New · 0.2 Actualis 0.2 reads GitHub Copilot CLI, and --card turns your own numbers into a postable image. Release notes →
Actualis

Reference

Command reference

Everything the CLI accepts. Flags compose unless noted.

Filters

FlagEffect
--days NOnly the last N days. The fastest way to make a slow run fast.
--project SUBSTROnly projects whose name contains SUBSTR.
--agent claude|codex|copilot|allWhich agents to include. Default all.
--top NProjects to list. Default 12.
--root DIRRead transcripts from DIR instead of the default locations.

Views

FlagEffect
--bashShell audit only. Skips cost entirely.
--coachCoaching findings only.
--agentsWhich agent platforms are installed, and whether their binaries are validly signed by the expected publisher.

Explaining a number

FlagEffect
--explainList the topics you can ask about.
--explain TOPICHow a number is computed, what it assumes, and how to check it. Topics: sources, cost, cache, tickets, secrets, subagents, shell, coach, agents, refusals, vendors, suppressions, diff, verify, replay. Run actualis --explain for the list your build actually has.
--why AFxxxWhy one coach finding fired, against your actual numbers.

Output

FlagEffect
--jsonMachine-readable output. Redacted by default. See integrations.
--shareA postable summary containing nothing identifying — no project names, branches, paths, commands or identifiers.
--card [MODE]Write a shareable 1200×630 SVG and PNG: supervision (default), cost or volume. Counts, four command categories and public model names only. Never overwrites.
--style STYLE--card layout: hero (default) or terminal.
--out DIR--card: the directory to write into. Default: the current directory.
--no-redactDo not redact credentials from output. Unsafe to share or pipe to a file you forget about.
--replay IDIncident report for one credential fingerprint: the exposure window, every command inside it graded by proximity, and the in-session subset touching egress, credentials or a database. Works with --json as an exportable incident record.
--aisvsMap what was measured onto OWASP AISVS 1.0 controls — chapter C9 (agentic action) and appendix C (AI coding tools). It falsifies rather than verifies: reading outcomes cannot inspect a runtime, so a control can be shown not holding with evidence from your own transcripts, and can never be shown to pass. Anything else is reported as consistent or no evidence.
--diff OLD.jsonCompare against a saved --json report: what appeared, what went away, what changed severity. Refuses a baseline written by a different schema version.

Gating a pipeline

FlagEffect
--fail-on LEVELExit 3 if any unsuppressed finding is at or above critical, high or any. The verdict goes to stderr, so --json on stdout stays byte-identical.
--suppress IDMark a finding as a false positive on this machine. It stays counted and still appears in --json, marked suppressed — a scan with many suppressions must not look like a clean one.
--reason TEXTWhy that suppression is correct. Recorded for review.
--suppressionsList current suppressions and where they were read from.

Exit codes are fixed, because a pipeline depends on them: 0 clean, 1 could not run, 2 a usage error, 3 findings, 130 interrupted. Findings are 3 rather than 1 deliberately — a pipeline that cannot tell a credential is exposed from you mistyped a flag will eventually be told to ignore both.

Live monitoring

FlagEffect
--watchPoll for new secrets and risky commands, notifying as they appear.
--interval SECPoll interval. Default 4.
--quietWith --watch: notify on secrets only, not every flagged command.

Other

FlagEffect
--self-checkVerify the privacy claims on your own machine, by executing them. See verifying the claims.
--service KINDPrint a launchd, systemd or newsyslog unit for --watch, with the paths already resolved.
--completions SHELLPrint a completion script for bash, zsh or fish. Generated from the parser, so it never drifts from the flags this build has.
--mcpRun as an MCP server over stdio so an agent can query itself.
--versionPrint the version.