VibeCoded

Are AI-suggested packages safe?

Last reviewed 2026-09-30Written by Jacob Masse, TrazTech Inc.

Not automatically. AI tools sometimes suggest package names that do not exist, and attackers register those names with malicious code, a pattern researchers call slopsquatting. They also suggest old or abandoned packages. Check every new dependency exists, is the one you intended, is maintained, and has plausible download numbers before installing it.

How to check

  • Look the package up on its registry page: owner, repository link, release history.
  • Be wary of new packages with few downloads and names close to popular ones.
  • Review lockfile changes in every pull request.
  • Run dependency scanning in CI.
  • Pin versions and update deliberately.

Why it happens

Models predict plausible names. A plausible name that nobody published is an opportunity for whoever publishes it first.

A worked example

You ask your AI editor to add PDF parsing. It writes an import for a package with a sensible name and runs the install. Before accepting, open the registry page. Check four things: the package exists and was first published more than a few months ago; the linked repository is real and active; weekly downloads are in the thousands, not single digits; and the name is not one letter off a popular package. If any check fails, ask the AI for the established library for the job instead, and say which one you expect.

Keep the lockfile in version control and read its changes in every pull request. A lockfile diff that adds dozens of new packages for a small feature is worth a second look. Automated dependency scanning in CI flags known vulnerable versions, but it will not flag a malicious package nobody has reported yet, which is why the human check on new names matters.

Getting it checked

TrazTech offers vibe-coding QA and security review, listed from $2,000 CAD. Get at least one other quote on the same scope; the questions to ask a testing firm help compare them.

Get a scope for your app

Tell us what you built, what it stores and who is about to use it.

Get matched

Common questions

Does my app builder handle this?

Hosted builders choose most dependencies themselves. Code you export and extend is your responsibility.

Is this part of a security test?

A code review checks dependencies; ask for it in scope.