Atomburst has released "Geiger," an open-source tool designed to inspect the configurations of AI agents running on machines, MCP (Model Context Protocol) servers, plugins, and AI extensions. This tool provides reports in plain language regarding what permissions each tool possesses, such as access to the file system, network usage, code execution, and retention of sensitive information.
Open-Source Tool "Geiger" Released to Inspect Permissions of AI Agents and MCP Servers
This article is a translation. Read the Japanese original
Targeted entities for inspection include CLI tools like Claude Code and DeepSeek Harness, development environments such as Claude Desktop, Cursor, VS Code, Windsurf, and Zed, as well as browser extensions. Additionally, it recognizes the policy enforcement layer applied by agents to MCP servers and reports its actual state.
Geiger operates in a read-only mode, reading only configuration files and directories; the tool itself does not execute any code it discovers. When outputting investigation results, sensitive information such as API keys is handled such that only the key name, file location, and value shape are reported, while the actual values themselves are not output. Data is processed only locally and is never sent to external servers.
Furthermore, it features functionality to suggest remediation steps for detected issues, a feature to compare differences with previous inspection results, and the ability to output exit codes intended for use in CI (Continuous Integration) environments.
Sources
- Show HN: Geiger – See every AI agent on your machine and what it can touch (Hacker News Frontpage、2026-09-09)
- Atomburst