vakt
CLI Usage
Scan code, control review thresholds, inspect findings, and export JSON reports with vakt.
Scan a directory
vakt .
vakt patrol ./repo
vakt scan ./repo patrol is the scan command; scan is an alias. Passing a path directly to vakt selects patrol. Use vakt patrol to scan the current directory without a path.
The scanner extracts functions and methods with their surrounding doc comments, decorators, and attributes. Files without functions are scored whole. Units longer than the model’s 16,384-token context are split and reported once using the highest score of their parts.
Dependency and build directories, binary files, generated or minified code, and files larger than 2 MiB are skipped by default. Reports record skipped files.
Choose what to scan
Use repeatable doublestar globs to narrow the scan. Quote patterns so your shell does not expand them:
vakt patrol ./repo --include 'src/**' --exclude '**/*_test.go' Repository .gitignore and .vaktignore files normally influence selection. For untrusted repositories, prevent their ignore files from hiding code:
vakt patrol ./repo --no-repo-ignores --include 'src/**' Symlinks are not followed by default. --follow-symlinks enables following links within the scan root, never outside it.
Use --top-level to include code outside functions. These fragments are less like the model’s training inputs and their scores are less reliable. --max-file-bytes changes the file-size limit; --min-tokens changes the minimum unit size, which defaults to 16 tokens.
Set review and failure thresholds
vakt patrol src --threshold 0.7 --top 10
vakt patrol . --threshold 0.5 --fail-on 0.9 --thresholdcontrols which functions are flagged. Default:0.5; accepted range: greater than0through1.--toplimits the number of findings printed in the terminal. Default:25. It does not limit scanning.--fail-onsets a separate score threshold for exit status1. Without it, the failure threshold is--threshold.
Scores are review signals, not confirmed vulnerabilities or CVSS ratings. Tune thresholds against reviewed examples from your own codebase. A function-level model cannot establish behavior that depends on callers, configuration, or other services.
Output formats
The default pretty format prints a terminal report. To save machine-readable results:
vakt . --format json --out report.json With --format json or --format both, the default JSON destination is vakt-report.json. Use both for terminal output plus a JSON file:
vakt . --format both To send only the JSON report to stdout:
vakt . --format json --out - The JSON includes every scored function’s severity and all 18 family probabilities. This is JSON, not a JSONL stream. --out applies only to json and both; both requires a file destination rather than -.
Use --quiet for summary-only terminal output, --verbose for backend and scoring details, and --no-color to disable terminal colors.
Inspect saved results
vakt show 1
vakt report vakt-report.json show reads ./vakt-report.json by default, so first save a report using --format json or --format both. Use vakt show 1 --report report.json for a different file. The default pretty scan does not save JSON. report renders a saved JSON report without running inference again.
Exit codes
0: no function meets the failure threshold.1: at least one function meets the failure threshold.2: usage, I/O, or scan error.130: interrupted scan.
When piping JSON to another command in Bash, enable set -o pipefail if your script must preserve a scan failure rather than only the final command’s status.
Command help
vakt --help
vakt patrol --help
vakt show --help
vakt report --help
vakt version For model and hardware settings, see Configuration. For CI examples, see Integrations.