What the tools we audited actually did
A scanner reads a tool’s description of itself. We run it in an isolated microVM under syscall tracing and write down what it does. This is the last 7 days of that.
52
servers executed
in 26 unattended audit runs
358
tool calls made
each one traced at the syscall level
0
credential probes
reads of secrets we planted as bait
1
blocked connections
egress attempts under a deny-all firewall
Where they connected
Hostnames captured from DNS while the tools were running. When several tools share a host it is usually one publisher’s own backend behind several packages — worth knowing either way, since a tool’s README rarely lists where it phones.
Audited this week
Each name links to its evidence page — the tools exercised, the hosts contacted, and the checks that passed.
Window: 7 days · generated Thu, 10 Sep 2026 20:55:50 GMT
See total behavioral coverage — and where it stops →