Plain-shell tools that check the code you are about to run, and the machine you run it on, for signs of a supply-chain or dev-environment attack. They run locally, need no account or API key, and have zero npm runtime dependencies.
npx am-i-hackedStatus: actively maintained, macOS and Linux. Current releases: am-i-hacked 2.1.0, am-i-being-recorded 1.0.0, secure-semgrep 1.0.1. Each package's changelog has the detail. Website: https://isaacbell.github.io/secure-devtools/, with guides such as how to inspect an untrusted repository and how to check AI-generated code.
| Tool | What it checks | Run |
|---|---|---|
am-i-hacked |
A project folder, before you open, install or run it, for malicious-code indicators: editor tasks that run on folder open, payloads disguised as asset files, obfuscation, capture code paired with an exfiltration endpoint, .env files in the git index, risky package.json scripts, official Yarn releases by SHA256, and Python virtualenv integrity. With --system, this machine: login items and their code signatures, crontab, shell startup files, AI-tool config, running processes, and the caches and bin folders where tooling installs code outside any project. |
npx am-i-hacked |
am-i-being-recorded |
Which browser extension is behind a screen-recording indicator, and what else on the machine can capture you. | npx am-i-being-recorded |
secure-semgrep |
Bundled Semgrep rules you own — AI-agent, bash and SSRF patterns — plus maintained registry loadouts (Python, JS, TS, React, Node, Rust), fetched from the Semgrep registry at scan time. Needs semgrep on PATH. |
npx secure-semgrep ./src |
Install all seven for your user account, or pick one:
npx skills add IsaacBell/secure-devtools -g
npx skills add IsaacBell/secure-devtools --skill ssrf-safe-fetchDrop -g to install into the current project, and add --list to see the skills without installing. The skills command reports anonymous install counts to skills.sh; set DISABLE_TELEMETRY=1 to turn that off.
The skills, in skills/: quarantine-review (inspect an untrusted repository without running any of it), secure-skill-pull (vet a skill or plugin from a URL without running its installer), create-skill (write, check and publish an agent skill), skill-publish-review (review skills before they go into a public repository), ssrf-safe-fetch (validate the URL and the resolved address before a server fetches it), login-item-triage (the manual method behind am-i-hacked's login-item signature checks) and jujutsu.
- One command from a cold machine:
npx am-i-hackedneeds no signup, account, API key or install step. - Exit
1on HIGH or MEDIUM findings, so it works as a pre-commit hook, apackage.jsonscript or a CI step. The am-i-hacked README has the workflow snippet. - It reads the repository for indicators advisory scanners cannot report: a
.vscode/tasks.jsonthat runs on folder open, a payload saved as a font file, a launchd or systemd item that starts at login, a capture tool paired with an exfiltration endpoint.npm audit, OSV-Scanner and Snyk match your dependencies against published advisories, so an unreported attack, or one committed into the tree, stays invisible to them. Run both.
The scanners look for warning signs; they are not antivirus and do not look up known viruses. A clean result means no warning signs were found, not that the code or the machine is safe. Some checks also flag ordinary code, such as eval; when a line is fine, mark it reviewed with a short reason (am-i-hacked-ignore: <reason>) and it still appears as reviewed on every run.
mise installs the pinned toolchain (node, pnpm, shellcheck, shfmt, ripgrep, jq, semgrep) from mise.toml.
mise install # the toolchain
mise run setup # dev dependencies and git hooks
mise run check # shellcheck, shfmt check and the bats tests: what CI runsmise run lists every task. The git hooks run the same checks before each commit. CI in .github/workflows/ runs the checks and tests, this repository's own security gate (mise run gate), a gitleaks secret scan, Semgrep, dependency review and a CodeAnt AI scan. Releases: docs/RELEASING.md. Static analysis runs as mise run semgrep (review mode) or mise run semgrep-strict (gate); secure-semgrep's README documents the loadouts and CI snippets.
- Maintainer: Isaac Bell (@IsaacBell).
- Contributing: CONTRIBUTING.md. Issues and pull requests are welcome.
- Security problems: report them privately; SECURITY.md has the details. Please do not open a public issue. Published fixes are listed under security advisories.
- Sponsor the work: ko-fi.
npm fundpoints to the same page.