{"_id":"@andesyte-oss/cli","_rev":"5-dca8903b1fd47e2e2f69948d65bb7d7d","name":"@andesyte-oss/cli","dist-tags":{"latest":"0.1.4"},"versions":{"0.1.0":{"name":"@andesyte-oss/cli","version":"0.1.0","keywords":["security","mcp","semgrep","osv","sast","cli"],"license":"MIT","_id":"@andesyte-oss/cli@0.1.0","maintainers":[{"name":"andesyte-npm","email":"open-source@andesyte.com"}],"homepage":"https://github.com/andesyte-oss/andesyte-cli#readme","bugs":{"url":"https://github.com/andesyte-oss/andesyte-cli/issues"},"bin":{"andesyte":"dist/index.js"},"dist":{"shasum":"80094936b56f6c919dd2027dd8692358916e0ae5","tarball":"https://registry.npmjs.org/@andesyte-oss/cli/-/cli-0.1.0.tgz","fileCount":9,"integrity":"sha512-suWJh7UNWsLt3w9gzzT0QzZiHor2Kj3CdIbIbHwbU9Dqz/NgH3CWpVoyi0mWBbwuwghM7s4Hav/L8K5T3pZC2Q==","signatures":[{"sig":"MEYCIQDJn6P9l/3gSbni505TTkvgfbG/KPpR8p7lIt2W/HlH8AIhAPBwHuEb2OGa7waAo5BBYkKCOb+Josf49TPf+52h5360","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":23273},"main":"./dist/index.js","type":"module","_from":"file:/tmp/andesyte-oss-cli-0.1.0.tgz","types":"./dist/index.d.ts","engines":{"node":">=20.11"},"mcpName":"com.andesyte/code-security","scripts":{"build":"tsc -p tsconfig.json && chmod +x dist/index.js","typecheck":"tsc -p tsconfig.json --noEmit"},"_npmUser":{"name":"andesyte-npm","email":"open-source@andesyte.com"},"_resolved":"/tmp/andesyte-oss-cli-0.1.0.tgz","_integrity":"sha512-suWJh7UNWsLt3w9gzzT0QzZiHor2Kj3CdIbIbHwbU9Dqz/NgH3CWpVoyi0mWBbwuwghM7s4Hav/L8K5T3pZC2Q==","repository":{"url":"git+https://github.com/andesyte-oss/andesyte-cli.git","type":"git","directory":"packages/cli"},"_npmVersion":"11.19.0","description":"Andesyte local security CLI and MCP server: check code and dependencies without sending source anywhere.","directories":{},"_nodeVersion":"26.8.1","dependencies":{"zod":"^3.25.76","@modelcontextprotocol/sdk":"^1.12.0","@andesyte-oss/scanner-core":"0.1.0","@andesyte-oss/security-rules":"0.1.0"},"publishConfig":{"access":"public","provenance":true},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/cli_0.1.0_1788517035018_0.6992794275497471","host":"s3://npm-registry-packages-npm-production"}},"0.1.1":{"name":"@andesyte-oss/cli","version":"0.1.1","keywords":["security","mcp","semgrep","osv","sast","cli"],"license":"MIT","_id":"@andesyte-oss/cli@0.1.1","maintainers":[{"name":"andesyte-npm","email":"open-source@andesyte.com"}],"homepage":"https://github.com/andesyte-oss/andesyte-cli#readme","bugs":{"url":"https://github.com/andesyte-oss/andesyte-cli/issues"},"bin":{"andesyte":"dist/index.js"},"dist":{"shasum":"58dc9da5ad23232f799e842898fe5e4858f0f74e","tarball":"https://registry.npmjs.org/@andesyte-oss/cli/-/cli-0.1.1.tgz","fileCount":9,"integrity":"sha512-Bk0b7+lsknIRK0yN+YnTKAWq7elJRt1/4trF7pfFbolBmdIH5X0T2PM1o7j/eIu1dxjjlIMDsxpI66/0+zTXKw==","signatures":[{"sig":"MEQCIDnqBrqEDTx1ck47ujSr4VqPSbEs5xiSdkDKVxZCPfFpAiARjErwREybEUMZNRwYYCuQtx8Lu5VKyDnhADA+C8WbQg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":23273},"main":"./dist/index.js","type":"module","_from":"file:/tmp/pack2/andesyte-oss-cli-0.1.1.tgz","types":"./dist/index.d.ts","engines":{"node":">=20.19"},"mcpName":"com.andesyte/code-security","scripts":{"build":"tsc -p tsconfig.json && chmod +x dist/index.js","typecheck":"tsc -p tsconfig.json --noEmit"},"_npmUser":{"name":"andesyte-npm","email":"open-source@andesyte.com"},"_resolved":"/tmp/pack2/andesyte-oss-cli-0.1.1.tgz","_integrity":"sha512-Bk0b7+lsknIRK0yN+YnTKAWq7elJRt1/4trF7pfFbolBmdIH5X0T2PM1o7j/eIu1dxjjlIMDsxpI66/0+zTXKw==","repository":{"url":"git+https://github.com/andesyte-oss/andesyte-cli.git","type":"git","directory":"packages/cli"},"_npmVersion":"11.19.0","description":"Andesyte local security CLI and MCP server: check code and dependencies without sending source anywhere.","directories":{},"_nodeVersion":"26.8.1","dependencies":{"zod":"^3.25.76","@modelcontextprotocol/sdk":"^1.12.0","@andesyte-oss/scanner-core":"0.1.1","@andesyte-oss/security-rules":"0.1.1"},"publishConfig":{"access":"public","provenance":true},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/cli_0.1.1_1788524211573_0.625860278160004","host":"s3://npm-registry-packages-npm-production"}},"0.1.2":{"name":"@andesyte-oss/cli","version":"0.1.2","keywords":["security","mcp","semgrep","osv","sast","cli"],"license":"MIT","_id":"@andesyte-oss/cli@0.1.2","maintainers":[{"name":"andesyte-npm","email":"open-source@andesyte.com"}],"homepage":"https://github.com/andesyte-oss/andesyte-cli#readme","bugs":{"url":"https://github.com/andesyte-oss/andesyte-cli/issues"},"bin":{"andesyte":"dist/index.js"},"dist":{"shasum":"5bec0568305adf5e2fd424977adc125730aa6bdf","tarball":"https://registry.npmjs.org/@andesyte-oss/cli/-/cli-0.1.2.tgz","fileCount":11,"integrity":"sha512-WzOt0GS1cfG2DB208hVtcbdFiylx80BuYT3fYH5Ev93e0wYWgChPBFVwUXFxQgY5R0rq3wURjRXEzYjuRWhVTg==","signatures":[{"sig":"MEYCIQCQLdtd9C0GagaFpqcA30UxTfO9WB7vTFZNdfqGEq6dZQIhANS3bcvn3Nh6YQxnCdzNu18A/gp98XxbLd1VQ9AlFH/2","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":24983},"main":"./dist/index.js","type":"module","_from":"file:/tmp/pack3/andesyte-oss-cli-0.1.2.tgz","types":"./dist/index.d.ts","engines":{"node":">=20.19"},"mcpName":"com.andesyte/code-security","scripts":{"build":"tsc -p tsconfig.json && chmod +x dist/index.js","typecheck":"tsc -p tsconfig.json --noEmit"},"_npmUser":{"name":"andesyte-npm","email":"open-source@andesyte.com"},"_resolved":"/tmp/pack3/andesyte-oss-cli-0.1.2.tgz","_integrity":"sha512-WzOt0GS1cfG2DB208hVtcbdFiylx80BuYT3fYH5Ev93e0wYWgChPBFVwUXFxQgY5R0rq3wURjRXEzYjuRWhVTg==","repository":{"url":"git+https://github.com/andesyte-oss/andesyte-cli.git","type":"git","directory":"packages/cli"},"_npmVersion":"11.19.0","description":"Andesyte local security CLI and MCP server: check code and dependencies without sending source anywhere.","directories":{},"_nodeVersion":"26.8.1","dependencies":{"zod":"^3.25.76","@modelcontextprotocol/sdk":"^1.12.0","@andesyte-oss/scanner-core":"0.1.2","@andesyte-oss/security-rules":"0.1.2"},"publishConfig":{"access":"public","provenance":true},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/cli_0.1.2_1788527851418_0.37670858147945085","host":"s3://npm-registry-packages-npm-production"}},"0.1.3":{"name":"@andesyte-oss/cli","version":"0.1.3","keywords":["security","mcp","semgrep","osv","sast","cli"],"author":{"name":"Andesyte","email":"lewis@andesyte.com"},"license":"MIT","_id":"@andesyte-oss/cli@0.1.3","maintainers":[{"name":"andesyte-npm","email":"open-source@andesyte.com"}],"homepage":"https://andesyte.com","bugs":{"email":"lewis@andesyte.com"},"bin":{"andesyte":"dist/index.js"},"dist":{"shasum":"f975315aa3d2f909fad7ec18344430a03ad9e914","tarball":"https://registry.npmjs.org/@andesyte-oss/cli/-/cli-0.1.3.tgz","fileCount":13,"integrity":"sha512-Q8tuuMl2z4Bh2dEHzNqb43NHjOCM7yKrkQwHRXp3fUdNhp0T6qPXxStQkETwg2GZT2FXJlODAZXeXVzRYhsXcA==","signatures":[{"sig":"MEUCIQDRosgUSvp2okqF5RJmnxFYN1lWkx0WBI5J/LYd0A925AIgHB/2TZHD9ZAh0SXeB0OVRpHOBeGWd3USUmn20EIZJB0=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":40922},"main":"./dist/index.js","type":"module","_from":"file:/home/runner/work/andesyte-cli/andesyte-cli/candidate/andesyte-oss-cli-0.1.3.tgz","types":"./dist/index.d.ts","engines":{"node":">=20.19"},"mcpName":"com.andesyte/code-security","scripts":{"build":"tsc -p tsconfig.json && chmod +x dist/index.js","typecheck":"tsc -p tsconfig.json --noEmit"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","approver":{"name":"andesyte-npm","email":"open-source@andesyte.com"},"trustedPublisher":{"id":"github","oidcConfigId":"oidc:c1186e03-53ff-48f7-a6fa-00e061a4d572"}},"_resolved":"/home/runner/work/andesyte-cli/andesyte-cli/candidate/andesyte-oss-cli-0.1.3.tgz","_integrity":"sha512-Q8tuuMl2z4Bh2dEHzNqb43NHjOCM7yKrkQwHRXp3fUdNhp0T6qPXxStQkETwg2GZT2FXJlODAZXeXVzRYhsXcA==","repository":{"url":"git+https://github.com/andesyte-oss/andesyte-cli.git","type":"git","directory":"packages/cli"},"_npmVersion":"11.19.1","description":"Andesyte local security CLI and MCP server: check code and dependencies without uploading source.","directories":{},"_nodeVersion":"22.23.2","dependencies":{"zod":"^3.25.76","@modelcontextprotocol/sdk":"^1.12.0","@andesyte-oss/scanner-core":"0.1.3","@andesyte-oss/security-rules":"0.1.3"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/cli_0.1.3_1789206288787_0.09993349330596857","host":"s3://npm-registry-packages-npm-production"}},"0.1.4":{"_id":"@andesyte-oss/cli@0.1.4","bin":{"andesyte":"dist/index.js"},"bugs":{"email":"lewis@andesyte.com"},"dist":{"shasum":"ba1a2ca6dcbd7e2cc0f164c60d44a5fc2d38200f","tarball":"https://registry.npmjs.org/@andesyte-oss/cli/-/cli-0.1.4.tgz","integrity":"sha512-2tdCsWqU52pASs2HEbuFYqB0O5y28Mt+QV1fhycJ//Hqnol7RvQ/+ewqMCA+Ak41xJPlY+lF3s5dBMHonvAf/w==","fileCount":20,"unpackedSize":70702,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIDA6j7eS50zKL5vTdjTVes2gf23ehM7oM6apWgjLbmQIAiBFvUnSXyir+Q473cDV2dA3DCPnDi0c67vSFgS0C8zwvg=="}]},"main":"./dist/index.js","name":"@andesyte-oss/cli","type":"module","_from":"file:/home/runner/work/andesyte-cli/andesyte-cli/candidate/andesyte-oss-cli-0.1.4.tgz","types":"./dist/index.d.ts","author":{"name":"Andesyte","email":"lewis@andesyte.com"},"engines":{"node":">=20.19"},"license":"MIT","mcpName":"com.andesyte/code-security","scripts":{"build":"tsc -p tsconfig.json && chmod +x dist/index.js && node scripts/copy-skill.mjs","typecheck":"tsc -p tsconfig.json --noEmit"},"version":"0.1.4","_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:c1186e03-53ff-48f7-a6fa-00e061a4d572"},"approver":{"name":"andesyte-npm","email":"open-source@andesyte.com"}},"homepage":"https://andesyte.com","keywords":["security","mcp","semgrep","osv","sast","cli"],"_resolved":"/home/runner/work/andesyte-cli/andesyte-cli/candidate/andesyte-oss-cli-0.1.4.tgz","_integrity":"sha512-2tdCsWqU52pASs2HEbuFYqB0O5y28Mt+QV1fhycJ//Hqnol7RvQ/+ewqMCA+Ak41xJPlY+lF3s5dBMHonvAf/w==","repository":{"url":"git+https://github.com/andesyte-oss/andesyte-cli.git","type":"git","directory":"packages/cli"},"_npmVersion":"11.19.1","description":"Andesyte local security CLI and MCP server: check code and dependencies without uploading source.","directories":{},"maintainers":[{"name":"andesyte-npm","email":"open-source@andesyte.com"}],"_nodeVersion":"22.23.2","dependencies":{"zod":"^3.25.76","@modelcontextprotocol/sdk":"^1.12.0","@andesyte-oss/scanner-core":"0.1.4","@andesyte-oss/security-rules":"0.1.4"},"publishConfig":{"access":"public"},"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/cli_0.1.4_1789590365919_0.09719541326787828"},"_hasShrinkwrap":false}},"time":{"created":"2026-09-04T10:17:14.848Z","modified":"2026-09-16T20:26:06.140Z","0.1.0":"2026-09-04T10:17:15.151Z","0.1.1":"2026-09-04T12:16:51.729Z","0.1.2":"2026-09-04T13:17:31.550Z","0.1.3":"2026-09-12T09:44:48.882Z","0.1.4":"2026-09-16T20:26:06.042Z"},"bugs":{"email":"lewis@andesyte.com"},"author":{"name":"Andesyte","email":"lewis@andesyte.com"},"license":"MIT","homepage":"https://andesyte.com","keywords":["security","mcp","semgrep","osv","sast","cli"],"repository":{"url":"git+https://github.com/andesyte-oss/andesyte-cli.git","type":"git","directory":"packages/cli"},"description":"Andesyte local security CLI and MCP server: check code and dependencies without uploading source.","maintainers":[{"name":"andesyte-npm","email":"open-source@andesyte.com"}],"readme":"# Andesyte CLI\n\nLocal AI-code checks and dependency preflight for humans, CI and coding agents.\nThis repository contains an unreleased reliability candidate. Its behaviour may\nnot match the current npm release. Publication requires separate verification.\n\n## What it checks\n\nCode checks use packaged Semgrep rules for model output reaching execution,\nshell commands or unsafe HTML; credential-shaped prompt literals. There are six active rules: four apply to Python and two each\nto JavaScript and TypeScript. This is not general SAST, prompt-injection\nprevention, authorization review or a general secret scanner.\n\nDependency checks query exact coordinates from qualified npm, pnpm and narrow\nPython requirements inputs. Unqualified formats and unresolved records remain\nvisible as coverage gaps. See [Capabilities](../../docs/CAPABILITIES.md).\n\n## Install\n\nRequires Node.js >=20.19. Semgrep is a separate prerequisite for code checks.\nNothing installs an engine or downloads rules at runtime.\n\n```sh\nnpm install -g @andesyte-oss/cli\nuv tool install semgrep\n```\n\nPin a reviewed released CLI version in CI. Qualification currently uses Semgrep\n1.176.0. A newer engine needs compatibility testing before it is recommended.\n\n## Run\n\n```sh\nandesyte check code --changed\nandesyte check dependencies --changed\nandesyte check code --staged\nandesyte check dependencies --staged\nandesyte check code --path src/agent.py --json\nandesyte check dependencies --path package-lock.json --json\nandesyte check code --changed --base origin/main\n```\n\n- `changed` selects uncommitted files, or differences from an explicit base.\n- `staged` checks Git index bytes, including staged suppression policy. Unstaged\n  replacements cannot hide vulnerable content that will be committed.\n- Code checks scan entire selected files, not only newly introduced findings.\n- Dependency `changed`/`staged` checks compare coordinates with the base. An\n  explicit dependency path checks all its coordinates unless `--base` is given.\n- `--all` discovers the whole repository, subject to caps. Recognized manifests\n  without qualified resolution make dependency coverage partial. A lockfile's\n  mere presence does not prove every manifest change was resolved.\n- No selected targets is not evidence that the repository was checked.\n\n| Exit | Meaning |\n|---|---|\n| 0 | Complete selected scope, no unsuppressed findings |\n| 1 | Complete selected scope with findings |\n| 2 | Invalid invocation |\n| 3 | Failed or incomplete check, possibly with findings |\n\nDo not narrow away coverage gaps to obtain exit 0. Read findings in context and\nverify any changes with the application's tests.\n\n## MCP\n\nThe stdio server exposes only `check_code` and `check_dependencies`. Both use the\nsame project policy as the CLI. Its root is fixed at startup; configure it\nexplicitly rather than assuming the client's working directory.\n\n### Claude Code\n\n```sh\nclaude mcp add andesyte -- npx -y @andesyte-oss/cli mcp --cwd /absolute/project\n```\n\n### Codex\n\nIn the client's `config.toml`:\n\n```toml\n[mcp_servers.andesyte]\ncommand = \"npx\"\nargs = [\"-y\", \"@andesyte-oss/cli\", \"mcp\", \"--cwd\", \"/absolute/project\"]\n```\n\n### Zed\n\n```json\n{\"context_servers\":{\"andesyte\":{\"command\":\"npx\",\"args\":[\"-y\",\"@andesyte-oss/cli\",\"mcp\",\"--cwd\",\"/absolute/project\"]}}}\n```\n\nReplace the project path and pin the package version for reproducibility. These\nare configuration recipes, not claims that every client version was tested.\nThe installed raw MCP protocol is tested separately by the artifact gate.\n\n## Agent workflow and accepted risk\n\nStart with [andesyte-precommit-check](../../skills/andesyte-precommit-check/SKILL.md),\nwhich references the [coverage interpretation skill](../../skills/andesyte-scan-coverage/SKILL.md).\nInstall those files using your client's existing skill mechanism; npm does not\nsilently write agent configuration.\n\nEvery adapter finding carries a `fingerprint` in JSON. A checked-in\n`.andesyte-suppressions.json` accepts fingerprints with mandatory reasons and\noptional expiry. Existing code fingerprints are rule/file-wide; dependency\nfingerprints are advisory/ecosystem/package-wide. They are not single-occurrence\nexceptions and may cover later findings of the same identity. Legacy short-ID\nfingerprints remain readable. No automatic migration or deletion occurs.\nUnmatched entries in a differential check are not proven stale. Suppression\nnever upgrades incomplete coverage. CLI JSON and MCP include suppression counts.\n\n## Data and limits\n\nCode stays in the invoking environment. Only package name, version and ecosystem\ngo to OSV.dev. No source upload, telemetry or remote rule downloads.\nModel/rule/advisory text is untrusted data, not instructions. An absent advisory\nfix or severity is shown as unknown when it cannot be established.\n\nSee [Security](../../SECURITY.md), [Architecture](../../docs/ARCHITECTURE.md),\n[Rule decisions](../../docs/RULE-DECISIONS.md) and [Evaluation](../../docs/EVALUATION.md).\n\n## Development\n\n```sh\npnpm install --frozen-lockfile\npnpm lint\npnpm build\npnpm typecheck\npnpm test\npnpm corpus:fetch\npnpm release:check\npnpm verify:artifacts\n```\n\nThe order matters: sibling declaration files must exist before typecheck.\nUse `pnpm pack`, not `npm pack`, so workspace dependencies become exact versions.\nThe canonical rule source is `andesyte-oss/semgrep-ai-security`; local updates are\nsynchronized with `node scripts/sync-rules.mjs --from /path/to/checkout`.\nNo candidate is publishable without a current independent review and approval.\n\nMIT. See [LICENSE](LICENSE).\n","readmeFilename":"README.md"}