Screamless is an experimental observation tool, not a complete security or change-safety control. Do not use an empty report or a high readiness score as the sole approval for decommissioning, restart, or deployment.
Reports can contain infrastructure names, addresses, stable host identifiers (including machine IDs or hardware UUIDs), process names, and configuration evidence. Treat generated databases and HTML reports as sensitive operational data. Review them before sharing and store them with appropriate filesystem permissions.
Screamless enforces owner-only (0600) permissions for its SQLite database and
generated dashboard files on Unix systems. Keep the containing directory
restricted as well, and do not place these artifacts in a shared web root.
The packaged systemd collector runs as root to inspect host-wide process and
socket state and read protected configuration files. Its unit bounds Linux
capabilities to CAP_DAC_READ_SEARCH, CAP_NET_ADMIN, and CAP_SYS_PTRACE,
and enables systemd filesystem and device isolation. These capabilities still
permit sensitive host inspection; install and run the agent only on systems
where that access is authorized. The collector does not execute discovered
workload binaries for software-version detection.
The collector is local and polling-based. Missing privileges, failed probes, short-lived traffic, remote hosts, containers, and network namespaces can produce incomplete evidence. An incomplete probe is UNKNOWN, not evidence that no dependency exists.
To report a security issue, open a private GitHub security report or contact the repository maintainers before public disclosure: