{"_id":"@aximur/package-guard","name":"@aximur/package-guard","dist-tags":{"latest":"0.1.0"},"versions":{"0.1.0":{"name":"@aximur/package-guard","version":"0.1.0","description":"Stop AI coding agents from installing hallucinated, nonexistent, typo-close, or slopsquatted npm/PyPI packages before install.","license":"MIT","type":"commonjs","bin":{"aximur-guard-js":"hooks/npm-preinstall.js","aximur-npm-preinstall":"hooks/npm-preinstall.js"},"scripts":{"test:syntax":"node --check hooks/npm-preinstall.js"},"keywords":["ai","ai-agents","coding-agents","claude-code","cursor","copilot","mcp","package-guard","hallucinated-packages","slopsquatting","typosquatting","npm","pypi","supply-chain-security","dependency-security","preinstall","security"],"homepage":"https://www.npmjs.com/package/@aximur/package-guard","_id":"@aximur/package-guard@0.1.0","_nodeVersion":"24.15.0","_npmVersion":"11.12.1","dist":{"integrity":"sha512-9urkZjaDxRXZbW+X4xN6lURU6ut2VKYHUfJ967sVSh3CDhpkQPzh++d4YJMgu6CjZIsL5G3SQuN0w9kdnGX5Yw==","shasum":"540e5a67dcf453d7157ac77a137800eef9871d8e","tarball":"https://registry.npmjs.org/@aximur/package-guard/-/package-guard-0.1.0.tgz","fileCount":14,"unpackedSize":48337,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIDSjZJStSmWi+e0O84c95PKKG6K4f7nhlMOzA2Y1oHZ7AiBRsf9cMNJ7M/Eu6N/nAP776nQZb4JsUEgsUH7t+EaviQ=="}]},"_npmUser":{"name":"aximur","email":"contact@aximur.com"},"directories":{},"maintainers":[{"name":"aximur","email":"contact@aximur.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/package-guard_0.1.0_1783007195378_0.48610397973106245"},"_hasShrinkwrap":false}},"time":{"created":"2026-07-02T15:46:35.248Z","0.1.0":"2026-07-02T15:46:35.500Z","modified":"2026-07-02T15:46:35.765Z"},"maintainers":[{"name":"aximur","email":"contact@aximur.com"}],"description":"Stop AI coding agents from installing hallucinated, nonexistent, typo-close, or slopsquatted npm/PyPI packages before install.","homepage":"https://www.npmjs.com/package/@aximur/package-guard","keywords":["ai","ai-agents","coding-agents","claude-code","cursor","copilot","mcp","package-guard","hallucinated-packages","slopsquatting","typosquatting","npm","pypi","supply-chain-security","dependency-security","preinstall","security"],"license":"MIT","readme":"# AXIMUR Package Guard\n\nAXIMUR Package Guard stops AI coding agents from installing hallucinated, nonexistent, typo-close, or slopsquatted npm/PyPI packages before install.\n\nIt runs as a local CLI, npm preinstall hook, pip preinstall hook, or MCP-compatible package validation tool. Also available as @aximur/guard-hook.\n\n## Install\n\n```powershell\nnpm install -D @aximur/package-guard\n```\n\nNo account, token, or secret is required for standalone mode.\n\n## What it catches\n\n- `requests` -> safe\n- `reqeusts` -> suspicious\n- `react` -> safe\n- `loadash` -> suspicious\n- `definitely-not-a-real-package-name` -> danger\n\nPackage Guard checks registry existence and typo-close names before install, so agent-generated dependency mistakes can be stopped before they enter a repo.\n\n## Accurate commands\n\n```powershell\naximur-guard requests --ecosystem pypi --standalone\naximur-guard reqeusts --ecosystem pypi --standalone --json --fail-on suspicious\naximur-guard react --ecosystem npm --standalone\nnode hooks/npm-preinstall.js react --standalone --json\npython hooks/pip-preinstall.py requirements.txt\n```\n\n## npm preinstall hook\n\nCopy `hooks/npm-preinstall.js` into your repo, then add:\n\n```json\n{\n  \"scripts\": {\n    \"preinstall\": \"node hooks/npm-preinstall.js --standalone --fail-on danger\"\n  }\n}\n```\n\nStrict mode blocks both suspicious and danger findings:\n\n```json\n{\n  \"scripts\": {\n    \"preinstall\": \"node hooks/npm-preinstall.js --standalone --fail-on suspicious\"\n  }\n}\n```\n\n## pip preinstall hook\n\nCopy `hooks/pip-preinstall.py` into your repo, then run it before `pip install`:\n\n```powershell\npython hooks/pip-preinstall.py requirements.txt\npython hooks/pip-preinstall.py --fail-on suspicious requirements.txt\n```\n\n## MCP tool\n\nPackage Guard exposes an MCP-compatible validation tool:\n\n```text\nvalidate_package(package_name, ecosystem, fail_on)\n```\n\nUse it to check npm or PyPI package names before an AI coding agent installs them.\n\n## Blocked terminal warning\n\nWhen Package Guard blocks a suspicious or dangerous install, it prints `[AXIMUR PACKAGE GUARD] ACTION BLOCKED` with the package, ecosystem, verdict, and reason. Safe package checks do not print paid checkout links.\n\nBlocked warnings include two upgrade paths:\n\n- Team Starter hosted checks/API keys: https://buy.stripe.com/eVq3cxd9m0Ws5X70IwfIs04\n- Agent Security Setup one-time setup help: https://buy.stripe.com/aFa7sNd9meNiadn3UIfIs05\n\n## Team Starter\n\nNeed team-wide hosted checks, API keys, and higher-volume validation? AXIMUR Guard Team Starter is $49/mo per workspace for 25,000 hosted package-validation checks/month.\n\nhttps://buy.stripe.com/eVq3cxd9m0Ws5X70IwfIs04\n\n## Paid setup\n\nNeed help wiring this into a real repo, CI workflow, Claude Code, Cursor, Copilot, or MCP-compatible agent setup?\n\nAXIMUR Agent Security Setup is a one-time $499 setup service for npm/pip guard configuration, fail-on-danger policy, optional fail-on-suspicious mode, and setup help.\n\nhttps://buy.stripe.com/aFa7sNd9meNiadn3UIfIs05","readmeFilename":"README.md","_rev":"1-9be7118f595b750fc903d0caa9286e34"}