# Hallucinated APIs and Packages — AI Coding Assistants: Use Them Well and Review Them Hard

Source: https://www.geekswithgeeks.com/en/ai-coding-assistants/rev-hallucinations

> Spot methods, flags and libraries that do not exist and verify against documentation.

## Plausible names that are not real

A model can invent a function, a command-line flag or even a whole package that sounds right but does not exist. This is a **hallucination**. Sometimes you get an immediate error; sometimes the invented name matches a real but different or malicious package. Always check unfamiliar names in the **official documentation** and the package registry before installing.

## Trust, but verify

You own every line you commit. Review AI output more carefully than you would review your own.

![Four checks: does it exist, is it right, is it safe, is it needed.](assets/figures/ai-coding-assistants/section-5-map.svg) — Figure 5.1 — Exists, right, safe and needed.

## The error that gives it away

I ran this. JavaScript has `push` but Python lists use `append`; a model mixing languages can write the wrong one, and Python tells you immediately.

```python
nums = [1, 2]
try:
    nums.push(3)
except AttributeError as e:
    print(e)
nums.append(3)
print(nums)
```

Output:

```
'list' object has no attribute 'push'
[1, 2, 3]
```

## Check a package before installing

Look at the package's page: age, download count, maintainer, linked repository. Typo-squatted or brand-new packages with names an assistant "recommended" are a real supply-chain risk.

**Quiz:** An assistant suggests `npm install fast-json-validator-pro`. What should you do first?

- [x] Check that the package is real and reputable
- [ ] Install it immediately
- [ ] Install it globally
- [ ] Add it to production first

*Answer:* Check that the package is real and reputable. The name may be invented or malicious, so verify it on the registry before installing.
