who-sudod Source on GitHub: Audit macOS Auth Prompts Down to the Call Chain

zats · x · 2026-09-05

Follow-up to zats's who-sudod announcement with the GitHub repo (auditable source). Components include a PAM module, terminal sudo reader, installer and tests, to detect SecurityAgent/LocalAuthentication dialogs and hidden terminal sudo requests and surface the requester's process chain. Same story as the main post — see that entry for details.

Related event: who-sudod Reveals Which Process Is Asking for Your macOS Password(3 posts)→

Original post →

More from coding & agent

coding & agent channel →