am-i-hacked vs npm audit, Semgrep and antivirus
They answer different questions, so use more than one. am-i-hacked looks for signs that a project or machine is under attack. secure-semgrep finds insecure code with static analysis. npm audit, OSV-Scanner and Snyk match dependency versions against published advisories. Antivirus matches known malware. None of them proves code is safe.
Side by side
| Tool | Question it answers | Method | Blind spot |
|---|---|---|---|
| am-i-hacked | Does this project, or this machine, show signs of an attack? | Reads source, config and persistence entries for attack indicators | Known-vulnerable dependency versions; installed node_modules; known malware signatures |
| secure-semgrep | Is this code insecure? | Semgrep static analysis with bundled AI-agent, bash and SSRF rules plus registry packs | Malware indicators such as auto-run tasks and disguised payloads |
| quarantine-review skill | How do I inspect an untrusted repository without running it? | A procedure for an AI agent: contain, scan, read as data, extract with provenance | Only as good as the reading; it is a method, not a scanner |
| npm audit, OSV-Scanner, Snyk Open Source | Does any dependency version have a published advisory? | Match the lockfile against vulnerability databases | Unreported attacks; anything committed into your repository |
| Semgrep (alone) | Does code match these rules? | Pattern-based static analysis | Whatever the chosen rules do not cover |
| Antivirus and EDR | Is a known-malicious file or behavior present on this machine? | Signatures, reputation and behavior monitoring | Source-level tricks in a repository you have not run yet |
Which to use when
- Before opening or running a repository you did not write: am-i-hacked, then read what it flags. See how to inspect an untrusted repository.
- Before merging code you or an AI agent wrote: secure-semgrep, and your advisory scanner over the lockfile.
- On every dev-server start and in CI: am-i-hacked and your advisory scanner. Both exit non-zero on findings.
- When a machine might be compromised:
am-i-hacked --systemandam-i-being-recorded, alongside your antivirus or EDR, not instead of it.
Questions
Is am-i-hacked antivirus?
No. Antivirus matches files and behavior against known malware. am-i-hacked reads source code and configuration for warning signs of an attack, such as an editor task that runs on folder open or capture code paired with an exfiltration endpoint. It does not look up known malware, and a clean result does not prove safety.
Does am-i-hacked replace npm audit, OSV-Scanner or Snyk?
No. Those tools match dependency versions against published advisories. am-i-hacked looks for indicators in the code itself, including attacks committed into the repository or not yet reported. Run both.
What is the difference between am-i-hacked and secure-semgrep?
am-i-hacked looks for signs that code is malicious before you run it. secure-semgrep runs Semgrep static analysis to find insecure code you or an AI agent wrote, with bundled rules for AI-agent code, shell scripts and SSRF. They are complementary.
Is secure-semgrep a replacement for Semgrep?
No. It is a thin wrapper that needs semgrep installed. It adds bundled rules and picks Semgrep registry packs for your stack in one command.