Guides
Each guide answers one question completely: what the risk is, what to do step by step, what the tools catch, and what they do not.
Check a cloned or downloaded repository for malicious code without opening, installing or running it: contain it, scan it with am-i-hacked, read the flagged files as text, and only then decide.
How to check code written by an AI coding assistant or agent (Claude Code, Cursor, GitHub Copilot, Codex and others) for malicious or insecure patterns before you run it, using am-i-hacked and secure-semgrep.
A .vscode/tasks.json task with runOn set to folderOpen runs a command as soon as you open a folder. How the attack works, how to spot it, and how to scan for it with am-i-hacked before opening a repository.
npm audit, OSV-Scanner and Snyk match dependencies against published advisories. An attack committed into a repository, or one not yet reported, is invisible to them. How to add indicator-based checks with am-i-hacked to a dev script, a git pull and CI.
A third-party agent skill is untrusted text and its installer is untrusted code. How to fetch a skill as data, pin it to a commit, scan it, read it and record where it came from, without running the installer. Uses the secure-skill-pull skill and am-i-hacked.
A read-only audit of a macOS or Linux developer machine with am-i-hacked --system: login persistence and code signatures, crontab, shell startup files, AI coding tool config, running processes and the folders tooling installs code into.
How to decide whether a macOS login item or "Background Items Added" entry is legitimate: map the name to its launchd plist, check the program's code signature and Team ID against the vendor, read script payloads without running them, and preserve evidence.
macOS says "Brave Browser is recording your screen" but not which tab or extension. am-i-being-recorded reads Chromium-family browser profiles and names the extensions that can capture the display or a tab.
A checklist for server-side request forgery (SSRF): allow only http and https on ports 80 and 443, resolve the host and reject every non-public address, follow redirects by hand, cap size and time, and connect to the address you checked. With hostile test inputs and Semgrep rules.