OX VibeSec has added dependency vetting for packages that AI agents try to install. The feature checks every installation attempt against policy and blocks bad attempts before the package reaches a developer’s machine.

The feature now blocks known-malicious packages with no exceptions. A configurable cool-down period blocks newly published packages.

Claim check:

  • OX VibeSec has added a new dependency-vetting feature for packages that AI agents try to install. (confirmed by the publication itself: evidence; «OX VibeSec’s new Dependency Vetting capability inspects every install attempt against policy and blocks bad ones before they land with no workflow change required.»)
  • The feature checks every installation attempt against policy and blocks bad attempts before the package reaches a developer’s machine. (confirmed by the publication itself: evidence; «It inspects each dependency an agent tries to pull in, checks it against policy, and blocks bad attempts with a clear, actionable reason before the package ever touches the developer’s machine or your SBOM.»)
  • The feature now blocks known-malicious packages with no exceptions. (confirmed by the publication itself: evidence; «Available today: Known-malicious packages are blocked outright, no exceptions.»)
  • A configurable cool-down period blocks newly published packages. (confirmed by the publication itself: evidence; «There’s also a configurable cool-down period that blocks freshly published packages before the community has had a chance to flag them.»)

Primary sources:

score 66.7 · kind announcement · revision 1 · stories st-1wu8j56