Geiger's creator atomburst claims the released tool identifies AI agents running on a machine and what they can access, potentially giving operators a local inventory of agent exposure.
state: resolvedheat: lowuncertainty: mediumknownscott: lowagent-observability agentic-security local-agent-runtimeAtomburstofficialatomburst
What is this?
Geiger is a tool hosted in the Atomburstofficial/geiger GitHub repository and presented on Show HN by atomburst as a way to see AI agents on a machine and what they can touch. Its repository describes a read-only, no-telemetry command that inventories agents, MCP servers, plugins, and AI extensions; the sample output flags code execution, broad filesystem access, network access, and credentials in configuration files. These are creator claims and illustrative output: the supplied snippets do not establish detection completeness, whether discovered agents are actually running, or whether configuration-derived findings capture their effective access permissions.
Why it matters to Scott
Geiger’s claimed exposure inventory adds a tool example to the distinction Scott already holds in Observability and SiloOS: inspecting access is not enforcing containment. The supplied material establishes neither effective-permission verification nor applicability to his deployed workers, so it does not yet change his architecture or operating practice; radar pages on Actualis and Numbat track related visibility tools, not this Geiger release.
ip:concept.observabilityip:framework.siloosradar:actualis-local-coding-agent-observabilityradar:numbat-agent-endpoint-visibilityradar:concept.mcp-security
queries asked of Scott's wikis
- local coding agent inventory and runtime observability
- MCP server plugin permissions and credential exposure
- agent authority boundaries and least privilege
- agent harness filesystem network execution sandboxing
- configured permissions versus effective agent access
Measured heat
no measured readings yet — the hourly heat pass fills this in
How the heat travelled
Evidence (3) — ⭐ canonical anchor
Interpretation history
2026-09-28T05:29:28Z
Flowlight gave the case a second independent entrant, corroborating local agent-visibility tooling as an emerging category — but neither tool drew independent testing or adoption, and the category is already carried by Scott's Actualis/Numbat radar pages and his inspecting-is-not-enforcing canon. The Geiger episode itself closed at floor engagement (~0.33 pts/h vs 3.48 peak, day 19) with its detection claims still creator-asserted, so the case resolves absorbed into that established pattern rather than continuing as a watch.
2026-09-28T05:23:06Z
evidence attached: hn.story.49873751 — Second entrant (network-traffic visibility for local agents) corroborates the emerging local-agent-observability space the Geiger seed tracks.
2026-09-09T18:32:50Z
The refreshed discussion adds an unrelated agent-display idea, not a Geiger implementation or test. The announcement remains established, but inventory completeness and effective-access detection remain unvalidated; there is no new implication for Scott’s operating practices.
2026-09-09T17:25:58Z
The refreshed discussion adds an adjacent visibility-tool reference, not independent evidence that Geiger detects running agents or verifies their effective access. The case remains an announced inventory tool with unvalidated coverage, without a new implication for Scott’s operating practices.
2026-09-09T15:37:29Z
The refreshed discussion adds possible enterprise uses and containment advice, but no independent testing or concrete exposure findings. The GitHub echo repeats the creator’s announcement rather than corroborating detection coverage, so Geiger remains an unvalidated inventory tool, not evidence of effective-access verification.
2026-09-09T15:30:01Z
grounded: known/low — Geiger’s claimed exposure inventory adds a tool example to the distinction Scott already holds in Observability and SiloOS: inspecting access is not enforcing c
2026-09-09T15:27:50Z
case created — A first-party repository offers a concrete inspection tool, while completeness and security-control effectiveness remain unestablished.
Decision trace
- 09-28 15:29resolveFlowlight gave the case a second independent entrant, corroborating local agent-visibility tooling as an emerging category — but neither tool drew independent testing or adoption, and the category is
- 09-28 15:23attachSecond entrant (network-traffic visibility for local agents) corroborates the emerging local-agent-observability space the Geiger seed tracks.
- 09-28 15:23propose_attachSecond entrant (network-traffic visibility for local agents) corroborates the emerging local-agent-observability space the Geiger seed tracks.
- 09-10 09:21sensor_dirtyengagement_update
- 09-10 07:21sensor_dirtyengagement_update
- 09-10 04:32repriceThe refreshed discussion adds an unrelated agent-display idea, not a Geiger implementation or test. The announcement remains established, but inventory completeness and effective-access detection rema
- 09-10 04:32alert_silentThe new comment supplies no adoption report, detection result, or actionable exposure finding. It can wait for the next briefing without costing Scott an engineering or security decision.
- 09-10 04:32alert_routeThe new comment supplies no adoption report, detection result, or actionable exposure finding. It can wait for the next briefing without costing Scott an engineering or security decision.
- 09-10 04:22sensor_dirtycomment_update
- 09-10 03:25repriceThe refreshed discussion adds an adjacent visibility-tool reference, not independent evidence that Geiger detects running agents or verifies their effective access. The case remains an announced inven
- 09-10 03:25alert_silentThere is no new release, independent test, adoption report, or concrete exposure finding in this delta. The adjacent-tool recommendation and general containment discussion can wait for a briefing; the
- 09-10 03:25alert_routeThere is no new release, independent test, adoption report, or concrete exposure finding in this delta. The adjacent-tool recommendation and general containment discussion can wait for a briefing; the
- 09-10 02:21sensor_dirtycomment_update
- 09-10 01:37repriceThe refreshed discussion adds possible enterprise uses and containment advice, but no independent testing or concrete exposure findings. The GitHub echo repeats the creator’s announcement rather than
- 09-10 01:37alert_silentThe new comments do not establish adoption, inspection accuracy, or an actionable security finding for Scott. Tool discovery can wait for the next briefing; nothing in this delta changes his operating
- 09-10 01:37alert_routeThe new comments do not establish adoption, inspection accuracy, or an actionable security finding for Scott. Tool discovery can wait for the next briefing; nothing in this delta changes his operating
- 09-10 01:34alert_silentThe creator’s Show HN establishes the tool announcement, not the claimed completeness of its access inventory. The supplied evidence gives no supported-agent list, inspection method, or concrete expos
- 09-10 01:34alert_routeThe creator’s Show HN establishes the tool announcement, not the claimed completeness of its access inventory. The supplied evidence gives no supported-agent list, inspection method, or concrete expos
- 09-10 01:30groundGeiger’s claimed exposure inventory adds a tool example to the distinction Scott already holds in Observability and SiloOS: inspecting access is not enforcing containment. The supplied material establ
- 09-10 01:27createA first-party repository offers a concrete inspection tool, while completeness and security-control effectiveness remain unestablished.