[{"data":1,"prerenderedAt":4},["ShallowReactive",2],{"readme:geiger":3},"\u003Ch1>geiger\u003C\u002Fh1>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fgithub.com\u002FAtomburstofficial\u002Fgeiger\u002Factions\u002Fworkflows\u002Fci.yml\" rel=\"nofollow ugc noopener\">\u003Cimg src=\"https:\u002F\u002Fgithub.com\u002FAtomburstofficial\u002Fgeiger\u002Factions\u002Fworkflows\u002Fci.yml\u002Fbadge.svg\" alt=\"CI\" \u002F>\u003C\u002Fa>\n\u003Ca href=\"https:\u002F\u002Fwww.npmjs.com\u002Fpackage\u002Fgeiger-scan\" rel=\"nofollow ugc noopener\">\u003Cimg src=\"https:\u002F\u002Fimg.shields.io\u002Fnpm\u002Fv\u002Fgeiger-scan\" alt=\"npm\" \u002F>\u003C\u002Fa>\n\u003Ca href=\"https:\u002F\u002Fgithub.com\u002FAtomburstofficial\u002Fgeiger\u002Fblob\u002FHEAD\u002FLICENSE\" rel=\"nofollow ugc noopener\">\u003Cimg src=\"https:\u002F\u002Fimg.shields.io\u002Fbadge\u002Flicense-MIT-blue.svg\" alt=\"license: MIT\" \u002F>\u003C\u002Fa>\n\u003Cimg src=\"https:\u002F\u002Fimg.shields.io\u002Fbadge\u002Fnode-%E2%89%A518-brightgreen\" alt=\"node ≥18\" \u002F>\n\u003Cimg src=\"https:\u002F\u002Fimg.shields.io\u002Fbadge\u002Fdependencies-0-success\" alt=\"dependencies: 0\" \u002F>\u003C\u002Fp>\n\u003Cp>\u003Cstrong>A Geiger counter for AI agents.\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>One read-only command that inventories every AI agent, harness, MCP server,\nplugin, and AI extension on a machine — and tells you, in plain language,\nwhat each one can touch.\u003C\u002Fp>\n\u003Cpre>\u003Ccode>npx geiger-scan\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>No install. No account. No telemetry. Reads configs and directories, writes\nnothing (unless you ask for \u003Ccode>--json yourfile.json\u003C\u002Fcode>).\u003C\u002Fp>\n\u003Cp>\u003Cimg src=\"https:\u002F\u002Fraw.githubusercontent.com\u002FAtomburstofficial\u002Fgeiger\u002FHEAD\u002Fdocs\u002Fscan-terminal.svg\" alt=\"A geiger scan: findings grouped by ecosystem with exposure labels, a redacted credential, and plain-language fixes\" \u002F>\u003C\u002Fp>\n\u003Ch2>Why this exists\u003C\u002Fh2>\n\u003Cp>In August 2026, an open-source agent harness went from zero to 200,000+\nGitHub stars in three weeks. Its plugin ecosystem passed 13,000 repositories\nin the same window. One-click desktop clients appeared the same day it\nlaunched. Instagram carousels now teach office workers to install all of it.\u003C\u002Fp>\n\u003Cp>Every one of those installs is a program that can execute commands, read\nfiles, and hold credentials — configured in dotfiles nobody looks at twice.\nAsk yourself the question this tool answers: \u003Cstrong>what is actually running on\nthis machine, and what can it reach?\u003C\u002Fstrong> Most people cannot answer it. Now\nit's one command.\u003C\u002Fp>\n\u003Ch2>What a scan looks like\u003C\u002Fh2>\n\u003Cpre>\u003Ccode>  GEIGER  ·  a Geiger counter for AI agents\n  machine dev-laptop  ·  2026-09-06 12:24 UTC  ·  read-only · no telemetry\n  ──────────────────────────────────────────────────────────────\n\n  9 findings across 3 ecosystems  ·  7 can execute code  ·  1 credential in config files\n\n  claude-code  (6)\n    Claude Code  agent\n      [EXECUTES] [BROAD-FILESYSTEM] [NETWORK]\n      origin: registry · @anthropic-ai\u002Fclaude-code\n    magic (Claude Code · global)  MCP server\n      [EXECUTES] [HOLDS-SECRETS] [BROAD-FILESYSTEM]\n      origin: registry · @21st-dev\u002Fmagic@latest\n      credential: \"API_KEY\" — opaque value under a credential-named key · ~\u002F.claude.json\n      note: wrapped by a policy agent (domainguard-agent.exe) — enforcement layer in front of the server\n    hooks: UserPromptSubmit, PreToolUse  hook\n      [EXECUTES]\n      note: hooks execute without a prompt each time their event fires\n  ...\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>Real output from a real machine (values redacted — see below).\u003C\u002Fp>\n\u003Ch2>What it detects\u003C\u002Fh2>\n\u003Ctable>\n\u003Cthead>\n\u003Ctr>\n\u003Cth>Ecosystem\u003C\u002Fth>\n\u003Cth>What geiger reads\u003C\u002Fth>\n\u003C\u002Ftr>\n\u003C\u002Fthead>\n\u003Ctbody>\u003Ctr>\n\u003Ctd>\u003Cstrong>Claude Code\u003C\u002Fstrong>\u003C\u002Ftd>\n\u003Ctd>global + per-project MCP servers, hooks, plugins, skills, subagents, \u003Ccode>apiKeyHelper\u003C\u002Fcode>\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>\u003Cstrong>MCP hosts\u003C\u002Fstrong>\u003C\u002Ftd>\n\u003Ctd>Claude Desktop, Cursor, Windsurf, VS Code (user + project), Cline, Roo Code, Continue, Zed\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>\u003Cstrong>Other agents\u003C\u002Fstrong>\u003C\u002Ftd>\n\u003Ctd>Codex CLI, Gemini CLI, Kilo CLI, Grok Build, Aider, OpenCode, Qwen Code, DeepSeek Harness, Continue, GitHub Copilot CLI, Goose, JetBrains Junie, Open Interpreter, LM Studio, Ollama\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>\u003Cstrong>Editor extensions\u003C\u002Fstrong>\u003C\u002Ftd>\n\u003Ctd>AI extensions in VS Code \u002F Insiders \u002F Cursor\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>\u003Cstrong>JetBrains IDEs\u003C\u002Fstrong>\u003C\u002Ftd>\n\u003Ctd>AI Assistant \u002F MCP settings presence per product (the settings live inside the IDE — geiger points you at the right screen)\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>\u003Cstrong>Global CLIs\u003C\u002Fstrong>\u003C\u002Ftd>\n\u003Ctd>agent packages in global npm roots (read directly — npm is never executed)\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>\u003Cstrong>Browser extensions\u003C\u002Fstrong>\u003C\u002Ftd>\n\u003Ctd>AI extensions in Chrome \u002F Edge \u002F Brave \u002F Firefox profiles, with their granted permissions\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003C\u002Ftbody>\u003C\u002Ftable>\n\u003Cp>Every finding gets: what it is, where it came from (registry, store, git,\nlocal script, remote server — or \u003Cstrong>UNKNOWN-ORIGIN\u003C\u002Fstrong>), what it can do\n(\u003Cstrong>EXECUTES\u003C\u002Fstrong>, \u003Cstrong>HOLDS-SECRETS\u003C\u002Fstrong>, \u003Cstrong>BROAD-FILESYSTEM\u003C\u002Fstrong>, \u003Cstrong>BROAD-WEB\u003C\u002Fstrong>,\n\u003Cstrong>NETWORK\u003C\u002Fstrong>), and the evidence path so you can verify by hand.\u003C\u002Fp>\n\u003Cp>Geiger also recognizes \u003Cstrong>policy wrappers\u003C\u002Fstrong> (agents that put an enforcement\nlayer in front of MCP servers) and reports both layers instead of hiding the\nreal server behind the w\u003C\u002Fp>\n",1789121862670]