frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Show HN: CodeGate – An open-source CLI to detect AI-hallucinated packages

https://github.com/dariomonopoli-dev/codegate-cli
1•mondra•2h ago

Comments

mondra•2h ago
Hey HN,

I built this because I noticed a scary pattern: AI agents (like ChatGPT or Gemini) often hallucinate package names that don't exist.

For example, an agent might try to import cv2. If it runs pip install cv2, it fails because the real package is opencv-python. But if an attacker registers cv2 on PyPI (a technique called Slopsquatting), they can instantly compromise any agent that tries to install it.

CodeGate is a CLI tool that acts as a guardrail.

Scan: It checks requirements.txt for packages that don't exist (potential hallucinations) or are dangerously new.

Probe: It actively red-teams your LLM prompts to see if they suggest malicious packages.

Block: It uses a local SQLite knowledge graph (seeded with known hallucinations) to flag risky installs.

It's open source and available via pip install codegate-cli.

I'd love to hear your feedback on the trade-off I made. I went with a static blocklist (like a filter) because it's instant and works offline. The alternative is running every package in a secure sandbox, which catches more unknown threats but is much slower. Is the speed of a simple blocklist worth it, or should we always be sandboxing AI-generated code?

Don't stuff beans up your nose

https://en.wikipedia.org/wiki/Wikipedia:Don%27t_stuff_beans_up_your_nose
1•cyanf•28s ago•0 comments

Making a game on a custom bytecode VM in 7 days and 3kB

https://laurent.le-brun.eu/blog/making-a-game-on-a-custom-bytecode-vm-in-7-days-and-3kb
1•laurentlb•1m ago•0 comments

Show HN: Consulting-as-Code – A deterministic, neuro-symbolic agent architecture

https://vuduvations.github.io/Consulting-as-Code/
1•vuduvations•2m ago•1 comments

Pop _OS 24.04's New Scratch-Built Cosmic: Hands-On, with Screenshots

https://fossforce.com/2025/12/pop_os-24-04s-new-scratch-built-cosmic-hands-on-with-screenshots/
2•dxs•3m ago•0 comments

Show HN: Seen – x-platform/selfhosted/open-src photo and video solution

https://github.com/markrai/seen
1•markrai•3m ago•0 comments

Gunman in Brown University shooting found dead, linked to MIT killing

https://www.reuters.com/world/us/police-probe-links-between-brown-university-shooting-killing-mit...
2•andrepd•3m ago•0 comments

Show HN: We built a small app with my wife to track promises we do

https://lovechecks.app/
1•warkanlock•5m ago•0 comments

A Month of Chat-Oriented Programming with Claude

https://checkeagle.com/checklists/njr/a-month-of-chat-oriented-programming/
1•BafS•6m ago•0 comments

DHH Should Move Rails Off GitHub

https://cameronwestland.com/dhh-should-move-rails-off-github/
2•camwest•6m ago•0 comments

Show HN: BlazeDiff v2 – Fastest image diff with native binary and SIMD

https://github.com/teimurjan/blazediff
2•teimurjan•7m ago•0 comments

Is The Line dead? [video]

https://www.youtube.com/watch?v=zFVYgZMEOFg
1•camtarn•11m ago•1 comments

Curse of Dimensionality

https://en.wikipedia.org/wiki/Curse_of_dimensionality
2•cuechan•14m ago•0 comments

Show HN: RunMesh – OpenAI-first TypeScript framework for agentic applications

https://runmesh.llmbasedos.com/
1•iluxu•16m ago•0 comments

Show HN: LiteEvo – Let LLMs evolve their own playbook based on trial and error

https://github.com/wbopan/liteevo
1•mavoince•18m ago•0 comments

Always-on processor magic: how "Find My" works while iPhone is powered off

https://naehrdine.blogspot.com/2021/09/always-on-processor-magic-how-find-my.html
1•fanf2•20m ago•0 comments

EscapeBench: Towards Advancing Creative Intelligence Of Language Model Agents

https://aclanthology.org/2025.acl-long.39/
1•optimalsolver•22m ago•0 comments

US government sues US Virgin Islands & accuses officials of violating 2nd Amend.

https://apnews.com/article/usvi-us-government-trump-second-amendment-guns-45189a8a28da66b1307f4da...
2•sipofwater•24m ago•1 comments

DOMPurify, DOM-only, fast, Uber-tolerant XSS sanitizer for HTML, SVG and MathML

https://cure53.de/purify
1•handfuloflight•25m ago•0 comments

Vector Search for the Bible

https://searchyah.app/
1•quasibyte•25m ago•0 comments

Quake Deathmatch in the Browser via WebRTC

https://fte.triptohell.info/moodles/web/ftewebgl.html?+connect%20/hnews
1•klaussilveira•27m ago•0 comments

Americans Are Increasingly Convinced That Aliens Have Visited Earth

https://www.wired.com/story/americans-are-increasingly-convinced-that-aliens-have-visited-earth/
3•BerislavLopac•29m ago•2 comments

When Scope Lies: The Wildcard Pattern Drop Footgun in Rust

https://obeli.sk/blog/when-scope-lies/
1•todsacerdoti•29m ago•0 comments

Show HN: Lilo Write – Local-first spatial writing (Apple Notes/whiteboard baby)

https://lilowrite.com
1•Lucavalentino•30m ago•1 comments

Torvalds is sick of all the AI hype but says AI is finally maturing to the point

https://www.zdnet.com/article/linus-torvalds-ai-tool-maintaining-linux-code/
1•ctrlmeta•35m ago•0 comments

Litex: Formal math for everyone – set theory examples with Lean comparison

https://litexlang.com/doc/How_Litex_Works/Litex_vs_Lean_Set_Theory_Examples
1•litexlang•36m ago•1 comments

Show HN: Lidar, an extension to scrape websites as you visit them

https://imgur.com/a/QaGiYaS
1•gaigalas•39m ago•0 comments

Amazon drivers stole my package and now I can't get a refund

https://docs.google.com/document/d/1wWhbSfZQLLCNOZrgrU1LZEZfAN3cp3sIHpTD6ueEIoE/edit?tab=t.0#head...
3•haroldcampbell•39m ago•1 comments

Show HN: I built a 3D audio-reactive healing world with React Three Fiber

https://flow.inresonancewell.com
1•Chen777•40m ago•0 comments

UK to push for nudity-blocking software on devices

https://www.ft.com/content/0ef79775-eadf-4cc9-b32c-e97b0eff816f
6•GaryBluto•41m ago•2 comments

China's AI Chip Deficit: Why Huawei Can't Catch Nvidia

https://www.cfr.org/article/chinas-ai-chip-deficit-why-huawei-cant-catch-nvidia-and-us-export-con...
2•giuliomagnifico•42m ago•0 comments