Skip to content

Security Signals

Matt Konda edited this page Sep 20, 2026 · 2 revisions

Security Signals

Conscience automatically detects patterns in AI session data that may indicate misuse, data exposure, or unattended automation.

Tokenmaxxing

High compute consumption with little to show for it.

Signal Threshold What it means
High token-to-file ratio >100K tokens per file touched Lots of AI compute but few files changed — could be unproductive churn, or the AI repeatedly failed and retried
Excessive tokens per turn >20K output tokens per turn Unusually long AI responses — may indicate unreviewed generation
Extremely long session >12 hours A session running for half a day or more. May indicate unattended AI automation

Sensitive File Access

AI tools reading or writing files that typically contain secrets.

Files monitored: .env, .env.local, .env.production, credentials, credentials.json, credentials.yaml, id_rsa, id_ed25519, id_ecdsa, .pem, .key, .p12, .pfx, .jks, .keystore, secret, secrets.yaml, secrets.json, aws_access, .aws, service_account, serviceAccountKey, password, passwords

Read access triggers an INFO signal; write access triggers a WARNING.

Suspicious Bash Commands

Network exfiltration, encoding/obfuscation, and credential directory access patterns.

Network exfiltration

  • curl or wget piped to another command (|)
  • netcat or nc usage
  • scp or rsync with @ (remote targets)

Encoding/obfuscation

  • base64 piped to another command
  • openssl enc (encryption operations)

Credential directory access

  • Commands accessing /.ssh/, /.aws/, or /.gnupg/

Prompt Injection

Patterns in PR descriptions that could manipulate AI tools processing the PR:

  • Instruction override patterns — text that attempts to override AI system prompts
  • Zero-width characters — invisible characters that can alter AI tool behavior
  • Conversation injection — text structured to look like AI conversation turns

These signals fire when conscience examine --pr or conscience examine --repo processes PR bodies.

Severity levels

Level Meaning
HEALTHY A positive pattern (e.g., good cache efficiency)
INFO Worth noting, not concerning
CONCERN Deserves attention and discussion
WARNING Should be investigated

Conscience never renders verdicts — signals present evidence for human judgment. A WARNING for "extremely long session" might be a legitimate overnight batch job. The human decides.

Configuring thresholds

Most security signal thresholds are configurable in conscience.yaml. See Configuration for the full list.

The solo_project: true setting suppresses contribution-concentration signals for projects with a single developer (where 100% concentration is expected).

Related

Home

The eight commands

  • setup — what's configured
  • examine — analyze a project, PR, or all projects
  • report — github · ai · energy · tokens · authorship · attention · history · automation
  • reflect — retrospective questions
  • retro — aggregate saved reflections
  • push — send a snapshot to a dashboard
  • prune — remove a launcher behind failing automation
  • du — what conscience takes up on disk; --tidy old snapshots

Command Reference

Guides

Reference

Clone this wiki locally