Geiger is a read-only command that inventories AI agents, their harnesses, MCP servers, plugins, and AI extensions on a computer and shows in plain language what each discovered component can access.
The tool requires no installation, account, or telemetry. It reads configurations and directories, writing data only when JSON output is explicitly requested.
Geiger checks Claude Code, MCP hosts, other agents, editor extensions, global CLIs, and AI browser extensions. MCP servers are programs through which AI agents connect to external tools. For every finding, it states what it is, where it came from, what it can do, and the evidence path for manual checking.
This is an inventory of known configuration, not observation of running programs. Therefore Geiger does not see agents in nonstandard paths, other user accounts, containers, or WSL.
Claim check:
- Geiger is a read-only command that inventories AI agents, harnesses, MCP servers, plugins, and AI extensions on a computer and explains in plain language what each can access. (confirmed by the publication itself: evidence; «A Geiger counter for AI agents. One read-only command that inventories every AI agent, harness, MCP server, plugin, and AI extension on a machine — and tells you, in plain language, what each one can touch.»)
- Geiger requires no installation, account, or telemetry, reads configurations and directories, and writes nothing except an explicitly requested JSON file. (confirmed by the publication itself: evidence; «No install. No account. No telemetry. Reads configs and directories, writes nothing (unless you ask for –json yourfile.json ).»)
- Geiger detects Claude Code, MCP hosts, other agents, editor extensions, global CLIs, and AI browser extensions. (confirmed by the publication itself: evidence; «Claude Code global + per-project MCP servers, hooks, plugins, skills, subagents, apiKeyHelper MCP hosts Claude Desktop, Cursor, Windsurf, VS Code (user + project), Cline, Roo Code, Continue, Zed Other agents Codex CLI, Gemini CLI, Aider, OpenCode, Qwen Code, DeepSeek Harness, Continue, GitHub Copilot CLI, Goose, Open Interpreter, LM Studio, Ollama Editor extensions AI extensions in VS Code / Insiders / Cursor Global CLIs agent packages in global npm roots (read directly — npm is never executed) Browser extensions AI extensions in Chrome / Edge / Brave profiles, with their manifest permissions»)
- For every finding, Geiger states what it is, where it came from, what it can do, and the evidence path for manual checking. (confirmed by the publication itself: evidence; «Every finding gets: what it is, where it came from (registry, store, git, local script, remote server — or UNKNOWN-ORIGIN ), what it can do ( EXECUTES , HOLDS-SECRETS , BROAD-FILESYSTEM , BROAD-WEB , NETWORK ), and the evidence path so you can verify by hand.»)
- Geiger reads known configuration locations rather than runtime behavior, so it does not see agents in nonstandard paths, other user accounts, containers, or WSL. (confirmed by the publication itself: evidence; «Geiger reads known config locations . Agents installed in nonstandard paths, other user accounts, containers, or WSL (from the Windows side) are not seen. It reads configuration, not runtime behavior .»)
Primary sources:
score 64.3 · kind announcement · revision 1 · stories st-140r63p