惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

J
Java Code Geeks
腾讯CDC
M
MIT News - Artificial intelligence
Y
Y Combinator Blog
L
LangChain Blog
Vercel News
Vercel News
云风的 BLOG
云风的 BLOG
GbyAI
GbyAI
Stack Overflow Blog
Stack Overflow Blog
Microsoft Azure Blog
Microsoft Azure Blog
B
Blog RSS Feed
The GitHub Blog
The GitHub Blog
酷 壳 – CoolShell
酷 壳 – CoolShell
B
Blog
P
Proofpoint News Feed
H
Hackread – Cybersecurity News, Data Breaches, AI and More
博客园_首页
Google DeepMind News
Google DeepMind News
WordPress大学
WordPress大学
aimingoo的专栏
aimingoo的专栏
小众软件
小众软件
IT之家
IT之家
A
About on SuperTechFans
H
Help Net Security

Hacker News: Show HN

PurrrrrFocus: Pomodoro Timer App - App Store Workflow Engine — Multi-Step Orchestration for Bun RapidPhoto: Pro Photo Editor App - App Store GitHub - DheerG/swarms: Achieve extraordinary results with claude code across a variety of tasks SPICE simulation → oscilloscope → verification with Claude Code — Lucas Gerads Show HN: VCoding – A 5 MB native Windows IDE with no dynamic dependencies Show HN: LLMs don't hallucinate because they're bad at math, it's the format GitHub - Agent-FM/agentfm-core: AgentFM is a peer-to-peer network that turns everyday computers into a decentralized AI supercomputer. AgentFM lets you run massive AI workloads directly across a global mesh of idle CPUs and GPUs. Show HN: Tracking Top US Science Olympiad Alumni over Last 25 Years GitHub - Potarix/agent-hub: One place to talk to all your agents Show HN: Runtime security for AI agents(injection,tool abuse, data exfiltration) GitHub - dubeyKartikay/lazyspotify: Terminal Spotify client for macOS and Linux GitHub - the-banana-tool/king-louie: Easy to use GUI Personal AI Assistant. Win/Linux/Mac. Show HN I made my vacation rental bookable by AI agents–no Airbnb, 0% commission GitHub - basteez/jsf-autoreload: maven plugin to enable hot reload on jsf projects uvm32/hosts/host-gdbstub at main · ringtailsoftware/uvm32 GitHub - labsai/EDDI: Config-driven engine that turns JSON into production-grade AI agents. Multi-agent orchestration, 12+ LLM providers, MCP/A2A protocols, RAG, persistent memory, and enterprise compliance (EU AI Act, GDPR, HIPAA). Built on Quarkus. GitHub - glitchnsec/fortyone-oss: AI Executive Assistant Platform Quickstart | Alien GitHub - muxshed/shed: One stream in, or many. Every destination, simultaneously. No cloud middleman, no per-channel fees, no limits. GitHub - ocrbase-hq/ocrbase: 📄 PDF/IMG ->.MD/JSON Document OCR API for PaddleOCR and GLMOCR. Self-hostable. GitHub - impactjo/home-memory: MCP server that lets your AI assistant remember everything about your home. GitHub - Sets88/dbcls: DbCls is a powerful terminal database client that supports various databases GitHub - neptun2000/heor-agent-mcp GitHub - SeanFDZ/macmind: Single-layer transformer in HyperTalk for the classic Macintosh RollQuation: Math Puzzles - Apps on Google Play GitHub - dropbox/witchcraft Show HN: Agent-cache – Multi-tier LLM/tool/session caching for Valkey and Redis GitHub - opentalon/opentalon: OpenTalon is an open-source platform built from the ground up in Go as a robust alternative to OpenClaw LinkedIn™ 职位抓取工具 - Chrome 应用商店
GitHub - Secure-Code-HQ/audit: Open-source CLI agent for ...
juanisidoro · 2026-05-26 · via Hacker News: Show HN

Server Audit CLI

Run a security audit on your Linux server in 2 minutes. One command.

curl -sSL https://audit.securecodehq.com/run/YOUR_TOKEN | bash

Why this exists

Docker bypasses UFW silently. Redis runs without auth by default. PostgreSQL listens on 0.0.0.0 unless explicitly configured otherwise. SSH root login is enabled by default on most VPS providers.

These are the misconfigurations that keep appearing on production Linux servers because they require active checking to detect. Your firewall can look healthy while your database is fully exposed.

What it does

  • Scans SSH configuration (root login, port, authentication method, authorized keys)
  • Checks firewall exposure (open ports via ss/netstat)
  • Detects exposed secrets (.env files tracked by git, world-readable permissions, process environment)
  • Analyzes Docker misconfigurations (root containers, exposed ports, API access)
  • Checks database exposure (PostgreSQL, Redis, MongoDB network binding and auth)
  • Verifies system hardening (fail2ban, pending security updates, SSL certificates, swap, sudo users)
  • Reviews authentication logs (failed logins, attacking IPs, active attack detection)

What it does NOT do

  • Does not install anything persistent on your server
  • Does not open remote SSH connections to your server
  • Does not read file contents (only checks paths and permissions)
  • Does not run background processes or daemons
  • Does not modify any file, configuration, or system state
  • Does not store credentials, keys, or secrets
  • Self-deletes after execution

How the CLI works

The CLI does not contain security logic. It is a generic runner.

  1. It asks our backend: "what should I check?" (receives a list of commands)
  2. It runs those commands locally on your server (read-only)
  3. It sends the raw results as JSON to our backend
  4. Our backend analyzes the results and generates your report

The CLI never decides what is secure or insecure. It never scores, ranks, or evaluates anything. It executes commands and reports back.

What data leaves your server

Every field transmitted is documented:

Transparency

The source code in cli/ is the exact code that runs on your server. Not a simplified version, not a sanitized copy. The same code, byte for byte.

Every security check is documented with the exact command executed on your server:

Security model

How the system works, what runs where, and why it cannot harm your server:

Example output

See what a security report looks like before running anything:

curl -sSL https://audit.securecodehq.com/run/YOUR_TOKEN | bash

Dry run (no data sent)

curl -sSL https://audit.securecodehq.com/run/YOUR_TOKEN | bash -s -- --dry-run

This executes all checks locally and prints the full JSON payload to stdout without sending anything. Compare the output with our documented payload.

License

MIT