am-i-being-recorded

am-i-being-recorded is a command-line tool that names the browser extension behind a screen-recording indicator. macOS only tells you which app is recording; npx am-i-being-recorded reads Chrome, Brave, Edge, Chromium and Vivaldi profiles and flags each extension that can capture the display or a tab, with its ID, version and profile. It also lists which apps hold camera, microphone and screen-recording permission.

Install and run

npx am-i-being-recorded                       # every detected browser profile
npx am-i-being-recorded --min-severity HIGH   # only the loud findings
npx am-i-being-recorded --strict              # exit 1 on any finding

Needs jq. Short alias: aibr. It reads local files and process lists, and makes no network calls.

What it detects

Extension permissionSeverityWhy
desktopCaptureCRITICALCan record the entire display
tabCaptureHIGHCan record the active tab's audio and video
debuggerHIGHFull tab control over the DevTools protocol
nativeMessagingMEDIUMCan launch a native helper process
userScriptsMEDIUMCan inject scripts into pages
managementLOWCan enable or disable other extensions

Escalations: display capture plus access to every site, and any capture permission plus an offscreen document, which lets a stream outlive the tab that started it.

Live context on macOS: whether screensharingd and replayd are running, and which apps hold camera, microphone and screen-recording grants, each with its code signer and Team ID. On Linux: which process holds a /dev/video* camera. These lines are context, not findings.

Exit codes

Default mode is evidence: findings are printed and the exit status is 0. --strict makes any reported finding exit 1.

What it does not do

  • It reports capability, not proof of an active stream.
  • Safari and Firefox extensions, standalone recorder apps, and a page's own screen-share prompt are out of scope.
  • macOS screen-recording grants need root or Full Disk Access to read; the tool says when it cannot.
  • It is not a malware scanner.

Facts

Plain bash, zero npm runtime dependencies, MIT licensed. Source: apps/am-i-being-recorded.