vakt

CLI Usage

Scan code, control review thresholds, inspect findings, and export JSON reports with vakt.

Scan a directory

vakt .
vakt patrol ./repo
vakt scan ./repo

patrol is the scan command; scan is an alias. Passing a path directly to vakt selects patrol. Use vakt patrol to scan the current directory without a path.

The scanner extracts functions and methods with their surrounding doc comments, decorators, and attributes. Files without functions are scored whole. Units longer than the model’s 16,384-token context are split and reported once using the highest score of their parts.

Dependency and build directories, binary files, generated or minified code, and files larger than 2 MiB are skipped by default. Reports record skipped files.

Choose what to scan

Use repeatable doublestar globs to narrow the scan. Quote patterns so your shell does not expand them:

vakt patrol ./repo --include 'src/**' --exclude '**/*_test.go'

Repository .gitignore and .vaktignore files normally influence selection. For untrusted repositories, prevent their ignore files from hiding code:

vakt patrol ./repo --no-repo-ignores --include 'src/**'

Symlinks are not followed by default. --follow-symlinks enables following links within the scan root, never outside it.

Use --top-level to include code outside functions. These fragments are less like the model’s training inputs and their scores are less reliable. --max-file-bytes changes the file-size limit; --min-tokens changes the minimum unit size, which defaults to 16 tokens.

Set review and failure thresholds

vakt patrol src --threshold 0.7 --top 10
vakt patrol . --threshold 0.5 --fail-on 0.9
  • --threshold controls which functions are flagged. Default: 0.5; accepted range: greater than 0 through 1.
  • --top limits the number of findings printed in the terminal. Default: 25. It does not limit scanning.
  • --fail-on sets a separate score threshold for exit status 1. Without it, the failure threshold is --threshold.

Scores are review signals, not confirmed vulnerabilities or CVSS ratings. Tune thresholds against reviewed examples from your own codebase. A function-level model cannot establish behavior that depends on callers, configuration, or other services.

Output formats

The default pretty format prints a terminal report. To save machine-readable results:

vakt . --format json --out report.json

With --format json or --format both, the default JSON destination is vakt-report.json. Use both for terminal output plus a JSON file:

vakt . --format both

To send only the JSON report to stdout:

vakt . --format json --out -

The JSON includes every scored function’s severity and all 18 family probabilities. This is JSON, not a JSONL stream. --out applies only to json and both; both requires a file destination rather than -.

Use --quiet for summary-only terminal output, --verbose for backend and scoring details, and --no-color to disable terminal colors.

Inspect saved results

vakt show 1
vakt report vakt-report.json

show reads ./vakt-report.json by default, so first save a report using --format json or --format both. Use vakt show 1 --report report.json for a different file. The default pretty scan does not save JSON. report renders a saved JSON report without running inference again.

Exit codes

  • 0: no function meets the failure threshold.
  • 1: at least one function meets the failure threshold.
  • 2: usage, I/O, or scan error.
  • 130: interrupted scan.

When piping JSON to another command in Bash, enable set -o pipefail if your script must preserve a scan failure rather than only the final command’s status.

Command help

vakt --help
vakt patrol --help
vakt show --help
vakt report --help
vakt version

For model and hardware settings, see Configuration. For CI examples, see Integrations.

Improve team velocity with
better security and privacy.