Lesson 15 / 25

Hallucinated APIs and Packages

Spot methods, flags and libraries that do not exist and verify against documentation.

Plausible names that are not real

A model can invent a function, a command-line flag or even a whole package that sounds right but does not exist. This is a hallucination. Sometimes you get an immediate error; sometimes the invented name matches a real but different or malicious package. Always check unfamiliar names in the official documentation and the package registry before installing.

Trust, but verify

You own every line you commit. Review AI output more carefully than you would review your own.

Four checks: does it exist, is it right, is it safe, is it needed.
Figure 5.1 — Exists, right, safe and needed.

The error that gives it away

I ran this. JavaScript has push but Python lists use append; a model mixing languages can write the wrong one, and Python tells you immediately.

nums = [1, 2]
try:
    nums.push(3)
except AttributeError as e:
    print(e)
nums.append(3)
print(nums)

Output:

'list' object has no attribute 'push'
[1, 2, 3]

Check a package before installing

Look at the package's page: age, download count, maintainer, linked repository. Typo-squatted or brand-new packages with names an assistant "recommended" are a real supply-chain risk.

Quick check: An assistant suggests `npm install fast-json-validator-pro`. What should you do first?

  • Check that the package is real and reputable
  • Install it immediately
  • Install it globally
  • Add it to production first
Answer

Check that the package is real and reputable — The name may be invented or malicious, so verify it on the registry before installing.