am-i-hacked vs npm audit, Semgrep and antivirus

They answer different questions, so use more than one. am-i-hacked looks for signs that a project or machine is under attack. secure-semgrep finds insecure code with static analysis. npm audit, OSV-Scanner and Snyk match dependency versions against published advisories. Antivirus matches known malware. None of them proves code is safe.

Side by side

ToolQuestion it answersMethodBlind spot
am-i-hackedDoes this project, or this machine, show signs of an attack?Reads source, config and persistence entries for attack indicatorsKnown-vulnerable dependency versions; installed node_modules; known malware signatures
secure-semgrepIs this code insecure?Semgrep static analysis with bundled AI-agent, bash and SSRF rules plus registry packsMalware indicators such as auto-run tasks and disguised payloads
quarantine-review skillHow do I inspect an untrusted repository without running it?A procedure for an AI agent: contain, scan, read as data, extract with provenanceOnly as good as the reading; it is a method, not a scanner
npm audit, OSV-Scanner, Snyk Open SourceDoes any dependency version have a published advisory?Match the lockfile against vulnerability databasesUnreported attacks; anything committed into your repository
Semgrep (alone)Does code match these rules?Pattern-based static analysisWhatever the chosen rules do not cover
Antivirus and EDRIs a known-malicious file or behavior present on this machine?Signatures, reputation and behavior monitoringSource-level tricks in a repository you have not run yet

Which to use when

  • Before opening or running a repository you did not write: am-i-hacked, then read what it flags. See how to inspect an untrusted repository.
  • Before merging code you or an AI agent wrote: secure-semgrep, and your advisory scanner over the lockfile.
  • On every dev-server start and in CI: am-i-hacked and your advisory scanner. Both exit non-zero on findings.
  • When a machine might be compromised: am-i-hacked --system and am-i-being-recorded, alongside your antivirus or EDR, not instead of it.

Questions

Is am-i-hacked antivirus?

No. Antivirus matches files and behavior against known malware. am-i-hacked reads source code and configuration for warning signs of an attack, such as an editor task that runs on folder open or capture code paired with an exfiltration endpoint. It does not look up known malware, and a clean result does not prove safety.

Does am-i-hacked replace npm audit, OSV-Scanner or Snyk?

No. Those tools match dependency versions against published advisories. am-i-hacked looks for indicators in the code itself, including attacks committed into the repository or not yet reported. Run both.

What is the difference between am-i-hacked and secure-semgrep?

am-i-hacked looks for signs that code is malicious before you run it. secure-semgrep runs Semgrep static analysis to find insecure code you or an AI agent wrote, with bundled rules for AI-agent code, shell scripts and SSRF. They are complementary.

Is secure-semgrep a replacement for Semgrep?

No. It is a thin wrapper that needs semgrep installed. It adds bundled rules and picks Semgrep registry packs for your stack in one command.