🛡️ AI-Hacking Self-Audit (MVP v0.1)
A non-intrusive, zero-exfiltration personal security self-audit for macOS.
Why
AI-automated attacks now hit individuals, not just enterprises. This tool shows your security score and exactly what to fix — without attacking anything and without sending a single byte off your machine.
Principles
- Non-intrusive: reads local settings/permissions/git/network only. No exploiting.
- Zero-exfiltration: 100% local. No network calls (no socket/urllib/requests imports — verify it yourself).
- No value leakage: secret values are never recorded — only their location.
- Zero dependencies: Python standard library only → easy single-binary / pip install.
Install & run
pip install ai-hacking-defense
ai-hacking-defense # or: python3 scan.py → security_report.html
Checks: credentials · network · OS hardening · AI-agent risk · backup
License: open-core (free core, paid Pro). Zero-exfil is verifiable in source.
Docs
Feedback becomes releases
ai-hacking-defense feedback builds a masked, fully-previewed report draft — nothing is ever sent automatically; you submit it yourself on GitHub. Issues are collected into a backlog daily and shipped as releases with a public CHANGELOG, so your report visibly becomes the next version.
Platforms (honest note)
macOS: all checks verified. Windows/Linux: experimental — runs, but not yet fully verified.
Known limits (honest)
Detection catches common evasions, not all. Known gaps we have not closed yet:
- SSH private-key detection reads the PEM header in the first 8KB; a key hidden past 8KB, or in a non-PEM container (e.g. PuTTY
.ppk), may be missed. - Backup freshness rejects future-dated and empty commits, but a single trivial commit made just now still counts as a "recent backup" — it does not verify the backup is meaningful or restorable.
- Wi-Fi checks read only your own current connection (encryption type, DNS servers, ARP for gateway-MAC duplication). Router-side items (WPS, the default admin password, firmware) are off-device and are NOT auto-checked — check them yourself in the router admin page. A duplicated gateway MAC is reported as a possible MITM, not a verdict (proxy ARP, mesh routers, or a VPN can cause it legitimately).
- Vault/secret-access detection catches common obfuscations (base64, bidi, whitespace/quote split, and bare interpreter reads like
open(vault).read()), but it is best-effort, not a guarantee: a read assigned to a variable and then printed/sent, a tab-escaped command (e.g.ca+ TAB +t), or copying/sourcing the file (cp,source) can still be missed — new evasions always exist. - Detection rates (e.g. a 72-cell internal battery) are measured on our own corpora; real-world coverage will differ, and new evasions always exist.
What's in the package (v0.1.7)
Three stdlib-only command-line tools:
ahd-scan(alsoai-hacking-defense) — the 6-area security self-audit (now incl. Wi-Fi) + HTML report. Zero network.ahd-agent-guard— prompt-injection detector (warn-only, no blocking). On a public prompt-injection evasion corpus it detects 29/30 (96.7%) at 0 false positives in our test. This 96.7% is the injection detector's rate on that one corpus — not an overall "defense rate" across every attack type. Zero network.echo "<text>" | ahd-agent-guardahd-threat-feed— refreshes public vulnerability feeds (OSV, CISA KEV, EPSS) to a local cache. GET-only of public databases from a fixed allowlist — none of your data is ever sent.
"Zero-exfiltration" precisely
ahd-scan and ahd-agent-guard make no network calls at all. ahd-threat-feed only downloads public vulnerability data (GET-only, allowlisted hosts) and uploads nothing. In all cases, none of your files, secrets, or data ever leave your machine — that is what zero-exfiltration means here.
Not in the package (internal-only, not advertised)
This package detects and reports. It does not auto-block, run a background dashboard, or hook into your pipelines. "Warn-only" is literal — see each report card's limits.
Reproduce the detection rate yourself
pip install ai-hacking-defense
python3 reproduce_detection.py # prints detection % and false-positive % on a public evasion corpus
It reports 29/30 = 96.7% detection at 0 false positives on our standard prompt-injection corpus (one honest miss: full letter-spacing). Scope note: this measures the prompt-injection detector only; other attack types (credential, vault, network) are measured separately and are lower — not rolled into a single "defense rate."
Metadata
Release files for ai-hacking-defense 0.1.7
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| ai_hacking_defense-0.1.7.tar.gz | 51.0 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| ai_hacking_defense-0.1.7-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 100.5 kB
Release files / ai_hacking_defense-0.1.7.tar.gz
| Download URL | ai_hacking_defense-0.1.7.tar.gz |
|---|---|
| Size | 51.0 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
f6da92ca4737fa932e98ed89e90e77ea2f8d0d258c2b5827021501d04ea115ef
|
|
BLAKE2b-256 checksum How to use checksums |
cfd980311e2f95482dfcfd99312df465d7dbd012d8035d914f7449b2d3e5093a
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.13.2
|
Release files / ai_hacking_defense-0.1.7-py3-none-any.whl
| Download URL | ai_hacking_defense-0.1.7-py3-none-any.whl |
|---|---|
| Size | 49.6 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
fc0a4b60abbdbfbe8ffd185b4a93606b0960df0dc47374610f78b38b7f7e5c93
|
|
BLAKE2b-256 checksum How to use checksums |
2acdf03e184576c52fb34a4880d7f0283f6a83e5b3bf6950225748379f84a424
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.13.2
|