Skip to main content

🛡️ AI-Hacking Self-Audit (MVP v0.1)

A non-intrusive, zero-exfiltration personal security self-audit for macOS.

Why

AI-automated attacks now hit individuals, not just enterprises. This tool shows your security score and exactly what to fix — without attacking anything and without sending a single byte off your machine.

Principles

  • Non-intrusive: reads local settings/permissions/git/network only. No exploiting.
  • Zero-exfiltration: 100% local. No network calls (no socket/urllib/requests imports — verify it yourself).
  • No value leakage: secret values are never recorded — only their location.
  • Zero dependencies: Python standard library only → easy single-binary / pip install.

Install & run

pip install ai-hacking-defense
ai-hacking-defense     # or: python3 scan.py → security_report.html

Checks: credentials · network · OS hardening · AI-agent risk · backup

License: open-core (free core, paid Pro). Zero-exfil is verifiable in source.

Docs

Feedback becomes releases

ai-hacking-defense feedback builds a masked, fully-previewed report draft — nothing is ever sent automatically; you submit it yourself on GitHub. Issues are collected into a backlog daily and shipped as releases with a public CHANGELOG, so your report visibly becomes the next version.

Platforms (honest note)

macOS: all checks verified. Windows/Linux: experimental — runs, but not yet fully verified.

Known limits (honest)

Detection catches common evasions, not all. Known gaps we have not closed yet:

  • SSH private-key detection reads the PEM header in the first 8KB; a key hidden past 8KB, or in a non-PEM container (e.g. PuTTY .ppk), may be missed.
  • Backup freshness rejects future-dated and empty commits, but a single trivial commit made just now still counts as a "recent backup" — it does not verify the backup is meaningful or restorable.
  • Wi-Fi checks read only your own current connection (encryption type, DNS servers, ARP for gateway-MAC duplication). Router-side items (WPS, the default admin password, firmware) are off-device and are NOT auto-checked — check them yourself in the router admin page. A duplicated gateway MAC is reported as a possible MITM, not a verdict (proxy ARP, mesh routers, or a VPN can cause it legitimately).
  • Vault/secret-access detection catches common obfuscations (base64, bidi, whitespace/quote split, and bare interpreter reads like open(vault).read()), but it is best-effort, not a guarantee: a read assigned to a variable and then printed/sent, a backslash-escaped command (e.g. ca\t), or copying/sourcing the file (cp, source) can still be missed — new evasions always exist.
  • Real-time file-access / exfil watch is snapshot-based (via lsof), not a continuous kernel-level stream: without root not every read is observed, encrypted exfiltration is only inferred from read->connect timing (payload never inspected), and normal backup/sync/browser access is whitelisted (a brand-new legitimate tool may false-positive). It watches only the paths you specify, never the whole disk.
  • Detection rates (e.g. a 72-cell internal battery) are measured on our own corpora; real-world coverage will differ, and new evasions always exist.

What's in the package (v0.1.8)

Three stdlib-only command-line tools:

  • ahd-scan (also ai-hacking-defense) — the 7-area security self-audit (incl. Wi-Fi + file-access watch) + HTML report. Zero network.
  • ahd-agent-guard — prompt-injection detector (warn-only, no blocking). On a public prompt-injection evasion corpus it detects 29/30 (96.7%) at 0 false positives in our test. This 96.7% is the injection detector's rate on that one corpus — not an overall "defense rate" across every attack type. Zero network. echo "<text>" | ahd-agent-guard
  • ahd-threat-feed — refreshes public vulnerability feeds (OSV, CISA KEV, EPSS) to a local cache. GET-only of public databases from a fixed allowlist — none of your data is ever sent.

"Zero-exfiltration" precisely

ahd-scan and ahd-agent-guard make no network calls at all. ahd-threat-feed only downloads public vulnerability data (GET-only, allowlisted hosts) and uploads nothing. In all cases, none of your files, secrets, or data ever leave your machine — that is what zero-exfiltration means here.

Not in the package (internal-only, not advertised)

This package detects and reports. It does not auto-block, run a background dashboard, or hook into your pipelines. "Warn-only" is literal — see each report card's limits.

Reproduce the detection rate yourself

pip install ai-hacking-defense
python3 reproduce_detection.py   # prints detection % and false-positive % on a public evasion corpus

It reports 29/30 = 96.7% detection at 0 false positives on our standard prompt-injection corpus (one honest miss: full letter-spacing). Scope note: this measures the prompt-injection detector only; other attack types (credential, vault, network) are measured separately and are lower — not rolled into a single "defense rate."

Metadata

Release files for ai-hacking-defense 0.1.8

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for ai-hacking-defense 0.1.8
File Size Uploaded
ai_hacking_defense-0.1.8.tar.gz 56.6 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for ai-hacking-defense 0.1.8
File Interpreter ABI Platform
ai_hacking_defense-0.1.8-py3-none-any.whl Python 3 none any Details

Total release size: 111.5 kB

Release files / ai_hacking_defense-0.1.8.tar.gz

Download URL ai_hacking_defense-0.1.8.tar.gz
Size 56.6 kB
Tags Source
SHA-256 checksum
How to use checksums
6b4fa2f1525fa0b750a34d588d2f7e6defc500e1a62340ecfefd3689f06ff37c
BLAKE2b-256 checksum
How to use checksums
599d9a016f549d56eb48ccdd288a2d6131076775404222f099c0d63c67c520f4
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.2

Release files / ai_hacking_defense-0.1.8-py3-none-any.whl

Download URL ai_hacking_defense-0.1.8-py3-none-any.whl
Size 55.0 kB
Tags Python 3
SHA-256 checksum
How to use checksums
9e83cb27566706d6beeb9799c9ee597c5e91f6bbb7b4d5dc8f001b8712a90f67
BLAKE2b-256 checksum
How to use checksums
73bd9880eeba6a46278cfd7e7f14c2785c60bdd08f636d5ee4a2f41a80cbf2e7
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.2

Release history Release notifications | RSS feed

This release

0.1.8 This release

2 release files

0.1.7

2 release files

0.1.6

2 release files

0.1.5

2 release files

0.1.4

2 release files

0.1.3

2 release files

0.1.2

2 release files

0.1.1

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page