CLI
A minimal, dependency-free, read-only CLI for querying Wirecheck from a terminal or CI: scan status, impact analysis, and unresolved references, without opening the web UI. Packaged as wirecheck-cli; not yet published to the npm registry, so install it from the repository for now.
Install and authenticate
git clone https://github.com/kev-er/wirecheck.git node wirecheck/cli/wirecheck.mjs auth login <token> # token from Settings > CLI access tokens node wirecheck/cli/wirecheck.mjs auth status
The examples below use the wirecheck command for brevity; until the npm package is published, substitute node cli/wirecheck.mjs.
For CI (non-interactive), set WIRECHECK_TOKEN instead of running auth login; it is never written to disk or logged. Locally, the token is stored at ~/.wirecheck/config.json, mode 0600.
Commands
wirecheck status [--json] wirecheck impact <name> [--operation REVOKE|DISABLE|REMOVE|REPLACE|MODIFY] [--json] wirecheck unknowns [--json] wirecheck compare <owner/repo> [--base <scanId>] [--head <scanId>] [--json] wirecheck verify retirement <name> [--operation REVOKE|DISABLE|REMOVE] [--json] wirecheck auth logout
Agent workflow
Three additional commands exist specifically for a coding agent to call before and while making a change:
wirecheck preflight <name> [--operation OP] [--json|--agent] wirecheck context <name> [--json|--agent] wirecheck evidence <name> [--json]
preflight is the “before you touch it” check: known impact, UNKNOWNs, the component's own evidence, affected repositories, and how fresh the underlying scan data is, deliberately never a safe_to_remove boolean. context bundles identity, owner, lifecycle, impact, evidence, and retirement status into one call instead of several. --agent is accepted as an alias for --json everywhere above; it never runs different logic, it only adds a recommended_next_queries field to the response.
Design notes
- Every answer comes from the server's own
/api/v1/*routes, the same services the web UI calls. The CLI never scans or infers relationships independently. - Exit codes:
0success,1internal/network error,2auth/config error,3the request was understood but the answer is “no” (not found, ambiguous, invalid input). comparediffs two completed, already-scanned snapshots (scan ids, defaulting to the two most recent); it is not a git-diff-aware comparison against a working tree.
Not yet implemented
wirecheck scan . (local or remote scanning from the CLI) and CI strict-exit-code mode. These are deferred until the read-only workflow above is proven with real use.
See the use cases for worked examples of these commands against real scenarios.