Open-Source MCP Scanner Catches AI-Hallucinated Package Names to Block Slopsquatting Attacks
Cool_Inspector_5202 · reddit · 2026-09-30
A developer released slopsquat-scanner, an open-source MCP security scanner targeting "slopsquatting" — attackers pre-registering plausible-sounding but nonexistent package names hallucinated by LLM coding assistants, so that npm/pip installs pull attacker code.
How it works
- Checks package names live against the real npm/PyPI registries rather than a static blocklist, since the risk is by definition new names
- Flags packages that don't exist or were published suspiciously recently
Usage: deployed as a standalone remote MCP server on Hugging Face Spaces — try it without installing anything, or point an agent at /gradioapi/mcp/ directly.
It's part of the GuardBee family of 25 single-purpose open-source MCP servers, covering secret scanning, indirect prompt-injection detection in RAG content, dependency CVE auditing via OSV.dev, TLS/cert inspection, DNS misconfig checks, pickle/safetensors supply-chain scanning, and an MCP-server permission auditor. MIT licensed, available on GitHub and the official MCP Registry.
More from coding & agent
- OpenAI Codex now natively runs open models like GLM-5.3 Flash and Kimi K3 — HarveenChadha · 2026-09-30
- Yacine: Local realtors all know him now — his AI agents retry forever — yacineMTB · 2026-09-30
- Google ships Jetpack Compose A2UI renderer to turn agent streams into native Android UI — rseroter · 2026-09-30
- v0 now lets ChatGPT Plus and Pro subscribers build with their ChatGPT tokens — tomjohndesign · 2026-09-30
- Teaching agents from outcomes: an async reflection loop that turns resolutions into rules — FirstClothes6582 · 2026-09-30
- Vorflux partners with OpenAI: ChatGPT subscriptions now OAuth into its agent harness — ycombinator · 2026-09-30