AI Developer Tools

Confessor

A forensic tool that reconstructs AI coding agent sessions from local logs to detect sensitive file reads and data exfiltration attempts.

Confessor logo

Confessor

Visit website

What is Confessor?

Confessor is an open-source command-line tool that audits AI coding agents by replaying their local session logs. It identifies every file the agent opened, every secret that entered its context, and flags exposure paths where sensitive data was read followed by a network call. It also scans chat exports from ChatGPT, Claude, and Gemini for secret leakage.

Confessor vs Similar AI Tools

Pricing ModelFreeFreeFreeFree
Free Credits
Key Features
  • Agent session reconstruction from Claude Code JSONL logs
  • Detection of sensitive files opened (e.g., .env, SSH keys, browser passwords)
  • Secret detection in agent context using 30+ pattern rules
  • Seven breakable boxes covering OWASP Agentic Top-10 vulnerabilities
  • Three guided simulations for cascading failures, human-agent trust, and rogue agents
  • Network-isolated Docker containers for safe execution
  • Code-to-runtime reasoning across cloud, Git, and Kubernetes
  • Action-gate enforces read-only policy on every API call
  • Sandboxed JavaScript execution for concurrent research
  • Append-only, SHA-256-addressed event history through Jaybase
  • AES-256-GCM encryption for stored node payloads
  • Unified RBAC for ledger, notes, snapshots, and audit reads
Pros
  • Zero network calls ensures complete privacy
  • No dependencies required to run
  • Covers full OWASP Agentic Top-10 in a realistic manner
  • Docker isolation prevents accidental damage
  • Read-only by construction prevents accidental writes
  • Evidence-backed verification cross-checks every finding
  • Opinionated and secure accounting CLI with immutable audit trail
  • Designed for AI agent integration with JSON output
Cons
  • Currently only supports Claude Code log format
  • Detection is rule-based, may miss novel patterns
  • Requires Docker and technical setup
  • Not for production use; only for lab environments
  • Requires an LLM API key, incurring token costs
  • Limited to read-only operations, cannot remediate
  • Pre-1.0, limited feature set
  • No native QuickBooks import (agents must normalize data)
Best For
  • Developers using Claude Code or similar AI coding agents
  • Security auditors reviewing AI agent behavior
  • Security researchers focusing on AI agent vulnerabilities
  • Developers building MCP-based applications
  • Security engineers
  • DevOps teams
  • Small teams needing secure, auditable accounting with AI agent support
  • Developers integrating automated bookkeeping workflows

How to use Confessor?

  1. 1Ensure Node.js >= 18.17 is installed.
  2. 2Run `npx confessor` to analyze local Claude Code logs (automatically finds `~/.claude/projects`).
  3. 3Optionally, provide a path to a chat export ZIP file (e.g., `npx confessor ~/Downloads/chatgpt-export.zip`) to scan chat histories.
  4. 4View the generated `confessor-report.html` in your browser.

Confessor Key Features

  • Agent session reconstruction from Claude Code JSONL logs
  • Detection of sensitive files opened (e.g., .env, SSH keys, browser passwords)
  • Secret detection in agent context using 30+ pattern rules
  • Exposure path identification (sensitive read followed by network call)
  • Zero network calls and zero runtime dependencies
  • Chat history scanning for ChatGPT, Claude, and Gemini exports
  • Structural redaction of secrets in output
  • Offline HTML report with CSP blocking external loads

Confessor Use Cases

  • Audit what an AI coding agent accessed during a task
  • Detect potential data exfiltration by AI agents
  • Compliance review of AI agent interactions with sensitive files
  • Personal privacy audit of chat history with AI services

Confessor Pricing & Free Credits

Confessor currently operates on a Free model.

This tool is completely free to use

Open Source

Free

MIT licensed, freely available on GitHub

Confessor Pros & Cons

Pros

  • Zero network calls ensures complete privacy
  • No dependencies required to run
  • Detects exposure paths that other tools miss
  • Works offline on local logs only

Cons

  • Currently only supports Claude Code log format
  • Detection is rule-based, may miss novel patterns
  • Retrospective only, not real-time monitoring

What is Confessor best for?

  • Developers using Claude Code or similar AI coding agents
  • Security auditors reviewing AI agent behavior
  • Privacy-conscious users wanting to inspect chat exports

Confessor FAQ

Top free alternatives to Confessor

Openbase logo

A voice-controlled IDE that enables developers to initiate AI coding sessions with Codex or Claude Code, approve commands, and review diffs from their phone.

Free
SureWire logo

SureWire is a specialized QA platform that stress-tests AI agents for safety, reliability, and compliance using purpose-built testing agents.

Free
Notte logo

Browser infrastructure platform for AI agents to run on the internet at speed with cloud browser sessions, agents, and serverless functions.

Free
YAFL logo

An agent-first file transfer tool that enables secure, encrypted file sharing between AI agents via MCP calls without human involvement.

Free
Manifest logo

Manifest converts any URL into a structured JSON map of what AI agents can interact with on a page—buttons, forms, inputs, and required fields.

Free
B

Personal GitHub Pages site by Basert, currently displaying default welcome content and instructions for using GitHub Pages with Jekyll.

Free
Termaxa logo

A cooperative gate for shell commands that AI agents run, providing previews, backups, policy enforcement, and audit for tools like Claude Code and Cursor.

Free
Agentcard logo

Agentcard provides agent-friendly card issuing and payment infrastructure for AI agents, enabling 5-minute setup and autonomous purchases.

Free

Best alternatives AI Tools to Confessor

mcploitable logo

A collection of deliberately vulnerable MCP servers for training in agentic security, mapped to the OWASP Top 10 for Agentic Applications.

Cynative logo

Open-source AI tool for deep infrastructure research, running frontier models across code, cloud, and runtime to deliver verified answers.

Magpie logo

Magpie is an opinionated accounting CLI for humans and AI agents, providing double-entry bookkeeping with RBAC and immutable event storage on Jaybase.

agent-manager logo

Terminal UI to manage AI coding-agent sessions (Claude Code, OpenCode, Codex, Grok Build) in tmux with live status, group tree, and diff review.

Openbase logo

A voice-controlled IDE that enables developers to initiate AI coding sessions with Codex or Claude Code, approve commands, and review diffs from their phone.

Free
OpsCat logo

Zero-config, single-binary software catalog with auto-discovery, dependency visualization, compliance scorecards, and native MCP integration for AI agents.

BrowserAct Skills logo

Browser automation CLI for AI agents to bypass anti-bot walls, hand off to humans, and run parallel tasks.

lee-ai logo

An AI-powered shopper assistant that provides a live cursor to guide website visitors, point out products, and display price calculations.