Use cases / Security and platform teams
Stopping hallucinated dependencies
Slopsquatting: attackers register the package names models invent. Catch them at review.
The problem
Models confidently import packages that do not exist, and attackers now publish malware under exactly those names. A new line in requirements.txt looks harmless.
What visualdiff does
- Every added npm or PyPI dependency is looked up: does it exist, and how old is it?
- Names a letter or two away from popular packages are called out as likely typo-squats.
- Policy can forbid new dependencies outright in sensitive repositories.
In the sample, “reqeusts” is flagged both as an imitation of requests and as absent from PyPI.
Related
- Reviewing pull requests written by agentsAgents open pull requests faster than anyone can read them. Read the 10% that decides whether it is safe.
- Large refactors that hide a behaviour changeA refactor is supposed to change nothing. Find the one line that does.
- Seeing which running systems a change reachesThe diff says rds.tf. The map says orders-db, the API in front of it, and the queue behind it.
- Knowing whether review is keeping upThe sanity index: is the codebase getting harder to review as more of it is written by machines?