# How to check a package name an LLM suggested before installing it

Last updated: 2026-10-10

Before you install a package a model suggested, look the name up in its registry and stop if the registry does not list it. `POST /v1/check/packages` (US$0.005 per batch) checks up to 10 names on npm, PyPI or crates.io in one call and returns, for each, whether the registry lists it, its latest version, creation time and flags, under one signed receipt.

## Why invented names matter

Models sometimes suggest package names that sound right but were never published. Running the install command then fails, or worse: someone can register that name later and publish their own code under it. Checking the name first catches the first case and shows you the flags worth a second look in the second.

## Check a batch

```json
{ "packages": [
  { "ecosystem": "npm", "name": "left-pad" },
  { "ecosystem": "pypi", "name": "requests" },
  { "ecosystem": "crates", "name": "serde" }
] }
```

For each name:

- `exists` is `false` when the registry answered 404: do not install it.
- `signals` lists `created_recently` (under 30 days old), `deprecated`, `yanked` and `name_differs` (the registry spells the name differently).
- `latest_version`, `license`, `homepage` and `repository` come from the registry, so you can compare them with what the model said.

Try the route free on demo data: [`GET /v1/sample/packages`](https://vehcdj664efetfrsolne5umanq.srv.us/v1/sample/packages). Details: [Check packages](/docs/check-packages).

## Questions

### Does a listed package mean it is fine to install?

No. The answer says whether the registry lists the name when we looked. A listed package can still be malicious, abandoned or not the one you meant. Read the signals and the publisher's details before you install.

### Which registries are covered?

npm (including scoped names), PyPI and crates.io. Each name is checked against its registry's naming rules before payment, and a request with an invalid name gets 400 and is not charged.

### What if a registry is down?

A failed lookup is reported per name with status lookup_failed and a reason. If every lookup in the batch fails, the call gets 502 and is not charged. See Payments and Errors in the docs.

### Can my coding agent call it from a sandbox?

Yes, if the sandbox can reach our API. Agents can call it over HTTPS with x402 payment, or through the MCP server, which has one tool per route.
