | ailint overlaps? |\n|---|---|---|\n| **ESLint** | Code style, patterns | No |\n| **TypeScript** | Type correctness | No |\n| **npm audit** | Known vulnerabilities | No |\n| **ailint** | Package existence, API existence | **This is the gap** |\n\n## Try the demo\n\n```bash\ngit clone https://github.com/lucianfialho/ailint-cli\ncd ailint-cli\nnpm install\nnpx tsx src/index.ts check examples/demo-project\n```\n\n## License\n\nMIT\n","readmeFilename":"README.md"}