rafter-cli (Python)
Python CLI for Rafter — the security toolkit for developers. Full feature parity with the Node.js package.
Local security toolkit — Fast, deterministic secret scanning (21+ patterns, Betterleaks), policy enforcement with risk-tiered rules, pre-commit hooks, pretool hooks, extension auditing, custom rule authoring, and full audit logging. Works with Claude Code, Codex CLI, OpenClaw, and 5 more platforms. No API key required. No data leaves your machine.
Remote code analysis — Deep security audits that combine agentic analysis with a full SAST/SCA toolchain. The engine examines your codebase the way a professional cybersecurity auditor would — tracing data flows, reasoning about business logic, and surfacing vulnerabilities that static rules alone miss — then cross-references findings with industry-standard static analysis and dependency scanning. Structured JSON reports with documented exit codes. Your code is deleted immediately after analysis completes.
MCP server — Expose Rafter security tools to any MCP-compatible client (Cursor, Windsurf, Claude Desktop, Cline) over stdio.
Installation
pip install rafter-cli
Requires Python 3.10+.
Quick Start
Remote Code Analysis
export RAFTER_API_KEY="your-key" # or add to .env file
rafter run # scan current repo (auto-detected)
rafter scan --repo myorg/myrepo --branch main # scan specific repo
rafter get SCAN_ID # retrieve results
rafter get SCAN_ID --interactive # poll until complete
rafter usage # check quota
Important: The code analysis engine runs against the remote repository on GitHub, not your local files. Your code is deleted immediately after analysis completes.
Local Security
rafter agent init # initialize config + detect environments
rafter agent init --all # install all detected integrations
rafter agent init --local # write config to ./.rafter (ephemeral/benchmark)
rafter agent list # show detected integrations + status
rafter agent enable claude-code # toggle a single platform on/off
rafter secrets . # scan for secrets
rafter secrets --diff HEAD~1 # scan changed files
rafter secrets --history # scan full git history (betterleaks engine)
rafter agent exec "git commit" # execute with risk assessment
rafter agent audit # view security logs
rafter agent audit --verify # verify tamper-evident hash chain
rafter agent config show # view configuration
Skills
rafter skill list # installed + available skills
rafter skill install --all # install all four skills
rafter skill review github:owner/repo # audit a third-party skill before install
rafter skill review --installed # audit every skill already on disk
Four skills ship with the CLI: rafter (router), rafter-code-review, rafter-secure-design, rafter-skill-review.
Pretool Hooks (Claude Code)
rafter agent init --with-claude-code # install PreToolUse hooks
rafter hook pretool # hook handler (reads stdin, writes decision)
rafter policy export --format claude # export hook config
MCP Server
rafter mcp serve # start MCP server over stdio
Add to any MCP client config:
{
"rafter": {
"command": "rafter",
"args": ["mcp", "serve"]
}
}
Tools: scan_secrets, evaluate_command, read_audit_log, get_config
Resources: rafter://config, rafter://policy
Commands
rafter run [options]
Alias: rafter scan
Trigger a new security scan for your repository.
-r, --repo <repo>— org/repo (default: auto-detected from git remote)-b, --branch <branch>— branch (default: current branch or 'main')-k, --api-key <key>— API key (orRAFTER_API_KEYenv var)-f, --format <format>—jsonormd(default:md)--skip-interactive— don't wait for scan completion--quiet— suppress status messages
rafter get <scan-id> [options]
Retrieve results from a scan.
-k, --api-key <key>— API key-f, --format <format>—jsonormd(default:md)--interactive— poll until scan completes--quiet— suppress status messages
rafter usage [options]
Check API quota and usage.
-k, --api-key <key>— API key
rafter mcp serve [options]
Start MCP server over stdio transport.
--transport <type>— Transport type (default:stdio)
rafter hook pretool
PreToolUse hook handler. Reads tool input JSON from stdin, writes decision to stdout.
rafter policy export [options]
Export Rafter policy for agent platforms.
--format <type>— Target format:claudeorcodex--output <path>— Write to file instead of stdout
Piping and Automation
# Filter high-severity vulnerabilities (SARIF levels: error, warning, note)
rafter get SCAN_ID --format json | jq '.vulnerabilities[] | select(.level=="error")'
# CI gate
if rafter get SCAN_ID --format json | jq -e '.vulnerabilities | length > 0'; then
echo "Vulnerabilities found!" && exit 1
fi
Exit Codes
| Code | Meaning |
|---|---|
| 0 | Success |
| 1 | General error / secrets found |
| 2 | Scan not found |
| 3 | Quota exhausted |
Documentation
Full docs at docs.rafter.so.
Metadata
Release files for rafter-cli 0.10.3
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| rafter_cli-0.10.3.tar.gz | 253.5 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| rafter_cli-0.10.3-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 561.6 kB
Release files / rafter_cli-0.10.3.tar.gz
| Download URL | rafter_cli-0.10.3.tar.gz |
|---|---|
| Size | 253.5 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
4979f7fbe91e4b5f60a7f9a1cdbf4ff91777151c5c8d2cb12148d28bacadd266
|
|
BLAKE2b-256 checksum How to use checksums |
4a6ffadf5029bba530c481113fa49c163223d38164def6fd9c964b3d3a4b4a46
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.11.16
|
Release files / rafter_cli-0.10.3-py3-none-any.whl
| Download URL | rafter_cli-0.10.3-py3-none-any.whl |
|---|---|
| Size | 308.2 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
95a474c9d9e76d6cc955c9ca254ce946bd394cfe021ad0a5cece58145161d2f2
|
|
BLAKE2b-256 checksum How to use checksums |
8b8a77dbd69d192e00176610582fdca3194bcb6e8a5e6c0ed417af937f54ea4e
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.11.16
|