Skip to main content

rafter-cli (Python)

Python CLI for Rafter — the security toolkit for developers. Full feature parity with the Node.js package.

Local security toolkit — Fast, deterministic secret scanning (21+ patterns, Betterleaks), policy enforcement with risk-tiered rules, pre-commit hooks, pretool hooks, extension auditing, custom rule authoring, and full audit logging. Works with Claude Code, Codex CLI, OpenClaw, and 5 more platforms. No API key required. No data leaves your machine.

Remote code analysis — Deep security audits that combine agentic analysis with a full SAST/SCA toolchain. The engine examines your codebase the way a professional cybersecurity auditor would — tracing data flows, reasoning about business logic, and surfacing vulnerabilities that static rules alone miss — then cross-references findings with industry-standard static analysis and dependency scanning. Structured JSON reports with documented exit codes. Your code is deleted immediately after analysis completes.

MCP server — Expose Rafter security tools to any MCP-compatible client (Cursor, Windsurf, Claude Desktop, Cline) over stdio.

Installation

pip install rafter-cli

Requires Python 3.10+.

Quick Start

Remote Code Analysis

export RAFTER_API_KEY="your-key"   # or add to .env file

rafter run                                    # scan current repo (auto-detected)
rafter scan --repo myorg/myrepo --branch main # scan specific repo
rafter get SCAN_ID                            # retrieve results
rafter get SCAN_ID --interactive              # poll until complete
rafter usage                                  # check quota

Important: The code analysis engine runs against the remote repository on GitHub, not your local files. Your code is deleted immediately after analysis completes.

Local Security

rafter agent init                # initialize config + detect environments
rafter agent init --all          # install all detected integrations
rafter agent init --local        # write config to ./.rafter (ephemeral/benchmark)
rafter agent list                # show detected integrations + status
rafter agent enable claude-code  # toggle a single platform on/off
rafter secrets .                 # scan for secrets
rafter secrets --diff HEAD~1     # scan changed files
rafter secrets --history         # scan full git history (betterleaks engine)
rafter agent exec "git commit"   # execute with risk assessment
rafter agent audit               # view security logs
rafter agent audit --verify      # verify tamper-evident hash chain
rafter agent config show         # view configuration

Skills

rafter skill list                      # installed + available skills
rafter skill install --all             # install all four skills
rafter skill review github:owner/repo  # audit a third-party skill before install
rafter skill review --installed        # audit every skill already on disk

Four skills ship with the CLI: rafter (router), rafter-code-review, rafter-secure-design, rafter-skill-review.

Pretool Hooks (Claude Code)

rafter agent init --with-claude-code  # install PreToolUse hooks
rafter hook pretool              # hook handler (reads stdin, writes decision)
rafter policy export --format claude  # export hook config

MCP Server

rafter mcp serve                 # start MCP server over stdio

Add to any MCP client config:

{
  "rafter": {
    "command": "rafter",
    "args": ["mcp", "serve"]
  }
}

Tools: scan_secrets, evaluate_command, read_audit_log, get_config Resources: rafter://config, rafter://policy

Commands

rafter run [options]

Alias: rafter scan

Trigger a new security scan for your repository.

  • -r, --repo <repo> — org/repo (default: auto-detected from git remote)
  • -b, --branch <branch> — branch (default: current branch or 'main')
  • -k, --api-key <key> — API key (or RAFTER_API_KEY env var)
  • -f, --format <format> — json or md (default: md)
  • --skip-interactive — don't wait for scan completion
  • --quiet — suppress status messages

rafter get <scan-id> [options]

Retrieve results from a scan.

  • -k, --api-key <key> — API key
  • -f, --format <format> — json or md (default: md)
  • --interactive — poll until scan completes
  • --quiet — suppress status messages

rafter usage [options]

Check API quota and usage.

  • -k, --api-key <key> — API key

rafter mcp serve [options]

Start MCP server over stdio transport.

  • --transport <type> — Transport type (default: stdio)

rafter hook pretool

PreToolUse hook handler. Reads tool input JSON from stdin, writes decision to stdout.

rafter policy export [options]

Export Rafter policy for agent platforms.

  • --format <type> — Target format: claude or codex
  • --output <path> — Write to file instead of stdout

Piping and Automation

# Filter high-severity vulnerabilities (SARIF levels: error, warning, note)
rafter get SCAN_ID --format json | jq '.vulnerabilities[] | select(.level=="error")'

# CI gate
if rafter get SCAN_ID --format json | jq -e '.vulnerabilities | length > 0'; then
    echo "Vulnerabilities found!" && exit 1
fi

Exit Codes

Code Meaning
0 Success
1 General error / secrets found
2 Scan not found
3 Quota exhausted

Documentation

Full docs at docs.rafter.so.

Metadata

Release files for rafter-cli 0.10.3

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for rafter-cli 0.10.3
File Size Uploaded
rafter_cli-0.10.3.tar.gz 253.5 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for rafter-cli 0.10.3
File Interpreter ABI Platform
rafter_cli-0.10.3-py3-none-any.whl Python 3 none any Details

Total release size: 561.6 kB

Release files / rafter_cli-0.10.3.tar.gz

Download URL rafter_cli-0.10.3.tar.gz
Size 253.5 kB
Tags Source
SHA-256 checksum
How to use checksums
4979f7fbe91e4b5f60a7f9a1cdbf4ff91777151c5c8d2cb12148d28bacadd266
BLAKE2b-256 checksum
How to use checksums
4a6ffadf5029bba530c481113fa49c163223d38164def6fd9c964b3d3a4b4a46
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.11.16

Release files / rafter_cli-0.10.3-py3-none-any.whl

Download URL rafter_cli-0.10.3-py3-none-any.whl
Size 308.2 kB
Tags Python 3
SHA-256 checksum
How to use checksums
95a474c9d9e76d6cc955c9ca254ce946bd394cfe021ad0a5cece58145161d2f2
BLAKE2b-256 checksum
How to use checksums
8b8a77dbd69d192e00176610582fdca3194bcb6e8a5e6c0ed417af937f54ea4e
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.11.16

Release history Release notifications | RSS feed

0.10.5

2 release files

0.10.4

2 release files

This release

0.10.3 This release

2 release files

0.10.2

2 release files

0.10.0

2 release files

0.9.1

2 release files

0.9.0

2 release files

0.8.10

2 release files

0.8.9

2 release files

0.8.7

2 release files

0.8.6

2 release files

0.8.5

2 release files

0.8.4

2 release files

0.8.3

2 release files

0.8.2

2 release files

0.8.1

2 release files

0.8.0

2 release files

0.7.9

2 release files

0.7.7

2 release files

0.7.6

2 release files

0.7.4

2 release files

0.7.3

2 release files

0.7.2

2 release files

0.7.1

2 release files

0.7.0

2 release files

0.6.6

2 release files

0.6.5

2 release files

0.6.4

2 release files

0.6.3

2 release files

0.6.1

2 release files

0.5.9

2 release files

0.5.5

2 release files

0.5.3

2 release files

0.5.1

2 release files

0.4.2

2 release files

0.4.1

2 release files

0.4.0

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page