Nifty Dependency Guard
Catch risky dependencies before you install them: made-up (AI-hallucinated) packages, lookalike names, brand-new versions, install scripts and deprecations, in package.json and requirements.txt.
Maintained. No sign-in. No telemetry. Works in VS Code, Cursor, Windsurf, VSCodium and other editors that use Open VSX.
Features


Open a package.json or requirements.txt and risky dependencies are underlined before you install them:
- Packages that don't exist. AI assistants sometimes suggest packages that were never published, and attackers register those names ("slopsquatting"). A dependency that isn't on npm or PyPI is marked as an error. Scoped packages missing from the public registry are treated as private.
- Lookalike names.
expresss, lodahs, reqeusts, cross_env: names one or two keystrokes away from a popular package are flagged, unless the package is itself widely used.
- Brand-new releases. When the version you'd install came out in the last 7 days, you're warned. That's the window in which hijacked maintainer accounts publish malicious updates. You're also warned when the package itself is less than 30 days old.
- Install scripts. Versions that run
preinstall, install or postinstall scripts are pointed out, with the command they run.
- Deprecated and yanked versions, with the maintainer's deprecation message.
- Hover over a dependency for its latest version, when the resolved version was published, weekly downloads, maintainer count and a link to the registry page.
- Check the whole workspace in one go, and quick-fix Don't flag this again for packages you trust.
- Works in the browser on vscode.dev and github.dev.
For AI coding agents
The same checks run as a command-line tool, nifty-guard on npm, that can stop an agent before it installs a made-up package. Install it once:
npm install -g nifty-guard
For Claude Code, add it as a hook in ~/.claude/settings.json, and every npm, pnpm, yarn, bun, npx, pip, uv, poetry or pipx install Claude runs is checked first:
{
"hooks": {
"PreToolUse": [
{ "matcher": "Bash", "hooks": [{ "type": "command", "command": "nifty-guard hook claude", "timeout": 30 }] }
]
}
}
Made-up and lookalike names are blocked, and Claude is told why so it can find the right package. Brand-new packages and releases ask you first. Anything else runs as normal. You can also check a command yourself: nifty-guard npm install left-pad lodahs.
Commands
| Command |
What it does |
Nifty Dependency Guard: Check Dependencies in This File |
Check the open package.json or requirements.txt |
Nifty Dependency Guard: Check All Dependencies in Workspace |
Check every manifest and list problems in the Problems panel |
Nifty Dependency Guard: Forget Cached Registry Data |
Fetch fresh data on the next check |
Settings
| Setting |
Default |
What it does |
nifty.guard.checkOn |
open |
Check when a manifest is opened (and saved), only on save, or manual |
nifty.guard.newVersionDays |
7 |
Warn about versions newer than this |
nifty.guard.newPackageDays |
30 |
Warn about packages newer than this |
nifty.guard.lookalikeMinDownloads |
10000 |
Weekly npm downloads above which a lookalike name isn't flagged |
nifty.guard.ignore |
[] |
Package names (or prefix*) never to flag |
nifty.guard.hover |
true |
Show registry details on hover |
nifty.guard.npmRegistry, npmDownloadsUrl, pypiUrl |
public registries |
Where to look packages up (point these at a mirror if you use one) |
nifty.guard.timeoutMs |
10000 |
How long to wait for the registry |
Privacy
To check a dependency, the extension asks the public registry about that package name. That's the same request npm install or pip install would make. Nothing else is sent, and there's no telemetry. Answers are cached for an hour.
Install
- VS Code: search for "Nifty Dependency Guard" in the Extensions view, or install from the Visual Studio Marketplace.
- Cursor, Windsurf, VSCodium, Kiro, Antigravity: install from Open VSX.
- Nifty Extension Audit: Extension Security Check: See what your installed extensions can do: activation, processes, network, native code, telemetry and secrets access, scored and reported, with an allowlist policy for teams. (Open VSX)
- Nifty Licenses: Dependency License Checker & SBOM: See the license of every dependency (npm, Python, Cargo, Go, NuGet, Composer), get warned about GPL and unknown licenses, and export an SBOM or third-party notices. (Open VSX)
- Nifty Node Search: Search Files in node_modules: Fuzzy-find and open files inside node_modules, jump to a package's README, and see installed versions. (Open VSX)
- Nifty Agent Config: AGENTS.md, Rules & MCP Files: See which AGENTS.md, CLAUDE.md, Cursor, Copilot, Windsurf and Gemini rules apply to the file you are editing. Lint rule and MCP files for hidden text, secrets and broken links, and keep them in sync. (Open VSX)
- Nifty AI Review: Review AI Agent Changes: Review what an AI agent changed, hunk by hunk: checkpoints before it runs, accept or reject each change, leave comments, and send your feedback back to the agent. (Open VSX)
- Nifty Code Metrics: Complexity & Hotspots: Complexity and size for every function in any language, as CodeLens and warnings, plus a hotspots view of the complex files that change most often. (Open VSX)
See all 100+ Nifty extensions and web tools at https://getnifty.dev
| |