Reference
Command reference
Everything the CLI accepts. Flags compose unless noted.
Filters
| Flag | Effect |
|---|---|
--days N | Only the last N days. The fastest way to make a slow run fast. |
--project SUBSTR | Only projects whose name contains SUBSTR. |
--agent claude|codex|copilot|all | Which agents to include. Default all. |
--top N | Projects to list. Default 12. |
--root DIR | Read transcripts from DIR instead of the default locations. |
Views
| Flag | Effect |
|---|---|
--bash | Shell audit only. Skips cost entirely. |
--coach | Coaching findings only. |
--agents | Which agent platforms are installed, and whether their binaries are validly signed by the expected publisher. |
Explaining a number
| Flag | Effect |
|---|---|
--explain | List the topics you can ask about. |
--explain TOPIC | How a number is computed, what it assumes, and how to check it. Topics: sources, cost, cache, tickets, secrets, subagents, shell, coach, agents, refusals, vendors, suppressions, diff, verify, replay. Run actualis --explain for the list your build actually has. |
--why AFxxx | Why one coach finding fired, against your actual numbers. |
Output
| Flag | Effect |
|---|---|
--json | Machine-readable output. Redacted by default. See integrations. |
--share | A postable summary containing nothing identifying — no project names, branches, paths, commands or identifiers. |
--card [MODE] | Write a shareable 1200×630 SVG and PNG: supervision (default), cost or volume. Counts, four command categories and public model names only. Never overwrites. |
--style STYLE | --card layout: hero (default) or terminal. |
--out DIR | --card: the directory to write into. Default: the current directory. |
--no-redact | Do not redact credentials from output. Unsafe to share or pipe to a file you forget about. |
--replay ID | Incident report for one credential fingerprint: the exposure window, every command inside it graded by proximity, and the in-session subset touching egress, credentials or a database. Works with --json as an exportable incident record. |
--aisvs | Map what was measured onto OWASP AISVS 1.0 controls — chapter C9 (agentic action) and appendix C (AI coding tools). It falsifies rather than verifies: reading outcomes cannot inspect a runtime, so a control can be shown not holding with evidence from your own transcripts, and can never be shown to pass. Anything else is reported as consistent or no evidence. |
--diff OLD.json | Compare against a saved --json report: what appeared, what went away, what changed severity. Refuses a baseline written by a different schema version. |
Gating a pipeline
| Flag | Effect |
|---|---|
--fail-on LEVEL | Exit 3 if any unsuppressed finding is at or above critical, high or any. The verdict goes to stderr, so --json on stdout stays byte-identical. |
--suppress ID | Mark a finding as a false positive on this machine. It stays counted and still appears in --json, marked suppressed — a scan with many suppressions must not look like a clean one. |
--reason TEXT | Why that suppression is correct. Recorded for review. |
--suppressions | List current suppressions and where they were read from. |
Exit codes are fixed, because a pipeline depends on them: 0 clean,
1 could not run, 2 a usage error, 3 findings,
130 interrupted. Findings are 3 rather than 1
deliberately — a pipeline that cannot tell a credential is exposed from
you mistyped a flag will eventually be told to ignore both.
Live monitoring
| Flag | Effect |
|---|---|
--watch | Poll for new secrets and risky commands, notifying as they appear. |
--interval SEC | Poll interval. Default 4. |
--quiet | With --watch: notify on secrets only, not every flagged command. |
Other
| Flag | Effect |
|---|---|
--self-check | Verify the privacy claims on your own machine, by executing them. See verifying the claims. |
--service KIND | Print a launchd, systemd or newsyslog unit for --watch, with the paths already resolved. |
--completions SHELL | Print a completion script for bash, zsh or fish. Generated from the parser, so it never drifts from the flags this build has. |
--mcp | Run as an MCP server over stdio so an agent can query itself. |
--version | Print the version. |