Skip to content

Security: cyberducttape/ScreemLess

Security

SECURITY.md

Security Policy

Screamless is an experimental observation tool, not a complete security or change-safety control. Do not use an empty report or a high readiness score as the sole approval for decommissioning, restart, or deployment.

Reports can contain infrastructure names, addresses, stable host identifiers (including machine IDs or hardware UUIDs), process names, and configuration evidence. Treat generated databases and HTML reports as sensitive operational data. Review them before sharing and store them with appropriate filesystem permissions.

Screamless enforces owner-only (0600) permissions for its SQLite database and generated dashboard files on Unix systems. Keep the containing directory restricted as well, and do not place these artifacts in a shared web root.

The packaged systemd collector runs as root to inspect host-wide process and socket state and read protected configuration files. Its unit bounds Linux capabilities to CAP_DAC_READ_SEARCH, CAP_NET_ADMIN, and CAP_SYS_PTRACE, and enables systemd filesystem and device isolation. These capabilities still permit sensitive host inspection; install and run the agent only on systems where that access is authorized. The collector does not execute discovered workload binaries for software-version detection.

The collector is local and polling-based. Missing privileges, failed probes, short-lived traffic, remote hosts, containers, and network namespaces can produce incomplete evidence. An incomplete probe is UNKNOWN, not evidence that no dependency exists.

To report a security issue, open a private GitHub security report or contact the repository maintainers before public disclosure:

https://github.com/cyberducttape/ScreemLess/security

There aren't any published security advisories