Security, trust and threat model
secure-devtools is open source under the MIT license and maintained by Isaac Bell. The tools are plain bash with zero npm runtime dependencies. am-i-hacked and am-i-being-recorded are read-only and make no network calls; none of the tools collects telemetry. Each package is tested in CI and released with npm two-factor authentication. Vulnerabilities are reported privately through GitHub security advisories.
What runs on your machine
- Each tool is a bash script. The npm packages have zero runtime dependencies and ship only
bin/,README.md,LICENSEand, for am-i-hacked and am-i-being-recorded,CHANGELOG.md; secure-semgrep also ships itsrules/. npxdownloads the package from npm. To pin what runs, use a version (npx am-i-hacked@2) or install it as a dev dependency with a lockfile.- Releases are tagged
<name>@<version>in the repository.
Permissions and network behavior
| Tool | Reads | Writes | Network |
|---|---|---|---|
| am-i-hacked (folder) | Files under the scanned folder | Nothing | None |
am-i-hacked --system | Login items, crontab, shell startup files, AI-tool config, process list; runs codesign read-only on macOS | Nothing | None. No root or sudo. |
| safe-pull | Incoming commits | Fast-forwards your branch only when the inspection is clean | git fetch from your remote |
| am-i-being-recorded | Browser profile folders, process list, macOS privacy database where permitted | Nothing | None |
| secure-semgrep | The code you point it at | Nothing of its own | Semgrep downloads registry packs; -N uses bundled rules only |
The tools collect no telemetry and need no account or API key. Secret values found in config are never printed. The skills installer CLI, which is a separate project, reports anonymous install counts to skills.sh; set DISABLE_TELEMETRY=1 to turn that off.
Threat model
In scope: attacks that reach a developer through code they are about to open, install or run, and the persistence, capture and tool-config changes such attacks leave on the machine. Examples: an editor task that runs on folder open, a malicious install script, an obfuscated payload, a capture tool sending to a Telegram bot, a hook added to an AI coding tool, a tampered login item.
Out of scope: known-vulnerable dependency versions (use an advisory scanner), known malware signatures (use antivirus or EDR), kernel or firmware compromise, and anything that hides from a read-only user-level scan. The scanners can miss malware and can flag code that is fine.
A detection bypass, a way to make a scan pass while the thing it should catch is present, is treated as a security vulnerability.
Testing and CI
- Each package has a Bats test suite. Lint and format run with
shellcheckandshfmt.mise run checkruns all of it, locally and in CI. - The repository's own security gate runs am-i-hacked on every pull request. It uses
pull_request_targetwith the workflow, scanner and toolchain from the base branch, checks out the pull request as data only, and has a read-only token and no secrets. - CI also runs a gitleaks secret scan, Semgrep, GitHub dependency review and a CodeAnt AI scan. Actions are pinned to commit SHAs.
Release process
- Each package is released on its own from a clean
main, with npm two-factor authentication. - The release script runs the full check first, refuses a version already on npm, and refuses any package with lifecycle scripts (
prepare,prepack,postinstalland the like) that would run during pack, publish or install. - Each package has a changelog. Behavior changes are marked CHANGED.
Reporting a vulnerability
Report privately through a GitHub security advisory, not a public issue. Only the latest release of each package gets security fixes. Published fixes are listed under security advisories. The full policy is in SECURITY.md.
Project facts
- Maintainer: Isaac Bell (@IsaacBell).
- License: MIT. Third-party notices are in NOTICE.md.
- Platforms: macOS and Linux.
- Current releases: am-i-hacked 2.0.1, am-i-being-recorded 1.0.0, secure-semgrep 1.0.1.
- Plans: ROADMAP.md.