npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

am-i-being-recorded

v1.0.0

Published

Audit screen/tab capture surfaces and the browser extensions that can start them

Downloads

138

Readme

am-i-being-recorded

npm version License: MIT CI

Find out which browser extension is recording your screen — and what else on the machine can capture you.

pnpx am-i-being-recorded     # or: npx am-i-being-recorded

The sibling of am-i-hacked: that one audits your code, this one audits your machine.

macOS attributes an active capture to the application, never the tab or extension responsible. A purple indicator that says "Brave Browser is recording your screen" is accurate but not actionable. This tool turns that attribution back into a name.

Installation

Requires jq to read extension manifests. Everything else is preinstalled on macOS and most Linux distros.

# macOS
brew install jq

# Debian/Ubuntu
apt-get install jq

Run without installing:

pnpx am-i-being-recorded

Install as a dev dependency:

pnpm add -D am-i-being-recorded   # or: npm install -D am-i-being-recorded

What it checks

Browser extensions (macOS and Linux). Reads Chromium-family profile directories (Brave, Chrome, Chromium, Edge, Vivaldi) and flags extensions whose permissions allow display capture, tab capture, or deep browser control:

| Permission | Severity | Why it matters | | --- | --- | --- | | desktopCapture | CRITICAL | Can record the entire display | | tabCapture | HIGH | Can record the active tab's audio/video | | debugger | HIGH | Full tab control over the DevTools protocol | | nativeMessaging | MEDIUM | Can launch a native helper process | | userScripts | MEDIUM | Can inject arbitrary scripts into pages | | management | LOW | Can enable or disable other extensions |

Two combinations escalate:

  • desktopCapture + access to every site (<all_urls>) — recordings can include any page you visit.
  • any capture permission + offscreen — the stream can outlive the tab or window that requested it, which is the shape of a "stuck" indicator.

Only the newest installed version of an extension is reported once per profile; Chromium leaves older version directories behind, and they are not loaded.

Live context (not findings). On macOS: whether screensharingd and replayd are running, and which apps hold camera, microphone, and screen-recording grants in the TCC privacy database, each with its code signer and Team ID (signed: Zoom Video Communications, Inc. [BJ4HAAB9B3], unsigned, ad-hoc signed). An unsigned app holding a capture grant is worth a look. On Linux: which process holds a /dev/video* camera device. These lines are context for a human; findings come only from extension capabilities, so there is no "known good app" allowlist to maintain.

Usage

# Audit every detected browser profile on this machine
am-i-being-recorded

# Only the loud stuff
am-i-being-recorded --min-severity HIGH

# Gate mode: non-zero exit when anything at or above the floor is found
am-i-being-recorded --strict

# Scan a fixture tree instead of the live profiles (used by the tests)
am-i-being-recorded --root ./fixtures --no-live

The command is also installed as the short alias aibr.

Findings are severity-tagged and printed highest first. The default mode is evidence: findings are reported and the exit status stays 0. --strict turns any reported finding into exit status 1.

Reading the output

A stuck capture is usually an extension holding a display stream. The finding that explains the indicator names the extension, its ID, its version, and the profile it lives in:

  CRITICAL Example Screen Recorder (aaaabbbbccccddddeeeeffffgggghhhh) v1.2.3
           Google/Chrome/Default - Can capture the entire display (screen recording)
  HIGH     Example Screen Recorder (aaaabbbbccccddddeeeeffffgggghhhh) v1.2.3
           Google/Chrome/Default - Capture permission plus an offscreen document can outlive the visible tab

To stop the capture, disable or remove that extension in chrome://extensions (or brave://extensions), then restart the browser so the indicator clears. An extension installed in several profiles shows up once per profile.

Limitations

  • The extension pass reports capability, not proof of an active stream. A screen recorder you installed and use on purpose will (correctly) be flagged.
  • Live context is best-effort. macOS Screen Recording grants need root or Full Disk Access to read; the TCC schema is undocumented and may change. The tool says so instead of guessing.
  • Detection covers Chromium-family extensions. Safari and Firefox extensions, standalone recorder apps, and a page's own getDisplayMedia prompt are out of scope.
  • This is not a malware scanner. Treat it as triage that names a suspect.

Contributing

Bug reports and pull requests are welcome at https://github.com/IsaacBell/secure-devtools/issues.

# Clone the monorepo and work inside this package
cd apps/am-i-being-recorded
pnpm test          # bats test suite (runs against synthetic fixtures, not your real browser data)
pnpm lint          # shellcheck
pnpm format:check  # shfmt
pnpm check         # all of the above

The test suite drives the filesystem pass against synthetic profile trees so it runs without touching the host's real browser data and passes on Linux CI.

License

MIT — see LICENSE.