
Read-only CLI that inventories AI agents, MCP servers, plugins, and extensions on a machine, reporting their capabilities and exposure with plain-language remediation.
A Geiger counter for AI agents.
One read-only command that inventories every AI agent, harness, MCP server, plugin, and AI extension on a machine — and tells you, in plain language, what each one can touch.
npx geiger-scan
No install. No account. No telemetry. Reads configs and directories, writes
nothing (unless you ask for --json yourfile.json).
In August 2026, an open-source agent harness went from zero to 200,000+ GitHub stars in three weeks. Its plugin ecosystem passed 13,000 repositories in the same window. One-click desktop clients appeared the same day it launched. Instagram carousels now teach office workers to install all of it.
Every one of those installs is a program that can execute commands, read files, and hold credentials — configured in dotfiles nobody looks at twice. Ask yourself the question this tool answers: what is actually running on this machine, and what can it reach? Most people cannot answer it. Now it's one command.
GEIGER · a Geiger counter for AI agents
machine dev-laptop · 2026-09-06 12:24 UTC · read-only · no telemetry
──────────────────────────────────────────────────────────────
9 findings across 3 ecosystems · 7 can execute code · 1 credential in config files
claude-code (6)
Claude Code agent
[EXECUTES] [BROAD-FILESYSTEM] [NETWORK]
origin: registry · @anthropic-ai/claude-code
magic (Claude Code · global) MCP server
[EXECUTES] [HOLDS-SECRETS] [BROAD-FILESYSTEM]
origin: registry · @21st-dev/magic@latest
credential: "API_KEY" — opaque value under a credential-named key · ~/.claude.json
note: wrapped by a policy agent (domainguard-agent.exe) — enforcement layer in front of the server
hooks: UserPromptSubmit, PreToolUse hook
[EXECUTES]
note: hooks execute without a prompt each time their event fires
...
Real output from a real machine (values redacted — see below).
| Ecosystem | What geiger reads |
|---|---|
| Claude Code | global + per-project MCP servers, hooks, plugins, skills, subagents, apiKeyHelper |
| MCP hosts | MCP servers configured in Claude Desktop, Cursor, Windsurf, VS Code (user + project), Cline, Roo Code, Continue, Zed |
| AI apps & IDEs | Cursor, Windsurf, Zed, Claude Desktop, ChatGPT Desktop, Codex desktop app — reported by presence, so an installed client with zero MCP servers still shows up |
| Other agents | Codex CLI, Gemini CLI, Kilo CLI, Grok Build, Aider, OpenCode, Qwen Code, DeepSeek Harness, Continue, GitHub Copilot CLI, Goose, JetBrains Junie, Open Interpreter, LM Studio, Ollama |
| Hooks | Claude Code (settings), Cursor (hooks.json), Codex (notify in config.toml), Gemini CLI (settings) — the commands are listed, because hooks run with no prompt |
| Git hooks | live hooks in .git/hooks (samples ignored), core.hooksPath redirects, and merge drivers — git runs these itself, and agent tooling installs itself here |
| Skill & subagent text | what a skill actually says: its description, instruction text that tries to override the agent or hide work from you, commands with a hostile shape, and credential shapes — a name in a directory listing tells you nothing |
| Editor extensions | AI extensions in VS Code / Insiders / Cursor |
| JetBrains IDEs | AI Assistant / MCP settings presence per product (the settings live inside the IDE — geiger points you at the right screen) |
| Global CLIs | agent packages in global npm roots (read directly — npm is never executed) |
| AI browsers | Comet, Dia, ChatGPT Atlas — the browser is the agent, so its presence is a finding |
| Browser extensions | AI extensions in Chrome / Edge / Brave / Vivaldi / Arc / Comet / Dia / Atlas / Firefox profiles, with their granted permissions |
Every finding gets: what it is, where it came from (registry, store, git, local script, remote server — or UNKNOWN-ORIGIN), what it can do (EXECUTES, HOLDS-SECRETS, BROAD-FILESYSTEM, BROAD-WEB, NETWORK), and the evidence path so you can verify by hand.
Geiger also recognizes policy wrappers (agents that put an enforcement layer in front of MCP servers) and reports both layers instead of hiding the real server behind the wrapper.
--json file
you explicitly name.Node.js 18 or newer. That's it. Node ships with npm and npx, and
geiger has zero dependencies, so nothing else gets installed. No global
install, no admin rights, no account.
If Node isn't on the machine yet, it's one command with the package manager
you already have — then open a new terminal so npx is on the path:
winget install OpenJS.NodeJS.LTS # Windows
brew install node # macOS (Homebrew)
sudo apt install nodejs npm # Debian / Ubuntu
Other platforms and version managers (nvm, fnm): https://nodejs.org/en/download
npx geiger-scan scan, print the report
npx geiger-scan --html report.html self-contained HTML report with per-finding
"what to do" remediation guidance
npx geiger-scan --json out.json machine-readable findings (schemaVersion 1)
npx geiger-scan --path D:\repo1 --path E:\repo2
also scan these project directories for
project-level agent and MCP configs
npx geiger-scan --home C:\Users\other scan a different home root (another user
profile, a mounted image)
npx geiger-scan --strict exit 2 if anything can execute code or
holds secrets
npx geiger-scan --diff baseline.json compare against an earlier --json
snapshot: what appeared, disappeared,
or escalated since then
Drift alarm: once you've reviewed a machine, save a baseline
(--json baseline.json) and put geiger-scan --strict --diff baseline.json
in cron or CI. It exits 2 only when something new can execute code or
hold secrets — the standing, already-reviewed inventory stays quiet. Same
mental model as a lockfile: accept what's there, alarm on change.
Registry blocked, or want the unreleased main?
npx github:Atomburstofficial/geiger runs straight from this repo (still
needs Node — see Requirements).