Security, trust and threat model

secure-devtools is open source under the MIT license and maintained by Isaac Bell. The tools are plain bash with zero npm runtime dependencies. am-i-hacked and am-i-being-recorded are read-only and make no network calls; none of the tools collects telemetry. Each package is tested in CI and released with npm two-factor authentication. Vulnerabilities are reported privately through GitHub security advisories.

What runs on your machine

  • Each tool is a bash script. The npm packages have zero runtime dependencies and ship only bin/, README.md, LICENSE and, for am-i-hacked and am-i-being-recorded, CHANGELOG.md; secure-semgrep also ships its rules/.
  • npx downloads the package from npm. To pin what runs, use a version (npx am-i-hacked@2) or install it as a dev dependency with a lockfile.
  • Releases are tagged <name>@<version> in the repository.

Permissions and network behavior

ToolReadsWritesNetwork
am-i-hacked (folder)Files under the scanned folderNothingNone
am-i-hacked --systemLogin items, crontab, shell startup files, AI-tool config, process list; runs codesign read-only on macOSNothingNone. No root or sudo.
safe-pullIncoming commitsFast-forwards your branch only when the inspection is cleangit fetch from your remote
am-i-being-recordedBrowser profile folders, process list, macOS privacy database where permittedNothingNone
secure-semgrepThe code you point it atNothing of its ownSemgrep downloads registry packs; -N uses bundled rules only

The tools collect no telemetry and need no account or API key. Secret values found in config are never printed. The skills installer CLI, which is a separate project, reports anonymous install counts to skills.sh; set DISABLE_TELEMETRY=1 to turn that off.

Threat model

In scope: attacks that reach a developer through code they are about to open, install or run, and the persistence, capture and tool-config changes such attacks leave on the machine. Examples: an editor task that runs on folder open, a malicious install script, an obfuscated payload, a capture tool sending to a Telegram bot, a hook added to an AI coding tool, a tampered login item.

Out of scope: known-vulnerable dependency versions (use an advisory scanner), known malware signatures (use antivirus or EDR), kernel or firmware compromise, and anything that hides from a read-only user-level scan. The scanners can miss malware and can flag code that is fine.

A detection bypass, a way to make a scan pass while the thing it should catch is present, is treated as a security vulnerability.

Testing and CI

  • Each package has a Bats test suite. Lint and format run with shellcheck and shfmt. mise run check runs all of it, locally and in CI.
  • The repository's own security gate runs am-i-hacked on every pull request. It uses pull_request_target with the workflow, scanner and toolchain from the base branch, checks out the pull request as data only, and has a read-only token and no secrets.
  • CI also runs a gitleaks secret scan, Semgrep, GitHub dependency review and a CodeAnt AI scan. Actions are pinned to commit SHAs.

Release process

  • Each package is released on its own from a clean main, with npm two-factor authentication.
  • The release script runs the full check first, refuses a version already on npm, and refuses any package with lifecycle scripts (prepare, prepack, postinstall and the like) that would run during pack, publish or install.
  • Each package has a changelog. Behavior changes are marked CHANGED.

Reporting a vulnerability

Report privately through a GitHub security advisory, not a public issue. Only the latest release of each package gets security fixes. Published fixes are listed under security advisories. The full policy is in SECURITY.md.

Project facts

  • Maintainer: Isaac Bell (@IsaacBell).
  • License: MIT. Third-party notices are in NOTICE.md.
  • Platforms: macOS and Linux.
  • Current releases: am-i-hacked 2.0.1, am-i-being-recorded 1.0.0, secure-semgrep 1.0.1.
  • Plans: ROADMAP.md.