{"actions":{"bootstrapAndRun":{"effect":"installs rote if missing, inspects, prepares, and asks before running","href":"https://play.modiqo.ai/install?play=lgoyal6/dependency-confusion@0.2.0","method":"GET","rel":"https://rote.dev/rels/bootstrap-and-run","requiresConsent":true,"responseMediaType":"text/x-shellscript"},"inspect":{"command":"rote play inspect https://play.modiqo.ai/lgoyal6/dependency-confusion@0.2.0","effect":"read-only"},"installCliOnly":{"effect":"installs the rote CLI, nothing else","href":"https://play.modiqo.ai/install","method":"GET","rel":"https://rote.dev/rels/install-cli","requiresConsent":true,"responseMediaType":"text/x-shellscript"},"run":{"command":"rote play run https://play.modiqo.ai/lgoyal6/dependency-confusion@0.2.0","effect":"executes the play locally after consent","headless":{"approvalAssertion":"--yes","approvalRequiredBeforeInvocation":true,"commandTemplate":"rote play run https://play.modiqo.ai/lgoyal6/dependency-confusion@0.2.0 <name=value...> --yes","stdinPolicy":"never pipe input to automate the interactive Ready selector"},"requiresConsent":true}},"description":"Answers one question about a repository: which internal-looking dependencies could be hijacked by a public package of the same name. The bug is that an internal package name nobody claimed on the public registry can be registered by anyone, and the next install may pull theirs instead of yours. Four things are looked for: a dependency whose name looks internal (an npm scope this repository publishes under, a distribution prefix that matches how it names itself, a Go module on a host that is not a public forge, or a lockfile entry that does not resolve to the public registry); a private-registry configuration that does not pin the scope, meaning an .npmrc with a bare registry= line and no @scope:registry mapping, or a pip --extra-index-url, which ADDS an index rather than replacing one so pip queries both and installs the higher version; a lockfile entry for an internal-looking name that resolves from the public registry while the tree's own configuration expects a private source, meaning the public copy alrea","distribution":{"digest":"sha256:163b2b1084810359eb2edf5c24e627ea6ad086d074f6c7f1cf636bfd55b023fb","mediaType":"application/vnd.modiqo.rote-flow","size":36624,"verifiedBy":"rote verifies the downloaded archive against this digest before it runs"},"effects":{"credentialsProvidedBy":"runner","credentialsRemainLocal":true,"declaredWrites":[],"publisherReceivesCredentials":false},"id":"https://play.modiqo.ai/lgoyal6/dependency-confusion@0.2.0","inputPolicy":{"optionalWithDefault":"show_default_and_accept_override","optionalWithoutDefault":"omit_unless_supplied","required":"ask","secrets":"collect_locally_outside_conversation"},"links":{"docs":"https://rote.dev","page":"https://play.modiqo.ai/lgoyal6/dependency-confusion@0.2.0","protocol":"https://play.modiqo.ai/.well-known/rote","self":"https://play.modiqo.ai/lgoyal6/dependency-confusion@0.2.0.json"},"name":"dependency-confusion","owner":{"kind":"user","slug":"lgoyal6"},"parameters":[{"description":"Directory tree whose dependency manifests, lockfiles and registry configuration should be audited for names a public registry could hijack","example":".","input":{"allowCustom":true,"choices":[],"label":"Root"},"name":"root","required":true,"type":"string"},{"default":"6","description":"How many directory levels below root to search for dependency manifests","example":"3","input":{"allowCustom":true,"choices":[],"label":"Depth"},"name":"depth","required":false,"type":"string"}],"preparation":[{"action":{"command":"rote play inspect https://play.modiqo.ai/lgoyal6/dependency-confusion@0.2.0 --json","effect":"read-only"},"step":1,"type":"inspect_local_readiness"},{"references":["/parameters"],"step":2,"type":"collect_parameters"},{"references":["/parameters","/requirements","/effects"],"step":3,"type":"review"},{"consentBoundary":"the user approves the exact play and parameter values","references":["/parameters","/requirements","/effects"],"step":4,"type":"obtain_run_consent"},{"action":{"command":"rote play run https://play.modiqo.ai/lgoyal6/dependency-confusion@0.2.0","headlessCommandTemplate":"rote play run https://play.modiqo.ai/lgoyal6/dependency-confusion@0.2.0 <name=value...> --yes"},"preservesAcquisitionBoundaries":["adapter_selection","oauth_dcr","google_discovery","static_token_setup","runtime_security_checks"],"requiresConsent":true,"step":5,"type":"run"}],"producedBy":{"roteVersion":"0.79.0"},"publishedAt":"2026-09-04T04:31:44.745447+00:00","reference":"lgoyal6/dependency-confusion@0.2.0","requirements":{"adapters":[],"browser":{"dependencies":[],"runtime":false,"signIn":false},"localTools":["bash","python3","find","grep","sed","wc","tr","cat","mktemp","rm"],"roteCli":{"minimumVersion":"0.62.0"},"sessions":false},"resolution":"pinned","schema":"rote.play.v1","stats":{"downloads":1,"installs":0},"steps":{"count":3,"names":["analyze","discover","verify"]},"title":"dependency-confusion","type":"play","version":"0.2.0","visibility":"public"}