Running an assessment
An assessment is secfoo's case file: an Application ID / Security Assessment Request, a review status, and one or more attached runs or uploaded files. The Assessments, Third-Party, and Responsible AI dashboards are all built on top of it — a run with no assessment attached is readable via secfoo show, but never shows up there.
The default: let secfoo create one for you
You don't need a separate setup step for the common case. Just run a skill:
secfoo run --skill security-architecture-review --agent claude
With no --assessment flag, secfoo creates an internal assessment for the resolved project automatically, and attaches the run to it. On a real terminal you'll be prompted for two fields before the run starts:
Skip the prompt entirely by passing both flags up front, or by running non-interactively (CI, scripts) — in that case secfoo just proceeds without asking, leaving the application ID unset if you didn't pass --app-id:
secfoo run --skill security-architecture-review --agent claude \
--project-name "Checkout Service" --app-id APP-042
Repeat scans accumulate, they don't fragment
Run the same command again next week, against the same target, with the same --app-id:
secfoo run --skill security-architecture-review --agent claude \
--project-name "Checkout Service" --app-id APP-042
This attaches to the same assessment instead of creating a new one — matched on (project, application ID). That's what lets the Assessments page show one case file with a growing history of runs, rather than a new near-empty one every time you rescan. If you push runs from more than one machine (a laptop and a CI runner, say) with the same --app-id against the same target, the enterprise portal consolidates them the same way once both sync.
--app-id by mistake gets its own separate assessment, not merged into an unrelated one.Manual assessments: third-party reviews and richer metadata
Auto-creation always makes an internal assessment with just a project and (optionally) an application ID. For a vendor review with a SAR number and a named reviewer, or anything you want to set up before the first run happens, create it explicitly:
secfoo assessment create \
--project https://github.com/org/vendor-app \
--type third-party --app-id APP-042 \
--sar SAR-2026-0007 --reviewer "Jane Doe"
Then attach runs to it by id — this always skips auto-creation and the interactive prompt, whether or not a matching application ID already exists:
secfoo run --skill security-architecture-review --agent claude --assessment 1
Update its status, application ID, SAR number, reviewer, or review date at any point:
secfoo assessment update 1 --status completed --review-date 2026-09-08
For a third-party review, attach the vendor's AI-BOM (model/tool inventory) directly — recognized by filename (containing ai-bom) or extension (.json/.csv) and parsed immediately:
secfoo assessment upload 1 ai-bom.json
Finding it again later
secfoo assessment list # every case file, most recently updated first
secfoo assessment list --type third-party # filter by type
secfoo assessment show 1 # details, attachments, and every attached run
Or browse the same data in secfoo serve — the local dashboard's Assessments page is the same register the CLI commands above are reading and writing.
See the CLI reference for the full assessment subcommand list, including delete (detaches runs, doesn't delete them) and the complete flag set for create/update.