CLI reference
Every secfoo command, grouped the way the CLI itself groups them. Options in brackets are optional; ... marks a repeatable flag.
Core
secfoo run
Run one or more security skills against a target using the chosen agent. Multiple --skill flags run concurrently, not one after another.
If --assessment is omitted, a case file is created automatically for you — no separate secfoo assessment create step needed for the common case. On a real terminal, you'll be prompted for a project name and application ID (skip either by passing --project-name/--app-id directly, or leave both unset for a non-interactive run, e.g. in CI). A repeat run against the same target with the same --app-id attaches to that same assessment instead of creating a new one each time, so history accumulates in one case file across rescans.
secfoo run --skill <id>... [--target] [--confluence...] [--agent] [--depth] [--timeout] [--assessment] [--project-name] [--app-id] [--exclude...]
secfoo list
List past assessment runs.
secfoo list [--project] [--limit] [--status]
secfoo show <run-uuid>
Show a single assessment run's report.
secfoo show <run-uuid> [--json]
secfoo serve
Launch the local web dashboard.
secfoo serve [--host] [--port]
secfoo agents
List known agent adapters and whether their CLI is installed on this machine. No options.
secfoo agents
assessment case files
An assessment is a case-file container — an Application ID / Security Assessment Request, a review status, and one or more attached runs or uploaded files.
secfoo assessment create
Create a new assessment case file that runs and file attachments can attach to.
secfoo assessment create --type <internal|third-party> [--project] [--name] [--status] [--app-id] [--sar] [--reviewer] [--review-date] [--notes]
secfoo assessment list
List assessment case files.
secfoo assessment list [--type] [--status] [--search]secfoo assessment show <id>
Show a single assessment's details, attachments, and attached runs.
secfoo assessment show <assessment-id>secfoo assessment update <id>
Update fields on an existing assessment.
secfoo assessment update <assessment-id> [--status] [--app-id] [--sar] [--reviewer] [--review-date] [--notes]secfoo assessment upload <id> <file>
Attach a file to an assessment. AI-BOM files (name containing "ai-bom", .json or .csv) are parsed immediately into a model/tool inventory.
secfoo assessment upload <assessment-id> ai-bom.jsonsecfoo assessment delete <id>
Delete an assessment. Attached runs are detached, not deleted; attachments are removed.
secfoo assessment delete <assessment-id>exception risk acceptance
A risk acceptance against a project, with an expiry the dashboard tracks in 30/60/90-day buckets.
secfoo exception create
Grant a risk acceptance / waiver against a project.
secfoo exception create --title --justification --granted-by --expires-at [--project] [--control] [--assessment]
secfoo exception list
List exceptions, soonest-expiring first.
secfoo exception list [--status]secfoo exception show <id>
Show a single exception's details.
secfoo exception show <exception-id>secfoo exception update <id>
Update an exception — e.g. revoke it, or extend its expiry.
secfoo exception update <exception-id> [--status] [--expires-at] [--justification]secfoo exception delete <id>
Delete an exception record.
secfoo exception delete <exception-id>miss post-build findings
A threat an earlier model missed — recorded by hand, since nothing in a report can know what it missed.
secfoo miss create
Record a threat found after build that an earlier threat model missed.
secfoo miss create --title --discovered-at [--project] [--description] [--discovered-by] [--run]
secfoo miss list
List threats found post-build, most recent first.
secfoo miss listsecfoo miss show <id>
Show a single post-build finding's details.
secfoo miss show <finding-id>secfoo miss delete <id>
Delete a post-build finding record.
secfoo miss delete <finding-id>accept threat acceptance
The human loop-back for accepting one threat from a Threat Register — a named owner and justification, tracked independently of the model's own Disposition call.
secfoo accept create
Record a human risk acceptance for one threat from a Threat Register.
secfoo accept create --threat-id --title --justification --accepted-by [--project] [--expires-at] [--run]
secfoo accept list
List recorded threat acceptances, most recent first.
secfoo accept list [--status]secfoo accept show <id>
Show a single threat acceptance's details.
secfoo accept show <acceptance-id>secfoo accept update <id>
Update a threat acceptance — e.g. revoke it, or extend its review date.
secfoo accept update <acceptance-id> [--status] [--expires-at] [--justification]secfoo accept delete <id>
Delete a threat acceptance record.
secfoo accept delete <acceptance-id>cloud enterprise portal
Connect this machine to the secfoo enterprise portal. Every future successful secfoo run is pushed automatically — nothing local changes, and secfoo serve keeps working exactly as before.
secfoo cloud login
Connect this machine to the secfoo enterprise portal.
secfoo cloud login --api-key <key> [--portal-url]
secfoo cloud logout
Disconnect this machine from the enterprise portal.
secfoo cloud logoutsecfoo cloud status
Show portal connection status and how many local runs are unsynced.
secfoo cloud statussecfoo cloud sync
Push any local runs not yet synced to the portal.
secfoo cloud syncvendor optional assets
secfoo vendor mermaid
Download Mermaid so architecture diagrams render in the dashboard. Not bundled by default — ~3.5MB, fetched once and served locally afterwards.
secfoo vendor mermaid [--url] [--force]
config ~/.secfoo/config.toml
secfoo config init
Write a starter config.toml (defaults + an MCP server example).
secfoo config init [--force]
mcp agent integration
secfoo mcp list
Show MCP servers configured in ~/.secfoo/config.toml.
secfoo mcp list
secfoo mcp sync
Register configured MCP servers persistently into gemini's or Cursor's own config. claude doesn't need this — it picks up config.toml automatically on every run. agy isn't supported yet.
secfoo mcp sync --agent <agent>