am-i-being-recorded
am-i-being-recorded is a command-line tool that names the browser extension behind a screen-recording indicator. macOS only tells you which app is recording; npx am-i-being-recorded reads Chrome, Brave, Edge, Chromium and Vivaldi profiles and flags each extension that can capture the display or a tab, with its ID, version and profile. It also lists which apps hold camera, microphone and screen-recording permission.
Install and run
npx am-i-being-recorded # every detected browser profile
npx am-i-being-recorded --min-severity HIGH # only the loud findings
npx am-i-being-recorded --strict # exit 1 on any finding
Needs jq. Short alias: aibr. It reads local files and process lists, and makes no network calls.
What it detects
| Extension permission | Severity | Why |
|---|---|---|
desktopCapture | CRITICAL | Can record the entire display |
tabCapture | HIGH | Can record the active tab's audio and video |
debugger | HIGH | Full tab control over the DevTools protocol |
nativeMessaging | MEDIUM | Can launch a native helper process |
userScripts | MEDIUM | Can inject scripts into pages |
management | LOW | Can enable or disable other extensions |
Escalations: display capture plus access to every site, and any capture permission plus an offscreen document, which lets a stream outlive the tab that started it.
Live context on macOS: whether screensharingd and replayd are running, and which apps hold camera, microphone and screen-recording grants, each with its code signer and Team ID. On Linux: which process holds a /dev/video* camera. These lines are context, not findings.
Exit codes
Default mode is evidence: findings are printed and the exit status is 0. --strict makes any reported finding exit 1.
What it does not do
- It reports capability, not proof of an active stream.
- Safari and Firefox extensions, standalone recorder apps, and a page's own screen-share prompt are out of scope.
- macOS screen-recording grants need root or Full Disk Access to read; the tool says when it cannot.
- It is not a malware scanner.
Facts
Plain bash, zero npm runtime dependencies, MIT licensed. Source: apps/am-i-being-recorded.