Our slopsquatting detector had three ways to say "safe". None of them needed evidence.
Ask a language model which package to use and, now and then, it names one that does not exist. If someone registers that name first, the next developer — or the next coding agent — who follows the same suggestion installs whatever they put there. That is slopsquatting. We collect those names and score each one. A name that returns 404 is easy: it is a target. The hard case is a name that does…
Three criteria were used to assess the safety of packages: age, provenance, and registration before the name was suggested. Each criterion had its own method of determining the level of risk, but none of them relied on evidence. The first criterion, age, calculated the number of days a package had been published and classified it as high risk if published within the past two weeks, medium risk if published within the past two months, and low risk if published earlier.
However, this method was crude and could result in false positives. The second criterion, provenance, checked if the package had a signed build statement, indicating it was built by a trusted publisher. While this seemed like strong evidence, it was later found to be easily obtainable by anyone, making it a weak indicator of safety.
The third criterion, registration before the name was suggested, checked if the package was registered before the model suggested it. However, this criterion also had issues, as it could result in false positives if the package was registered early and the name was suggested later. Additionally, the absence of creation date for a package led to it being classified as medium risk, even if it was a Go module, which had its creation date recorded differently.
The audit proposed by the reader aimed to plot the registration date of cleared packages against the collection beginning date to determine if they clustered at the boundary.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.