Avoiding Hallucinated APIs

Stop the model inventing plausible-but-fake functions, packages, and options by constraining the toolbox and verifying every call.

TL;DR

  1. Models invent plausible functions, options, and even package names that do not exist.
  2. Constrain the toolbox, pin versions, allow only named libraries, and show real signatures.
  3. Catch hallucinations with the type-checker, the docs, and by refusing to run unknown calls.

Know The Failure

    Fake Methods

    Calls to methods that sound right but do not exist on the object.

    arr.removeDuplicates()  // not a
    real Array method
    Fake Options

    Parameters or config keys the real API never accepts.

    fetch(url, { retry: 3 })  // fetch
    has no retry option
    Fake Packages

    Entirely invented package names, a real supply-chain risk.

    import x from 'super-utils-pro'
    // does this even exist?

Shrink The Space

    Pin Versions

    A version anchors the model to one real API surface.

    "React 18, Next 15. Use only their
    real APIs."
    Allow-List Libraries

    Restrict to the dependencies you actually have.

    "Use only: zod, date-fns. No other
    packages."
    Show Real Signatures

    Paste the actual exports so the model calls what exists.

    "Available: parse(s: string):
    Result. Use this."

Catch With Tools

    Type-Check

    The compiler flags unknown members and wrong options instantly.

    tsc --noEmit  # red on fake calls
    Lint & Resolve

    Linters and module resolution surface unknown imports.

    Unresolved import -> likely
    hallucinated package.
    Check The Docs

    Confirm any unfamiliar call against the official reference.

    Does the doc list this method?
    No -> do not use it.

Safe Habits

    Verify Before Install

    Never add a package you have not confirmed exists and is correct.

    Check the registry + repo before
    `npm i`.
    Ask For Sources

    Have the model name where an API is documented.

    "Which package/version documents
    this? Link it."
    Distrust Confidence

    Idiomatic-looking code is not proof the call is real.

    Looks right != is real. Verify.

Tips

  1. Paste the real module's exports or signature so the model calls what actually exists.
  2. Treat any unfamiliar method or package as guilty until verified against the official docs.

Warnings

  1. Hallucinated package names are a supply-chain risk: never install a package you have not verified exists.
  2. Fake calls often look perfectly idiomatic, so they pass a casual read; let the compiler check, not your eyes.

In Practice

FAQ