Open-Source MCP Scanner Catches AI-Hallucinated Package Names to Block Slopsquatting Attacks

Cool_Inspector_5202 · reddit · 2026-09-30

A developer released slopsquat-scanner, an open-source MCP security scanner targeting "slopsquatting" — attackers pre-registering plausible-sounding but nonexistent package names hallucinated by LLM coding assistants, so that npm/pip installs pull attacker code.

How it works

Usage: deployed as a standalone remote MCP server on Hugging Face Spaces — try it without installing anything, or point an agent at /gradioapi/mcp/ directly.

It's part of the GuardBee family of 25 single-purpose open-source MCP servers, covering secret scanning, indirect prompt-injection detection in RAG content, dependency CVE auditing via OSV.dev, TLS/cert inspection, DNS misconfig checks, pickle/safetensors supply-chain scanning, and an MCP-server permission auditor. MIT licensed, available on GitHub and the official MCP Registry.

Original post →

More from coding & agent

coding & agent channel →