CLI

A minimal, dependency-free, read-only CLI for querying Wirecheck from a terminal or CI: scan status, impact analysis, and unresolved references, without opening the web UI. Packaged as wirecheck-cli; not yet published to the npm registry, so install it from the repository for now.

Install and authenticate

install
git clone https://github.com/kev-er/wirecheck.git
node wirecheck/cli/wirecheck.mjs auth login <token>  # token from Settings > CLI access tokens
node wirecheck/cli/wirecheck.mjs auth status

The examples below use the wirecheck command for brevity; until the npm package is published, substitute node cli/wirecheck.mjs.

For CI (non-interactive), set WIRECHECK_TOKEN instead of running auth login; it is never written to disk or logged. Locally, the token is stored at ~/.wirecheck/config.json, mode 0600.

Commands

wirecheck status [--json]
wirecheck impact <name> [--operation REVOKE|DISABLE|REMOVE|REPLACE|MODIFY] [--json]
wirecheck unknowns [--json]
wirecheck compare <owner/repo> [--base <scanId>] [--head <scanId>] [--json]
wirecheck verify retirement <name> [--operation REVOKE|DISABLE|REMOVE] [--json]
wirecheck auth logout

Agent workflow

Three additional commands exist specifically for a coding agent to call before and while making a change:

wirecheck preflight <name> [--operation OP] [--json|--agent]
wirecheck context <name> [--json|--agent]
wirecheck evidence <name> [--json]

preflight is the “before you touch it” check: known impact, UNKNOWNs, the component's own evidence, affected repositories, and how fresh the underlying scan data is, deliberately never a safe_to_remove boolean. context bundles identity, owner, lifecycle, impact, evidence, and retirement status into one call instead of several. --agent is accepted as an alias for --json everywhere above; it never runs different logic, it only adds a recommended_next_queries field to the response.

Design notes

  • Every answer comes from the server's own /api/v1/* routes, the same services the web UI calls. The CLI never scans or infers relationships independently.
  • Exit codes: 0 success, 1 internal/network error, 2 auth/config error, 3 the request was understood but the answer is “no” (not found, ambiguous, invalid input).
  • compare diffs two completed, already-scanned snapshots (scan ids, defaulting to the two most recent); it is not a git-diff-aware comparison against a working tree.

Not yet implemented

wirecheck scan . (local or remote scanning from the CLI) and CI strict-exit-code mode. These are deferred until the read-only workflow above is proven with real use.

See the use cases for worked examples of these commands against real scenarios.