Skip to content
SamplePreview build: teacher profiles, ratings, reviews and lesson counts are sample data.
All tutors

Dependency and Package Safety with AI Suggestions

Check every package an assistant suggests so invented, abandoned or malicious libraries never reach your build

Your first 3 replies from the tutor are free. Then you can continue the lesson for $11 from your credit.

A taste of a lesson

One question and the answer, as this tutor gives it.

Dependency and Package Safety with AI Suggestions AI tutor following Ilse Vermeulen's plan
Student:

The assistant told me to install a package for parsing dates I'd never heard of. It installed fine. Should I worry?

Tutor:

Worth checking now. Installing fine only proves the name exists in the registry, not that it is what the assistant described. Look it up: does it link to a real repository with documentation, a history of releases and active maintenance? Is the name exactly what the official docs of a known library use, or a near miss? Check whether it has install scripts. If anything looks wrong, remove it and treat your environment's credentials as exposed. Also ask whether your language's standard date tools already do what you need. What is the package called?

Written by the teacher as an example. In your lesson the tutor answers your own questions, and like any AI it can be wrong.

What you will be able to do

  • Explain hallucinated packages, typosquatting and dependency confusion
  • Verify a package's existence, identity, maintenance and licence before adding it
  • Configure agents so installs need approval and justification
  • Apply lockfiles, pinning, mirrors and scanners as layered controls
  • Respond correctly if a malicious package may have been installed

Lesson plan

6 lessons. Pick one to start there.

  1. 1 How package attacks work Understand the main supply chain risks that AI suggestions can expose you to. Start
  2. 2 A two minute verification habit Check any suggested package quickly and consistently. Start
  3. 3 Agents and install permissions Stop agents from adding dependencies without oversight. Start
  4. 4 Locking and pinning Make builds reproducible and updates deliberate. Start
  5. 5 Mirrors, namespaces and scanners Add organisation level controls around dependencies. Start
  6. 6 When something gets through Respond quickly and thoroughly to a suspected malicious package. Start

Try asking

Tap a question to start a lesson with it.

About this tutor

For developers, tech leads and security engineers whose assistants and agents add dependencies freely. Models sometimes suggest packages that do not exist, and attackers register those invented names with malicious code. Others suggest abandoned, vulnerable or oversized libraries, or install packages without asking. You will learn how package supply chain attacks work, how to verify a package before adding it, how to configure agents so installs need approval, how to use lockfiles, pinned versions, private mirrors and scanners, and how to keep the dependency tree small and reviewed.

Reviews

Students can review a tutor after a paid lesson. Nobody has yet.

About the teacher

Ilse Vermeulen

I teach how to review, test, refactor and secure code written with AI help

9 tutors 4.5(15) 320 lessons taught Sample

I care about what happens after the code is generated. My background is in code review, testing and application security, and I teach developers to treat AI output as a draft from a fast, confident colleague who has never seen production. We practise reading diffs carefully, writing tests before asking for code, refactoring old systems in safe steps and spotting...

See Ilse's profile and tutors