Are AI-suggested packages safe?
Not automatically. AI tools sometimes suggest package names that do not exist, and attackers register those names with malicious code, a pattern researchers call slopsquatting. They also suggest old or abandoned packages. Check every new dependency exists, is the one you intended, is maintained, and has plausible download numbers before installing it.
How to check
- Look the package up on its registry page: owner, repository link, release history.
- Be wary of new packages with few downloads and names close to popular ones.
- Review lockfile changes in every pull request.
- Run dependency scanning in CI.
- Pin versions and update deliberately.
Why it happens
Models predict plausible names. A plausible name that nobody published is an opportunity for whoever publishes it first.
A worked example
You ask your AI editor to add PDF parsing. It writes an import for a package with a sensible name and runs the install. Before accepting, open the registry page. Check four things: the package exists and was first published more than a few months ago; the linked repository is real and active; weekly downloads are in the thousands, not single digits; and the name is not one letter off a popular package. If any check fails, ask the AI for the established library for the job instead, and say which one you expect.
Keep the lockfile in version control and read its changes in every pull request. A lockfile diff that adds dozens of new packages for a small feature is worth a second look. Automated dependency scanning in CI flags known vulnerable versions, but it will not flag a malicious package nobody has reported yet, which is why the human check on new names matters.
Getting it checked
TrazTech offers vibe-coding QA and security review, listed from $2,000 CAD. Get at least one other quote on the same scope; the questions to ask a testing firm help compare them.
Related questions
Get a scope for your app
Tell us what you built, what it stores and who is about to use it.
Get matchedCommon questions
Does my app builder handle this?
Hosted builders choose most dependencies themselves. Code you export and extend is your responsibility.
Is this part of a security test?
A code review checks dependencies; ask for it in scope.