Skip to content

Commands

Find the command, arguments, and options for your task. This reference covers 61 top-level commands and their registered subcommands.

For a worked example, start with Scan Workflows, Console, or Research Workflows.

Scan and review

Assess a live target, a repository, or a package.

scan · review · audit

Work interactively

Open the console, configure your environment, and diagnose setup.

console · workbench · config · doctor

Review the evidence

Inspect findings, reproduce an issue, and validate a source fix.

findings · triage · verify · fix

Continue a run

Find a past scan, continue execution, or replay stored results.

history · resume · replay

Investigate further

Use specialized discovery, source review, and research workflows.

research · deep-review · hunt · memsafety

Connect and automate

Configure integrations and queued local work.

workflow · runs · mcp-server · orchestrate

Run commands as 0 <command>. Check your release with 0 --version and command-specific --help.

Option tables show registration defaults. — means no default is registered: a handler may resolve configuration or require an explicit value. Inverse --no-* options show the underlying positive boolean default. See Configuration for environment and runtime resolution.

  • With no arguments, Bun opens the interactive interface and Node prints installation guidance. See Console.
  • 0 -r [id] / 0 --resume [id] resume a console session; 0 -c / 0 --continue reopen the newest conversation; 0 -p / 0 --print run one console prompt. Scan sessions use 0 resume.
  • Use explicit commands in automation. Recognizable bare targets are routed automatically; ambiguous input is refused.
  • Commands register --help; root routing can prevent reaching a registration. See the triage routing limitation.
  • Scope, provider authentication, target authentication, filesystem access, and execution isolation have independent controls. See Scope & Authorization.
  • The operator-global SmolVM profile runs the entire CLI inside an online Kali guest, preserving original arguments and terminal streams. workbench and config remain host management commands. No Colima/Docker daemon is needed at runtime; failures never choose host execution implicitly.
  • Check the workflow’s outcome and verification status after a command completes. Verification exit codes vary by path.
  • Before exporting reports, invoking plugins, preparing disclosures, or running queued work, check the inputs and permissions. These actions can write externally or execute code.

Run chat with the full tool registry: recon, web, source-scan, variant-hunt, verify, and patch-gen.

0 console [options]

Full TUI use requires Bun and a usable TTY. Headless/readline approval limitations are documented in Console. Model credentials, target scope, and managed-service credentials are separate.

Guide: Read the workflow.

OptionRegistered defaultDescription
--target <url>—Engagement target the tools operate against (optional; can be named in-chat)
--scope <file>—Initial authorization scope. Non-TUI YOLO requires at least one in_scope entry; a scope file is not an OS-isolation boundary.
--finding <id>—Focus the chat on one persisted finding
--finding-intent <intent>—Finding workflow: investigate, verify, draft_fix, or impact. These instructions do not independently enforce tool permissions.
--db-path <path>—Persistent findings database (defaults to ZERO_DB_PATH or the local store)
-m, --model <id>—Model selection for the console. Saved-session precedence differs across TUI, readline, and print paths; see Console.
--role <role>—Tool set to expose: audit, review, discovery, attack, verify, or report. Defaults to audit; role selection is not authorization or OS isolation.
--mode <mode>—Autonomy mode: standard, recon, copilot, yolo. YOLO accepts absolute public-network targets without a launch target; explicit restrictions and exclusions still apply.
--yolo—Shortcut for —mode yolo. Omits per-action approval prompts; explicit restrictions and exclusions still apply.
--autonomy <mode>—Alias of —mode (standard|copilot|yolo|recon); —mode/—yolo take precedence.
--max-tool-calls <n>100Safety cap on tool-call rounds per message
--allow-scanners—Expose generic-scanner tool wrappers (sqlmap/nikto/…); default off
--resume [id]—Reopen a saved console session by id (or unique prefix); with no id, opens a session picker. Also reachable as 0 -r [id].
--continue—Reopen the most recent console session, no picker. Also reachable as 0 -c.
-p, --print [prompt]—Non-interactive: run ONE prompt through the engine, print the result, and exit (no TUI). Reads the prompt from the argument or piped stdin. Combine with —continue/—resume to query a saved session. Also reachable as 0 -p &lt;prompt&gt;.

See Console for slash commands and readline support.

See Console keyboard shortcuts.

See Console for Standard, Recon, Co-pilot, and YOLO behavior. No mode grants testing authorization.

Tool, network-scope, and directory approvals are distinct gates. Standard’s per-action prompts require a wired approval callback; Co-pilot skips that gate, and callback-free headless paths do not fail closed. Headless execution cannot answer an interactive request. Check the console mode and launcher limitations before relying on an approval boundary.

Console transcript resume differs from scan journal continuation. See Console and Scan Workflows.

The canonical settings reference is Configuration.

Open the interactive engagement interface (Bun-only).

0 tui

Aliases: watch.

Guide: Read the workflow.

Open a local dashboard for scans and findings.

0 dashboard [options]

Guide: Read the workflow.

OptionRegistered defaultDescription
--db-path <path>—Path to SQLite database
--port <port>48123Port to bind; 0 chooses a free loopback port
--host <host>127.0.0.1Loopback host to bind (127.0.0.0/8 or ::1)
--asset-dir <path>—Path to built dashboard assets
--dev-url <url>—Loopback Vite server for authenticated frontend hot reload
--backends-config <path>—Trusted backend connection registry JSON (default ~/.0/backends.json)
--engine-token-env <name>—Environment variable holding the engine bearer credential (32–4096 characters)
--engine-workspace <path>—Engine-owned authorized workspace for persistent workflow calls
--engine-scope <path>—Engine-owned scope JSON for persistent live-target workflows
--engine-target <target>—Restrict persistent workflow calls to this target
--engine-allow-apply—Admit explicitly approved patch application in persistent workflow calls
--engine-time-cap <ms>—Server workflow deadline ceiling (default 600000 ms)
--engine-cost-cap <usd>—Server workflow estimated cost ceiling (default $5)
--ready-json—Emit the bound dashboard URL as machine-readable JSON
--no-open—Do not auto-open a browser

Aliases: web.

Check local runtime prerequisites and suggest the next command

0 doctor

Guide: Read the workflow.

Inspect, export, and import the two-level console configuration

0 config

Guide: Read the workflow.

Subcommands: show · export · import.

Show each setting’s effective value and source: default, global, or project.

0 config show

Export effective configuration as JSON. Use --global for the global layer. Output goes to stdout unless a file is supplied.

0 config export [options] [file]
ArgumentRequiredDescription
fileNo
OptionRegistered defaultDescription
--global—Export only the global layer instead of the effective config

Merge a shared config into the global (default) or —project layer

0 config import [options] <file>
ArgumentRequiredDescription
fileYes
OptionRegistered defaultDescription
--project—Import into the per-project override instead of the global config
--global—Import into the global config (default)
--yes—Accept changes to security-sensitive settings (required to flip them)

Set up and inspect the whole-harness online SmolVM security workbench on Apple Silicon macOS. The local Linux guest contains 0, the security tools and the browser; Docker is not required to run the workbench.

0 workbench

Guide: Execution profile and grants.

Subcommands: run-agent · console-agent · setup · status · providers · configure · disable.

Internal, hidden entrypoint for the host-controlled CLI engine inside an admitted Linux SmolVM workbench. It exchanges framed controller messages over standard input/output; it is not an interactive command or a host-side launch shortcut. Normal CLI commands select this entrypoint automatically when the workbench profile is enabled. Direct invocation outside an admitted guest is refused.

0 workbench run-agent

Internal, hidden entrypoint for the host-controlled chat engine inside an admitted Linux SmolVM workbench. The host owns the terminal/browser UI and forwards requests, events and approvals over the framed controller transport. Use 0 console or 0 web to start a chat; do not invoke this transport endpoint manually. Direct invocation outside an admitted guest is refused.

0 workbench console-agent

Verify/provision the signed native runtime, approve a local archive by digest, and persist the operator-global SmolVM profile.

0 workbench setup [options]
OptionRegistered defaultDescription
--image <archive>—Local OCI/Docker archive to digest-pin and approve; never a mutable registry tag
--state <directory>—Private VM state directory (defaults to ~/.0/workbench)
--workspace <directory>—Explicit workspace mount; otherwise each invocation mounts its current directory
--provider <id>—Grant chatgpt-codex requests through the host provider broker; credentials stay on the host
--github—Unsupported: GitHub credential forwarding is refused
--no-github—Revoke the GitHub token grant
--cpus <count>—Guest virtual CPUs
--memory <MiB>—Guest RAM in MiB
--storage <GiB>—Guest private writable storage in GiB
--sandbox-image <reference=archive>—Approve an immutable image reference for brokered isolated container actions; repeat for multiple images

The supported provider grant is chatgpt-codex: model requests go through the host broker, and credentials stay on the host. GitHub credential forwarding is refused. The host HOME, SSH configuration and Docker socket are not mounted into the guest.

Read configuration, native runtime readiness, image approval, effective privacy, network mode, broker resource ceilings and retained guest admission. Does not download or launch a VM or reveal credential values.

0 workbench status [options]
OptionRegistered defaultDescription
--json—Print machine-readable status (no credential values)

List the exact identifiers accepted by --provider; this does not expose credentials.

0 workbench providers

Replace integration grants or operator-approved sibling image references.

0 workbench configure [options]
OptionRegistered defaultDescription
--provider <ids>—Replace provider grants with comma-separated IDs, or none
--github—Enable the explicit GitHub credential grant
--no-github—Revoke the GitHub credential grant
--current-workspace—Mount each invocation’s current directory instead of a fixed saved workspace
--sandbox-image <reference=archive>—Add or replace an operator-approved immutable sandbox image reference; repeat for multiple images
--clear-sandbox-images—Revoke all explicit sandbox image-reference grants

Explicitly switch to host-local execution. Approved image and guest state remain.

0 workbench disable

List, install, apply, export, and remove console colour themes

0 theme

Guide: Read the workflow.

Subcommands: list · install · apply · export · remove.

List built-in and installed themes, marking the active and default themes.

0 theme list

Download and validate a theme from the configured registry. Installation writes data and executes no code.

0 theme install [options] <id>
ArgumentRequiredDescription
idYes
OptionRegistered defaultDescription
--registry <url>—Theme registry index URL (https)

Set the console theme (a built-in name or an installed id)

0 theme apply [options] <id>
ArgumentRequiredDescription
idYes
OptionRegistered defaultDescription
--project—Write the choice to the per-project override instead of the global config
--global—Write the choice to the global config

Export a built-in or installed theme as a JSON manifest. Output goes to stdout unless a file is supplied.

0 theme export <id> [file]
ArgumentRequiredDescription
idYes
fileNo

Delete an installed theme (built-ins cannot be removed)

0 theme remove <id>
ArgumentRequiredDescription
idYes

Author and validate community extensions for the Hackstore — the extension store for 0. init scaffolds a new extension; validate checks a manifest against the same contract the CLI enforces on install. Publish by opening a pull request against the community index at github.com/0sec-labs/hackstore.

0 hackstore

Guide: Read the workflow.

Aliases: hack, store.

Subcommands: init · validate · prepare-submission.

Scaffold a new Hackstore extension (manifest, example tool, README)

0 hackstore init [options] <name>
ArgumentRequiredDescription
nameYes
OptionRegistered defaultDescription
--dir <path>—Parent directory to create the extension in (default: cwd)
--force—Write into a non-empty target directory

Validate an extension manifest against the Hackstore schema

0 hackstore validate [options] <path>
ArgumentRequiredDescription
pathYes
OptionRegistered defaultDescription
--json—Emit machine-readable JSON

Create a reviewed source bundle for a Hackstore pull request. This does not publish or submit the extension.

0 hackstore prepare-submission [options] <path>
ArgumentRequiredDescription
pathYes
OptionRegistered defaultDescription
--out <directory>—New output directory (default: <id>-submission)

Fetch and install the latest release binary for 0 (re-runs install.sh).

0 upgrade [options]

Guide: Read the workflow.

OptionRegistered defaultDescription
--version <tag>—Pin a specific release tag (e.g. v0.10.0)
--install-dir <path>—Override the install directory (default: ~/.0/bin)
--scan-dependencies—Scan the current project before upgrading
--fix-dependencies—Refuse upgrade when vulnerabilities are present; use 0 deps fix --yes to remediate

Aliases: update.

Scan and remediate project dependencies for known vulnerabilities.

0 deps

Subcommands: scan · fix.

Run the native advisory database scanner for the current project.

0 deps scan [options]
OptionRegistered defaultDescription
--cwd <path>—Project directory
--ecosystem <name>—Override detected ecosystem: npm, pnpm, cargo, pypi
--json—Emit machine-readable output

Apply the ecosystem package manager’s supported vulnerability fixes.

0 deps fix [options]
OptionRegistered defaultDescription
--cwd <path>—Project directory
--ecosystem <name>—Override detected ecosystem: npm, pnpm, cargo, pypi
--yes—Apply changes; without this flag print the command only

Run autonomous pentest against a URL, web app, or MCP server

0 scan [options]

Live HTTP/HTTPS/MCP targets require an engagement policy, including when --require-scope is omitted. See Scope & Authorization. --dry-run previews PR emission; the scan still executes. Use --race for benchmark/CTF workflows. An explicit rate can override the conservative profile’s fallback rate.

Guide: Read the workflow.

OptionRegistered defaultDescription
--target <target> required—Target URL or mcp:// endpoint
--depth <depth>defaultScan depth: quick, default, deep
--format <format>terminalOutput format: terminal, json, md, html, sarif, pdf
--runtime <runtime>autoModel provider: auto, api, claude, codex, gemini
--mode <mode>—Scan mode: probe, deep, mcp, web, http_audit (http_audit reads ZERO_TARGET_* env config)
--timeout <ms>30000Request timeout in milliseconds
--db-path <path>—Path to SQLite database
--api-key <key>—API key for LLM provider
-m, --model <model>—LLM model to use
--repo <path>—Source code path for white-box scanning
--auth <json>—Auth credentials: JSON string or path (bearer, cookie, basic, header)
--scope <path>—Path to a JSON scope policy (enable with 0 plugin enable scope)
--allow-scannersfalseExpose generic scanner tools in scope-enforced scans
--require-scopefalseSet ZERO_REQUIRE_SCOPE for scope-aware execution paths. Ordinary live-target scan already refuses missing scope, independently of this flag.
--attribution-header <name=value>—Header to attach to in-scope requests (repeatable); never sent out-of-scope
--attribution-ua <token>—Engagement token to embed in the User-Agent on in-scope traffic
--api-spec <path>—Path to an OpenAPI/Swagger spec for endpoint knowledge
--export <target>—Export findings to issue tracker (e.g. github:owner/repo)
--racefalseBest-of-N strategy racing (benchmark/CTF only)
--egatsfalseEvidence-gated attack tree search
--cost-ceiling <usd>—Soft estimated-model-cost ceiling; partial findings are retained when enforcement trips. In-flight work may overshoot. Overrides ZERO_COST_CEILING_USD.
--rate-limit <spec>—Per-host requests/sec cap, e.g. ‘5’ or ‘host=5,*=3’ (default 5)
--engagement-profile <name>—Engagement posture: standard (default) or conservative (quieter)
--no-waf-evasion—Disable adaptive WAF-evasion retries
--tuifalseOpen the terminal UI after the scan completes
--features <list>—Comma-separated feature flags to enable, e.g. ‘fp-moat’
--no-decoy-detection—Disable the anti-honeypot flag validator
--dispatch <mode>autoTool-call protocol: json, xml, auto (legacy loop only)
--emit <target>—Emit mode: ‘pr’ opens a GitHub PR per reproduced finding
--base <branch>—Base branch for --emit pr (default: main)
--dry-runfalseFor —emit pr only: print proposed git/gh emission commands. The scan itself still executes.
--emit-out-dir <path>—Directory for --emit pr rollup files (default: system temp)
--resume <run-id>—Resume a previous run from its on-disk journal
--branch-from <entry-index>—Branch the journal at an entry index before resuming (with —resume)
--verbosefalseShow detailed output
--replayfalseReplay the last scan’s results

scan --auth accepts inline JSON or a JSON file. Use a restricted file for real secrets. Choose one shape:

TypeJSON value
Bearer{"type":"bearer","token":"test-token"}
Cookie{"type":"cookie","value":"session=test-session"}
Basic{"type":"basic","username":"test-user","password":"test-password"}
Header{"type":"header","name":"X-API-Key","value":"test-key"}

Import endpoint knowledge. Target authorization is still required. See Recipes.

Use strategy racing for benchmark and CTF targets. Keep it off for normal live-target audits.

Section titled “--egats: Evidence-Gated Attack Tree Search”

Enable hypothesis-tree search. Findings still require verification. See Finding Triage.

See Budget Management for spend versus turn limits and partial outcomes.

Creates external GitHub issues. Review destination, permissions, and sensitive evidence first; see Integrations.

Audit a package for security vulnerabilities

0 audit [options] <package>

Guide: Read the workflow.

ArgumentRequiredDescription
packageYespackage name (e.g. lodash, express, requests)
OptionRegistered defaultDescription
--ecosystem <ecosystem>npmPackage ecosystem: npm, pypi, cargo, oci
--package-version <version>—Specific package version to audit (default: latest)
--pkg-version <version>—Alias for —package-version
--ver <version>—Alias for —package-version
--depth <depth>defaultAudit depth: quick, default, deep
--format <format>terminalOutput format: terminal, json, md, html, sarif, pdf
--runtime <runtime>autoRuntime: auto, claude, codex, gemini, api
--db-path <path>—Path to SQLite database
--api-key <key>—API key for LLM provider
-m, --model <model>—LLM model to use
--cost-ceiling <usd>—Soft estimated-model-cost ceiling; partial findings are retained when enforcement trips. In-flight work may overshoot. Overrides ZERO_COST_CEILING_USD.
--tuifalseOpen the local terminal UI after the audit completes
--resume <run-id>—Resume a previous run from its journal on disk (0#374)
--branch-from <entry-index>—Branch the journal at the given entry index before resuming (requires —resume).
--verbosefalseShow detailed output
--timeout <ms>600000AI agent timeout in milliseconds

Deep source code security review of a repository

0 review [options] <repo>

Static and AI review produce leads that need runtime verification. --changed-only controls static leads and prioritization; model filesystem access is unchanged. review --auth is unsupported.

Guide: Read the workflow.

ArgumentRequiredDescription
repoYesLocal path or git URL to review
OptionRegistered defaultDescription
--depth <depth>defaultReview depth: quick, default, deep
--format <format>terminalOutput format: terminal, json, md, html, sarif, pdf
--runtime <runtime>autoRuntime: auto, claude, codex, gemini, api, ollama
--db-path <path>—Path to SQLite database
--api-key <key>—API key for LLM provider
-m, --model <model>—LLM model to use
--cost-ceiling <usd>—Soft estimated-model-cost ceiling; partial findings are retained when enforcement trips. In-flight work may overshoot. Overrides ZERO_COST_CEILING_USD.
--tuifalseOpen the local terminal UI after the review completes
--diff-base <ref>—Git base ref to review against (for diff-aware review)
--changed-onlyfalseRestrict static scanner leads + prioritization to changed files
--profile <profile>defaultReview profile: default (web/JS/TS/Python), c-library (C/C++ memory safety, tier-1/2/3 harness), linux-kernel (kernel-aware static review), cardano-onchain (Aiken/Plutus validator logic), solana-onchain (Anchor/native Rust account-model authorization), evm-onchain (Solidity/Foundry/Hardhat DeFi/bridge — reentrancy, oracle manipulation, cross-chain replay), cairo-onchain (Cairo/Starknet DeFi — caller-auth gaps, share-rounding, L1↔L2 messages), move-onchain (Sui/Aptos Move — object/capability binding, shared-math overflow, reward-index accounting), cardano-haskell (first-party Cardano Haskell node stack — ledger/plutus/ouroboros/cardano-base), xnu-kernel (Apple XNU macOS/iOS source review), or xnu-re (decompiled Apple kext pseudo-C)
--target <target>—Alias for —profile; accepts the supported review profiles, with app normalized to default.
--ecosystem <ecosystem>—Review the SOURCE of a published package instead of a repo: npm, pypi, cargo, or oci. When set, <repo> is the package NAME — 0 installs it and reviews its extracted source. Omit for a local path or git URL.
--package-version <version>—Pin the package version to review (only with —ecosystem). Defaults to latest.
--seed-findings <path>—Path to ND-JSON leads from an external producer. ”-” reads stdin. Schema: gemmaforge.leads/v1. Tracked: 0#368.
--seed-onlyfalseSkip static scanner prioritisation and rely solely on —seed-findings. Only meaningful when —seed-findings is set.
--emit <target>—Emit target. Default unset → existing terminal/json/etc. pr → emit each reproduced finding as a GitHub PR with repro + suggested patch (0#377). Unverified findings roll up into hypotheses.md.
--base <branch>—Base branch for --emit pr (default: main)
--dry-runfalseFor —emit pr only: print proposed git/gh emission commands. The source review itself still executes.
--emit-out-dir <path>—Directory for --emit pr rollup files (default: system temp)
--harness-tier <tier>1C/C++ harness tier to construct: 1 (single-function libFuzzer, default), 2 (multi-component linker), 3 (Tier-2 build + QEMU sanitizer validation).
--harness-function <name>—Tier-2 only: name of the suspect function the harness should drive. Defaults to a heuristic placeholder.
--harness-header <path>—Tier-2 only: header to #include in the emitted harness. Defaults to the function name with a .h suffix.
--harness-build-system <system>autoTier-2 only: build system to grep-parse for object subset (autotools, cmake, meson, auto).
--harness-sanitizers <list>—Tier-2 only: comma-separated sanitizers to enable (asan, ubsan, msan). Default: asan,ubsan.
--harness-out <dir>—Tier-2 only: output directory for the emitted harness + linker fragment. Defaults to <repo>/.0-out/tier2.
--harness-qemu-kernel <path>—Tier-3 only: pre-built kernel image. Defaults to ZERO_KERNEL_QEMU_KERNEL.
--harness-qemu-disk <path>—Tier-3 only: pre-built rootfs image. Defaults to ZERO_KERNEL_QEMU_DISK.
--harness-wall-clock-ms <ms>—Tier-3 only: wall-clock budget in milliseconds for the full QEMU validation. Default 300000 (5m).
--subsystem <path>—Restrict the review to a specific subsystem directory (e.g. crypto/, net/tcp/). Only meaningful with —profile linux-kernel.
--hypothesis <text>—Operator hypothesis to seed the agent with a specific research direction. Modeled after Xint Code’s operator prompt.
--conversation <text>—PR/MR discussion thread to review against (untrusted). The latest message drives this run.
--prior-findings <path>—JSON array of prior findings. Fresh review treats it as untrusted context and investigates variants without repeating the originals.
--fix-commit <sha>—Analyze a security-fix commit and hunt for structurally similar unpatched code paths (variant hunting). Requires a local git repo. Resolves the commit to its full SHA and first-parent preimage. When used alone, feeds candidates as SeedFindings into the review pipeline. Combine with —variants-only to emit candidates as JSON without model/network calls.
--variants-onlyfalseEmit full variant-hunt result as JSON (candidates, language coverage, errors) and exit. Requires —fix-commit. No model, cloud, or network calls are made.
--npm-dynamicfalseAlso run the npm dynamic-discovery detector sweep (SSPP fuzz / validation read-stability / SSRF parser-diff) over the package in a disposable sandbox. Only effective with —ecosystem npm. Confirmed leads flow into the same verify → disclosure path.
--resume <run-id>—Resume a previous run from its journal on disk (0#374)
--branch-from <entry-index>—Branch the journal at the given entry index before resuming (requires —resume).
--verbosefalseShow detailed output
--timeout <ms>600000AI agent timeout in milliseconds

Profiles select review behavior and prerequisites. See Scan Workflows and Research Workflows. Static kernel review leaves VM execution and crash reproduction to a separate step.

Investigate a repository, reproduce findings, generate repair candidates, run regression tests, and independently verify repairs before delivery.

0 secure [options] <repo>

The repository can be a local Git checkout or an HTTPS Git URL. Execution is host-local in managed checkouts under the state directory, not in a newly provisioned sandbox. Repository code, the operator-approved setup command, and the required regression command run with the worker’s available permissions. Use an appropriately isolated worker for untrusted repositories; a disposable checkout is not a security boundary.

For example, after reviewing the repository’s test command:

Terminal window
0 secure ./my-repo --test-command "npm test" --state-dir "$HOME/.0/secure/my-repo"

The regression command must pass before and after a repair. Findings that cannot be reproduced or verified must not be treated as fixed. Inspect repairs, repairedFindingIds, blockedFindingIds, and errors as well as status: the current implementation can return completed while other findings remain blocked or errors are retained. Completion is not proof that every finding was fixed or that the repository contains no vulnerabilities.

Reported costUsd is not a reliable whole-workflow total: investigation usage is initially added, but a later repair-ledger update replaces it. The repair ceiling also checks that ledger separately from investigation spend. Use provider-side limits and inspect usage independently; do not treat --cost-ceiling as a guaranteed end-to-end cap.

--resume requires an explicit --state-dir. It checks configuration identity and repository revision, can retry blocked or failed work, and does not resume cancelled runs. It does not blindly replay publication.

Publication is opt-in. --publish uses authorized repository credentials and gh to open PRs for verified patches only; it never merges or deploys them. Review retained evidence and proposed patches before enabling publication.

--timeout bounds the whole workflow. The investigation phase currently relies on that deadline rather than immediate operator cancellation; the repair phase supports cancellation. The CLI accepts api or auto runtime selection and JSON output only.

Exit codes: 0 completed, 2 blocked, 3 failed, 130 cancelled.

Guide: Scope & Authorization.

ArgumentRequiredDescription
repoYesLocal Git repository or HTTPS Git URL; execution occurs in the current worker, not a newly provisioned sandbox
OptionRegistered defaultDescription
--test-command <command> required—Operator-approved regression command; must pass before and after repair
--setup-command <command>—Operator-approved setup/build command run in each disposable checkout
--state-dir <path>—Persistent run directory; defaults to a stable per-repository path so learnings accumulate
--runtime <runtime>apiNative repair runtime: auto or api
-m, --model <model>—Model for investigation and repair; inherits configured provider when omitted
--timeout <ms>3600000Whole workflow deadline in milliseconds
--cost-ceiling <usd>—Requested model-cost limit. Current accounting checks the repair ledger separately from investigation usage; this is not a guaranteed whole-workflow spend cap.
--max-findings <n>10Maximum findings selected for repair. Inspect blockedFindingIds separately from the overall run status.
--max-attempts <n>3Maximum repair candidates per finding
--max-turns <n>30Maximum model turns per repair phase
--resumefalseResume the compatible persisted run for this repository; never blindly replays publication
--publishfalsePublish verified patches as PRs using authorized repository credentials; never merge or deploy
--rules <text>—Plain-English team repair standards (e.g. “minimal diffs, no new dependencies”)
--format <format>jsonOutput format: json

Run a seedless DEPTH review: enumerate source files, apply profile-specific finder lenses, and check candidates with a multi-lens verification quorum. Results are leads requiring further verification. Exit 0: sweep completed, with or without leads. Exit 2: skipped because no files qualified or the review cap was exceeded. Exit 3: bad flags, unreadable target, or all finders failed.

0 deep-review [options] <target>

Guide: Read the workflow.

ArgumentRequiredDescription
targetYesSource tree to review (a local path or a git URL)
OptionRegistered defaultDescription
--profile <p>—Lens profile: evm-onchain | solana-onchain | cardano-onchain | cairo-onchain | move-onchain (else a generic default lens set)
--subsystem <path>—Narrow the review scope to a subdirectory (respects the 5000-file review cap)
--evolution-config <path>—Use the active source finder with private local execution receipts
--models <a,b>—Comma-separated finder models for diversity (default: single provider model, or $ZERO_DEEP_REVIEW_MODELS)
--attempts <N>—Finder attempts per candidate×lens×model, best-of-N (default 1, or $ZERO_DEEP_REVIEW_ATTEMPTS)
--concurrency <N>—Max finders in flight (default 8)
--cost-ceiling <usd>—Shared estimated-model-cost ceiling for planner and finder work. Checks can stop further work after recorded usage reaches the threshold; in-flight calls can overshoot.
--max-candidates <N>—Cap candidate files hunted, largest-first (default 8, or $ZERO_DEEP_REVIEW_MAX_CANDIDATES)
--threat-model—Enable pre-selection threat-model planner pass (trust-boundary lanes); default OFF
--quorum <N>—Multi-lens verify quorum (default: majority of the verify-lens count)
--format <fmt>jsonOutput format (json)
--output <path>—Write the result JSON to this path instead of stdout
--runtime <mode>—Engine runtime (default api)
--timeout <ms>600000Cloud agent timeout budget in milliseconds

Generate, source-retest, and optionally apply a scoped fix for one reproduced source finding

0 fix [options] <repo>

Guide: Read the workflow.

ArgumentRequiredDescription
repoYesClean local Git worktree containing the affected source file
OptionRegistered defaultDescription
--finding <path>—Path to an external finding JSON with verificationSpec
--finding-id <id>—Persisted finding ID (full ID or unique prefix)
--db-path <path>—Database containing —finding-id
--verification-result <path>—Optional verification_result JSON from 0 verify; required when the finding does not already carry one
--test-command <command> required—Explicit regression command to run in the isolated candidate worktree
--runtime <runtime>autoFix runtime: auto or api
-m, --model <model>—Model identifier for the selected runtime
--api-key <key>—API key for the selected runtime
--timeout <ms>600000Per-model-call timeout in milliseconds
--test-timeout <ms>300000Regression-command timeout in milliseconds
--max-attempts <n>3Maximum candidate patches; capped at 3
--applyfalseApply only a patch that passed isolated source recheck and regression command
--output <path>—Write the validated apply_patch DSL to this path

Show past scan history from run-local SQLite databases

0 history [options]

Guide: Read the workflow.

OptionRegistered defaultDescription
--db-path <path>—Path to one SQLite database
--limit <n>10Number of scans to show

Resume a previous scan from persisted state

0 resume [options] <scanId>

Resume requires the original persisted state, supported target routing, and valid authorization and credentials. See Scan Workflows before resuming a live target.

Guide: Read the workflow.

ArgumentRequiredDescription
scanIdYesScan ID to resume
OptionRegistered defaultDescription
--db-path <path>—Path to SQLite database
--format <format>—Output format override: terminal, json, md, html, sarif, pdf
--runtime <runtime>—Runtime override: auto, claude, codex, gemini, api
--timeout <ms>—AI agent timeout override in milliseconds
--api-key <key>—API key for LLM provider
-m, --model <model>—LLM model to use
--branch-from <entry-index>—Branch the journal at the given entry index before resuming. Copies entries 0..N into a new run and resumes from there.

Replay the last scan’s attack chain as an animated terminal sequence

0 replay [options]

Guide: Read the workflow.

OptionRegistered defaultDescription
--db-path <path>—Path to SQLite database
--scan <scanId>—Replay a specific scan by ID (default: last scan)

Browse and manage persisted findings

0 findings [options]

Human triage (new, accepted, suppressed) and verification have independent states. Accepting a finding records the operator’s decision; reproduction and fix verification remain separate steps.

Guide: Read the workflow.

Subcommands: list · show · accept · suppress · reopen.

OptionRegistered defaultDescription
--db-path <path>—Path to SQLite database
--scan <scanId>—Filter by scan ID
--severity <severity>—Filter by severity: critical, high, medium, low, info
--category <category>—Filter by attack category
--status <status>—Filter by status: discovered, verified, confirmed, scored, reported, fixed, false-positive
--triage <triage>—Filter by triage: new, accepted, suppressed
--limit <n>50Max findings/groups to show
--allfalseShow raw finding rows instead of grouped fingerprints

List findings from the database

0 findings list [options]
OptionRegistered defaultDescription
--db-path <path>—Path to SQLite database
--scan <scanId>—Filter by scan ID
--severity <severity>—Filter by severity: critical, high, medium, low, info
--category <category>—Filter by attack category
--status <status>—Filter by status: discovered, verified, confirmed, scored, reported, fixed, false-positive
--triage <triage>—Filter by triage: new, accepted, suppressed
--limit <n>—Max findings/groups to show

Show detailed information about a finding

0 findings show [options] <id>
ArgumentRequiredDescription
idYesFinding ID (full or prefix)
OptionRegistered defaultDescription
--db-path <path>—Path to SQLite database

Mark a finding family as accepted

0 findings accept [options] <id>
ArgumentRequiredDescription
idYesFinding ID (full or prefix)
OptionRegistered defaultDescription
--db-path <path>—Path to SQLite database
--note <text>—Optional triage note

Suppress a finding family across duplicate occurrences

0 findings suppress [options] <id>
ArgumentRequiredDescription
idYesFinding ID (full or prefix)
OptionRegistered defaultDescription
--db-path <path>—Path to SQLite database
--note <text>—Suppression reason

Reset a finding family back to new

0 findings reopen [options] <id>
ArgumentRequiredDescription
idYesFinding ID (full or prefix)
OptionRegistered defaultDescription
--db-path <path>—Path to SQLite database
--note <text>—Optional triage note

Triage findings and manage learned FP memories

0 triage

Guide: Read the workflow.

Subcommands: memory · mark-fp.

Manage Semgrep-style triage memories

0 triage memory

Subcommands: add · list · remove.

Create a memory from an existing finding

0 triage memory add [options]
OptionRegistered defaultDescription
--finding <id> required—Finding ID (full or prefix) to derive the memory from
--reason <text> required—Why this finding is a false positive
--scope <scope>targetMemory scope: global | target | package
--scope-value <value>—Scope identifier (target URL or package name)
--db-path <path>—Path to SQLite database

List all triage memories

0 triage memory list [options]
OptionRegistered defaultDescription
--scope <scope>—Filter by scope: global | target | package
--category <category>—Filter by vulnerability category
--db-path <path>—Path to SQLite database

Delete a memory by id

0 triage memory remove [options] <id>
ArgumentRequiredDescription
idYesMemory ID
OptionRegistered defaultDescription
--db-path <path>—Path to SQLite database

Mark a finding as false positive and auto-create a memory

0 triage mark-fp [options] <finding-id>
ArgumentRequiredDescription
finding-idYesFinding ID (full or prefix)
OptionRegistered defaultDescription
--reason <text> required—Why this finding is a false positive
--scope <scope>targetMemory scope: global | target | package
--scope-value <value>—Scope identifier (target URL or package name)
--db-path <path>—Path to SQLite database

Export an immutable scan timeline with UTC ISO-8601 timestamps, action summaries, and MITRE ATT&CK/ATLAS tags for SOC cross-referencing.

0 timeline [options] <scanId>

The scan ID is resolved only in the selected database. For run-local storage, pass --db-path ~/.0/runs/<scan-id>/state.db, adjusted for your state directory.

Guide: Read the workflow.

ArgumentRequiredDescription
scanIdYesScan id to export (see 0 history)
OptionRegistered defaultDescription
--format <format>markdownOutput format: json, csv, markdown
--since <iso>—Only include events at or after this timestamp (ISO-8601, e.g. 2026-07-28T09:00:00Z)
--until <iso>—Only include events at or before this timestamp (ISO-8601)
--attack-only—Only include events that map to a MITRE ATT&CK or ATLAS technique, dropping pipeline lifecycle noise
--db-path <path>—Path to SQLite database

Deterministically replay a finding’s PoC steps and emit a verification_result JSON.

0 verify [options] [finding]

Fixture, structured-step, kernel, and bundle verification use different status schemas and exit codes. Read the verdict for the chosen path in Verification Results and Scan Workflows.

Guide: Read the workflow.

ArgumentRequiredDescription
findingNoPath to a finding.json (0#193 deterministic-replay path). Equivalent to —finding when —runner is supplied.
OptionRegistered defaultDescription
--runner <kind>—Deterministic replay runner: local|smolvm|docker|qemu (default smolvm in an admitted workbench, local outside).
--docker-network <name>—Docker network for —runner docker. Defaults to none; bridge/custom networks require —scope and only permit HTTP steps.
--scope <path>—Engagement scope JSON required for HTTP replay; SmolVM also refuses private/loopback destinations.
--qemu-binary <path>—QEMU emulator for —runner qemu.
--qemu-kernel <path>—Guest kernel image for —runner qemu.
--qemu-busybox <path>—Static BusyBox binary used to build the offline QEMU guest.
--out <dir>—0#193 run directory (artifacts go under <out>/artifacts/). Defaults to a fresh tmpdir.
--finding <path>—Path to a finding.json.
--bundle <path>—Path to a reproduction bundle directory; requires —runner local|smolvm|docker outside an admitted workbench. Replays the bundle’s vulnerable and patched snapshots through the configured runner and emits an aggregate ReproductionBundleResult.
--create-bundle <plan.json>—Path to a BundlePlan JSON. Creates a reproduction bundle without executing any PoC steps. Requires —out <bundle-dir>.
--target <path>—Path to a target.json (PocExecutionTarget: baseUrl, env, cwd, timeoutMs, personas).
--fixture <name>—Run a built-in deterministic replay fixture. Supported: cli-path-traversal.
--fixture-command <json>—JSON argv array for the CLI under test. Supports {{apiUrl}}, {{exportDir}}, and {{fixtureMode}} placeholders.
--fixture-mode <mode>—Fixture behavior for —fixture: vulnerable or patched.
--retain-artifactsfalseKeep the fixture sandbox, harness metadata, and stdout/stderr logs.
--artifact-dir <path>—Use this directory as the fixture sandbox root.
--format <fmt>jsonOutput format. Only ‘json’ is supported.
--output <path>—Write the verification_result JSON to this path instead of stdout.
--kernel-finding <path>—Path to a kernel-review finding.json. Runs the Tier 2 agent loop to produce a reproducer and promote the finding via the kernel oracle. Requires ZERO_KERNEL_VERIFY=1.
--kernel-tree <path>—Linux source tree used by —kernel-finding for Tier 1 kernel build.
--kernel-config <profile>kasanKernel build config profile for —kernel-finding (only ‘kasan’ supported).
--attempts <N>—Max reproducer attempts for —kernel-finding (default 5).
--wall-clock <duration>—Wall-clock budget for —kernel-finding (e.g. 30m, 90s; default 30m).

Assemble GHSA-ready advisory drafts from persisted findings

0 disclose [options] [findingId]

Guide: Read the workflow.

ArgumentRequiredDescription
findingIdNoFinding ID (or prefix). Omit to batch every finding at or above —severity-floor.

Subcommands: evidence-pack · track · review.

OptionRegistered defaultDescription
--db-path <path>—Path to SQLite database
--scan <scanId>—Restrict to findings from this scan
--output-dir <path>—Directory to write advisories into (default ~/0/disclosures/scan-<id>)
--severity-floor <severity>mediumIn batch mode, only draft findings at or above this severity
--no-screenshots—Skip terminal-screenshot rendering even when freeze is available
--repo <path>—Local git checkout of the target repo to re-verify findings against
--ref <tag>—Git ref (tag/sha/branch) to check out before verifying — defaults to the repo’s current HEAD
--drop-fixedfalseMove findings whose status is ‘fixed’ or ‘file-removed’ into _dropped/ with a reason file instead of drafting an advisory for them
--reverifyfalseBehaviourally re-verify each finding’s PoC step graph against a live target. Requires —target-url.
--target-url <url>—Base URL the behavioural re-verify runtime dispatches http actions against (e.g. http://localhost:3108)
--target-env <kv...>—Repeated KEY=VALUE pairs added to the shell-action environment for behavioural re-verify
--target-timeout-ms <ms>—Per-step timeout for behavioural re-verify, in milliseconds (default 30000)
--keep-unrunfalseRoute could_not_run behavioural verdicts to needs-review instead of dropping them. Default-off because unverified PoCs should never auto-file.
--reverify-rps <n>—Per-host requests-per-second cap for behavioural reverify (default 2). Honours 429 Retry-After.
--scope-allowlist <hosts>—Comma-separated host allowlist for reverify. Supports *.domain.com wildcard (matches subdomains, NOT the apex). Out-of-scope http/shell steps fail closed.
--dry-runfalseShow what would be written without writing files

Create a vendor-notification draft from one finding JSON: issue, location, impact, reproduction, and remediation. Includes the mandatory ‘DRAFT — NOT SENT’ banner and sends nothing. #928

0 disclose evidence-pack [options] <finding.json>
ArgumentRequiredDescription
finding.jsonYesPath to a Finding JSON file
OptionRegistered defaultDescription
--target <label>—Affected target/package label for the ‘where’ line, e.g. [email protected]
--affected-ref <ref>—Git ref / version range string for the ‘where’ line
--allow-unreproducedfalseStage an internal draft even when the finding’s PoC did not reproduce (default off — unreproduced findings are a low-signal disclosure trip-wire)
--out <file>—Write the DRAFT markdown to a file instead of stdout

Create a disclosure record, or apply one legal transition with --record and --to. Records intent and sends nothing.

0 disclose track [options] <findingId>
ArgumentRequiredDescription
findingIdYesFinding ID the disclosure record is for
OptionRegistered defaultDescription
--record <file>—Existing disclosure-record JSON to transition (omit to open a fresh draft)
--to <status>—Target status for the transition (requires —record)
--actor <actor>—Actor recorded on the timeline event (default ‘operator’)
--message <text>—Free-text note recorded on the timeline event
--disclosed-to <vendor>—Vendor/contact stamped when transitioning into ‘sent’
--cve-id <cve>—CVE id stamped when transitioning into ‘cve_assigned’
--out <file>—Write the record JSON to a file instead of stdout

Render a deterministic, redacted local reproducibility manifest for human inspection. Sends and publishes nothing.

0 disclose review [options] <finding.json>
ArgumentRequiredDescription
finding.jsonYesPath to a Finding JSON file
OptionRegistered defaultDescription
--timestamp <iso>—Override generation timestamp for deterministic output
--tool-version <ver>—Override tool version string
--model-config <str>—Provider/model config, e.g. anthropic/claude-sonnet-4
--target <id>—Override the finding target identifier
--out <file>—Write manifest to a file instead of stdout

Import kernel crash reports (KASAN, UBSAN, oops, syzkaller) into 0 findings.

0 ingest [options] [path]

Guide: Read the workflow.

ArgumentRequiredDescription
pathNoPath to a crash report file or directory of reports
OptionRegistered defaultDescription
--format <format>autoInput format: auto | kasan | ubsan | oops | syzkaller | generic
-o, --output <format>terminalOutput format: terminal | json | sarif
--verify—Run kernel oracle verification for each report/reproducer
--syz <path>—Run a standalone syzkaller .syz program through the kernel VM oracle
--reproducer <path>—Run a standalone C reproducer through the kernel VM oracle
--kernel-tree <path>—Linux source tree for Tier 1 kernel build/cache resolution
--kernel-config <name>—Kernel build config name for —kernel-tree (e.g. kasan, defconfig+kasan)
--config <profile>—[deprecated] alias for —kernel-config
--kernel-cache-dir <path>—Kernel build cache directory (default: ~/.0/kernel-cache)
--expected-signature <pattern>—Registered but not forwarded to kernel verification; do not rely on this option as a required crash-signature match.
--force-kernel-build—Rebuild kernel VM artifacts even when a cache entry exists
--review-subsystem—After ingest, run linux-kernel review against the crash subsystem for sibling bugs
--tree <path>—Linux source tree used by —review-subsystem
--runtime <runtime>autoReview runtime for —review-subsystem: auto, claude, codex, gemini, api
--api-key <key>—API key for —review-subsystem API runtime
-m, --model <model>—Model for —review-subsystem
--timeout <ms>600000AI review timeout for —review-subsystem
--cost-ceiling <usd>—Estimated model-cost ceiling for subsystem review, not a guaranteed whole-job billing cap.
--review-subsystem-fixture <path>—
-v, --verbose—Verbose output
--persist—Write ingested findings to an isolated 0 run database (default: classify only)
--db-path <path>—Explicit SQLite path for —persist (default: a new ~/.0/runs/<run-id>/state.db)

Imported crash logs record a prior run. For a new reproduction, follow Kernel VM Verification and its execution and evidence requirements.

Manage the local findings database.

0 db

Guide: Read the workflow.

Subcommands: repair · reset.

Back up a malformed local SQLite database and recreate a clean one

0 db repair [options]
OptionRegistered defaultDescription
--db-path <path>—Path to SQLite database

Delete the local SQLite database and optionally reseed the verification workbench

0 db reset [options]
OptionRegistered defaultDescription
--db-path <path>—Path to SQLite database
--seed <preset>verificationSeed preset to load after reset

Run target-specific engines through the shared evidence research plane

0 research

Guide: Read the workflow.

Subcommands: pipeline · mobile · linux-matrix · linux.

Run the existing web/AI/source/package pipeline through the shared evidence plane

0 research pipeline [options]
OptionRegistered defaultDescription
--target <target> required—URL, local path, repository, package, or image
--target-type <type>—url, web-app, source-code, npm-package, pypi-package, cargo-package, or oci-image
--profile <profile>—Source review profile
--depth <depth>defaultquick, default, or deep
--runtime <runtime>autoauto, api, claude, codex, gemini, or ollama
--artifact-root <path>.0-researchResearch artifact root

Run passive mobile intake; indicators remain hypotheses and only scoped adapters may hand off targets

0 research mobile [options]
OptionRegistered defaultDescription
--target <path> required—Extracted APK/IPA directory or metadata file
--artifact-root <path>.0-researchResearch artifact root

Validate and hash vulnerable-vs-patched boot logs from externally executed runs. This command performs no boots.

0 research linux-matrix [options]
OptionRegistered defaultDescription
--matrix <path> required—Versioned external boot-matrix manifest JSON
--finding <path> required—Existing Finding JSON to bind the proof to
--artifact-root <path>.0-researchResearch artifact root

Run a supplied Linux kernel reproducer through the shared N-boot evidence gate

0 research linux [options]
OptionRegistered defaultDescription
--kernel-tree <path> required—Linux source tree
--reproducer <path> required—C reproducer or syzkaller .syz program
--finding <path> required—Existing Finding JSON to bind the proof to
--expected-signature <literal> required—Literal crash signature that every counted boot must contain
--boots <n>3Fresh boots
--min-hits <n>2Required reproducing boots
--artifact-root <path>.0-researchResearch artifact root

Hunt variants of a bug class using a proven fix. Generate candidate sites, run finders, and check their leads with an adversarial skeptic. Leads require verification before a 0-day claim. Exit 0: leads found; 1: none found; 2: no candidates; 3: error.

0 hunt [options]

Guide: Read the workflow.

OptionRegistered defaultDescription
--source <path> required—Source tree to hunt in (e.g. a linux checkout)
--seed <path> required—Fix diff / .patch whose bug class to hunt variants of
--ref <name>—Provenance label for the seed (e.g. the CVE / commit)
--concurrency <N>—Max finders in flight (default 4)
--max-candidates <N>—Registered but not forwarded by the current CLI handler; do not rely on this flag to bound work.
--skip-candidates <N>—Skip the first N ranked candidate sites before hunting (default 0)
--models <a,b>—Comma-separated finder models for diversity (default: provider default)
--reachable-only—Restrict candidates to paths built + zero-cap reachable on the kernelCTF COS target (default: HUNT_REACHABLE_ONLY env)
--reachable-prefer—Sort kernelCTF-reachable candidates first, without dropping any (default: HUNT_REACHABLE_PREFER env)
--no-verify—Skip the skeptic gate (emit all raw findings — triage only, never disclosure)
--novelty—Require lore.kernel.org duplicate suppression; abort before discovery when evidence is unavailable
--novelty-root <path>—Lore mirror root (default: ZERO_LORE_MIRROR_ROOT or /root/lore-mirror)
--novelty-lists <a,b>—Comma-separated lore lists to search (default: ZERO_LORE_LISTS or linux-media)
--novelty-recent-epochs <N>—Newest public-inbox epochs to sync per list when —novelty-sync is set (default 1)
--novelty-sync—Clone/fetch lore mirrors before running the novelty gate
--novelty-model <model>—Optional model override for the lore duplicate judge
--novelty-required—Legacy alias; —novelty already aborts when evidence is unavailable
--methodology—Use the kernel-LPE methodology preset: lifecycle/provenance lenses, best-of-4, top-2 skeptic gate, reachable-first
--invariant—Engine A: build (or load) the seed-touched subsystem’s stored invariant model and inject its rules + deterministic violation hypotheses into every finder prompt
--graph-slice—Load the seed-touched subsystem’s pre-exported Joern CPG and inject a compact interprocedural reachability slice around the fix site into every finder prompt (needs scripts/provision-cpg.sh; fail-open to flat-text)
--cpg <path>—Explicit CPG graphson JSON path for —graph-slice (default: <source>/.0/cpg/<subsystem>.json)
--ops-harvest <paths>—[—graph-slice] Comma-separated repo-relative C files to harvest static ops-struct initializers from; overrides a precomputed .ops.json
--graph-slice-hops <N>—[—graph-slice] Call-graph radius around the seed functions (default 3; use 8 for the exp527 known answer)
--exploitability—PROVE stage: after the skeptic+prover gate, run the execution-verified exploitability oracle on each confirmed finding (GREBE diversify + SCAVY differential). BOOTS REAL QEMU VMs — requires staged kernel-VM artifacts and is ignored under —no-verify. Never rejects a finding; it stamps a proven verdict and gates the weaponize budget.
--prove-min-ceiling <ceiling>—[—exploitability] Minimum assessed impact ceiling worth a VM slot: dos-only|info-leak|oob-write|uaf-control (default info-leak — filters out dos-only before QEMU is touched)
--output <path>—Write the hunt result JSON to this path instead of stdout
--runtime <mode>—Engine runtime (default api)
--timeout <ms>600000Accepted cloud agent timeout budget in milliseconds

Hunt the kernelCTF freshness window in a linux-next diff. Exclude files unreachable by unprivileged users, classify changes as semantic (lifetime, refcount, locking) or cosmetic, then run the invariant engine and adversarial verification on semantic changes. The ranked leads require novelty and reachability checks before disclosure. Exit 0: survivors; 1: none; 2: empty window; 3: error.

0 recency-hunt [options]

Guide: Read the workflow.

OptionRegistered defaultDescription
--tree <path> required—Kernel source tree to hunt (e.g. /root/linux-next)
--since <gitrange>—Explicit git range (e.g. HEAD~20..HEAD or <sha>..HEAD); overrides —hours
--hours <N>—Hunt commits from the last N hours (default 24)
-m, --model <model>—Model-build / finder model override
--classifier-model <model>—Semantic-vs-cosmetic classifier model (default gpt-5.5)
--runtime <mode>—Engine runtime (default api)
--model-dir <path>—Where per-file invariant models are stored (default <tree>/.recency-models)
--max-hunt-files <N>—Cap files run through the engine (default 25)
--max-classify-files <N>—Cap in-scope files sent to the LLM classifier (default 80; snapshot merge-window cost control)
--detectors <list>—Comma-separated detectors per semantic file: dataflow,refcount,race,dual-view (default the three static; dual-view is opt-in)
--dynamic-witness—Run the full machine: assumption-mining dual-view enumerator → KASAN synthesize→boot→witness oracle. Implies dual-view. VM boots are expensive — bounded by the budget below.
--witness-candidates <N>—Dynamic-witness RUN budget: total dual-view candidates booted through the KASAN oracle per run (default 10)
--witness-candidates-per-file <N>—Per-file cap on witnessed candidates, clamped to the run budget (default 6)
--witness-rounds <N>—Bounded PoC-repair rounds per candidate — each is one VM boot (default 2)
--witness-mode <mode>—PoC shape for the oracle: single (sequential), race (concurrent multi-thread), auto (race for race-shaped seams; default)
--witness-race-threads <N>—Race-mode worker threads driving entryA vs entryB (default 4)
--witness-race-iters <N>—Race-mode per-thread hammer iterations to widen the race window (default 200000)
--remine-assumptions—Force a fresh assumption mine for dual-view each run (default: reuse a stored per-file model if present)
--output <path>—Write the report JSON here instead of stdout
--md <path>—Also write the markdown report here
--report-dir <dir>—Scheduler mode: write <dir>/YYYY-MM-DD.{json,md} + log a one-line summary

Mine implicit function preconditions without a seed. Compare relied-on and enforced conditions without an LLM, then find reachable callers that omit a required precondition. Output contains candidates to disprove. Exit 0: completed, with or without candidates; 3: error.

0 assumption-hunt [options] <source-root>

Guide: Read the workflow.

ArgumentRequiredDescription
source-rootYesLocal source tree the subsystem files live under (e.g. a kernel checkout)
OptionRegistered defaultDescription
--files <a.c,b.c> required—Comma-separated subsystem source files, repo-relative to <source-root>
--subsystem <label>—Subsystem label for the stored model (e.g. net/unix)
--model-path <path>—Where the durable assumption model JSON lives (default under <source-root>/.0)
--remine—Force a fresh LLM mine even if the stored model exists
--skip-hunt—Stop after the deterministic caller-scan (no LLM finder/skeptic gate)
--no-verify—Run the finder fan-out but skip the skeptic gate
--models <a,b>—Comma-separated finder/mine models for diversity
--max-contexts <N>—Cap the violating contexts fed to the hunt
--no-wrapper-resolution—Disable v1 establisher-wrapper resolution (reproduces the v0 direct-token scan — FP ablation)
--no-finder-targeting—Feed the finder the whole subsystem file instead of focused per-function excerpts
--no-dual-view—Disable the v2 dual-api/cross-phase enumerator (caller-scan only — the v1 behavior)
--dynamic-witness—v3: route dual-view candidates to the KASAN synthesize→boot→witness oracle (bypasses the static skeptic). Needs a KASAN VM env (ZERO_KERNEL_QEMU_*).
--witness-rounds <N>—Bounded PoC-repair rounds per dual-view candidate (default 3)
--witness-candidates <N>—Cap dual-view candidates run through the dynamic oracle (default 10)
--witness-model <name>—Model for PoC synthesis (default: runtime default)
--witness-mode <mode>—PoC shape: single (sequential), race (concurrent multi-thread), auto (race for race-shaped seams; default)
--witness-race-threads <N>—Race-mode worker threads driving entryA vs entryB (default 4)
--witness-race-iters <N>—Race-mode per-thread hammer iterations to widen the race window (default 200000)
--excerpt-dir <path>—Where finder-targeting excerpts are written (default: os tmpdir)
--runtime <mode>—Engine runtime (default api)
--format <fmt>jsonOutput format (json)
--output <path>—Write the result JSON to this path instead of stdout

Scan userspace or Rust code for memory-safety faults in Monty mode. Clone the source, build a fuzz/sanitizer harness, run the fuzz loop, and report reproduced memory corruption. Exit 0: loop completed, with or without crashes; 2: skipped because the build system or execution prerequisite is unavailable; 3: bad flags or unreadable target.

0 memsafety [options] <source>

Guide: Read the workflow.

ArgumentRequiredDescription
sourceYesSource tree to fuzz (a local path or a git URL)
OptionRegistered defaultDescription
--subsystem <path>—Narrow the scanned root to a subdirectory
--language <lang>—Force the language: c | cpp | rust (else auto-detected)
--build-system <sys>—Force the build system: cargo | cmake | autotools | meson | make (else auto-detected)
--artifact-dir <path>—Persist bounded crash evidence outside the source tree
--artifact-max-bytes <bytes>—Aggregate byte ceiling for retained crash evidence (default 4194304)
--harness <name>—libFuzzer / cargo-fuzz harness target name
--fuzz-dir <path>—Non-standard cargo-fuzz directory (relative to source root)
--mirifalseAdditionally run cargo +nightly miri for UB detection (Rust)
--fuzz-timeout <sec>—Fuzz wall-clock budget in seconds (default 60)
--format <fmt>jsonOutput format (json)
--output <path>—Write the result JSON to this path instead of stdout
--runtime <mode>—Engine runtime (default api)
--timeout <ms>600000Clone/prepare timeout budget in milliseconds

Kernel security workflows

0 kernel

Guide: Read the workflow.

Subcommands: jev-prepass · jev-commit-prepass · jev-source-prepass · crash-triage · syzbot-mine · weights · variant-hunt.

Ranks source-review hypotheses before kernel verification. Requires ZERO_JEV_FEATURES=kernel and a configured Jev provider. Scores are advisory; verification runs only when --verify-top is greater than 0.

0 kernel jev-prepass [options]
OptionRegistered defaultDescription
--tree <path> required—Path to the exact Linux source tree
--upstream-tree <path>—Current upstream Linux tree used to exclude already-fixed bugs before Jev spend
--findings <path> required—Finding[] or scan-report JSON from a kernel source review
--verify-top <n>0Run the existing kernel oracle for the top N ranked hypotheses
--attempts <n>5Maximum kernel_run attempts per selected hypothesis
-o, --out <path>—Write the exhaustive ranked result to a file

Ranks commit diffs from a bounded Linux Git history for deeper review. Requires ZERO_JEV_FEATURES=kernel and a configured Jev provider. A score is not a confirmed vulnerability.

0 kernel jev-commit-prepass [options]
OptionRegistered defaultDescription
--tree <path> required—Path to a Linux git tree
--since <git-date>14 days agoEnumerate commits since this git date
--paths <csv>—Optional repo-relative path prefixes
--limit <n>400Maximum commits to enumerate
-o, --out <path>—Write ranked commit ledger to a file

Extracts C functions from a kernel subtree or source file and ranks them with Jev. Requires ZERO_JEV_FEATURES=kernel and a configured provider. The JSON ledger reports evaluated and unscored functions separately.

0 kernel jev-source-prepass [options]
OptionRegistered defaultDescription
--tree <path> required—Path to the Linux source tree
--subtree <path> required—Repo-relative kernel subtree or C source file
-o, --out <path>—Write the exhaustive function ranking ledger to a file

Ranks supplied crash records for further investigation. Requires ZERO_JEV_FEATURES=crash and a configured Jev provider. This command does not reproduce a crash or prove exploitability.

0 kernel crash-triage [options]
OptionRegistered defaultDescription
--crashes <path> required—Path to crash JSON (array of CrashRecord or { crashes: CrashRecord[] })
-o, --out <path>—Write ranked crash triage JSON to a file
--summary-out <path>—Write compact markdown crash summary to a file

Mine and LPE-rank syzbot’s invalid/auto-closed queue

0 kernel syzbot-mine [options]
OptionRegistered defaultDescription
--subsystems <csv>net,net/sched,net/tls,xfrm,crypto,vsock,nfcSubsystem labels to keep
--limit <n>30Maximum ranked candidates
--details <n>15Top candidate detail pages to enrich
--detail-delay <ms>750Delay between syzbot detail/repro requests

Generate an LLM-derived syzkaller choice_weights.json for a kernelCTF target

0 kernel weights [options]
OptionRegistered defaultDescription
--target <version> required—Target kernel version, e.g. 6.12.101
--crash-summary <path>—File with recent crash descriptions to inform weighting
--jev-prepass <path>—Jev commit/finding prepass JSON used as ranked weighting evidence
--enabled-syscalls <path>—JSON array file of manager-enabled syscall names to constrain the plan
--from-file <path>—Validate/normalize a raw model JSON plan instead of calling the API
-m, --model <model>—Override model (default: env/auto-detected)
--max-entries <n>48Maximum weighted syscalls
--dry-run—Print the weights file instead of writing
-o, --out <path>—Output path for choice_weights.json

Run foxguard-backed kernel advisory variant hunting

0 kernel variant-hunt [options]
OptionRegistered defaultDescription
--tree <path> required—Path to a Linux source tree
--advisory <url-or-file>—Advisory URL or local advisory path for provenance
--rules <path>—Foxguard rule directory, e.g. rules/kernel/dirty-frag-class
--foxguard <path>—Foxguard binary path
--sarif-input <path>—Use an existing foxguard SARIF file instead of invoking foxguard
--timeout <ms>120000Foxguard timeout in milliseconds
-o, --output <format>terminalOutput format: terminal | json | sarif
-v, --verbose—Verbose terminal output

Ranks recent repository commits for possible silent security fixes. Requires ZERO_JEV_FEATURES=radar and a configured Jev provider. Optional seed output feeds later investigation; ranking does not verify or dismiss vulnerabilities.

0 radar [options]
OptionRegistered defaultDescription
--repo <path> required—Path to a valid git working tree
--since <date-or-ref>—Git since-format constraint (e.g. ‘7 days ago’, ‘HEAD~50’)
--path <paths...>—Restrict scanning to specific file paths (repeatable)
--limit <N>—Maximum commits to enumerate (default 200)
--out <path>—Write ranked JSON results to file instead of stdout
--seeds-out <path>—Write SeedFindings JSON for variant-hunt candidates to file

Run the kernel-VM escalation ladder for a confirmed memory-safety finding (ADR-055 Phase 1). Missing VM artifacts produce exit 2 with no execution. With --climb, run the verification and weaponization chain through repeated boots until the deterministic oracle observes root.

0 exploit [options]

Guide: Read the workflow.

OptionRegistered defaultDescription
--finding <path>—Path to a confirmed kernel finding.json (required except with —autoclimb/—agent)
--reproducer <path>—Path to the proven memory-safety reproducer (C source), embedded for provenance.
--max-strategies <N>—Cap the number of applicable strategies attempted (bounds VM boots).
--output <path>—Write the weaponization result JSON to this path instead of stdout.
--climb—Engine-driven root-climb mode: drive the REAL verify→weaponization chain runner (real QEMU runner + real oracle, no overrides), looping boots until the oracle credits root. Requires staged kernel-VM artifacts.
--loop-boots <N>—[—climb] Max genuine QEMU boots to loop (root race is ~1/6-8). Default 8.
--vmlinux <path>—[—climb] Resolved vmlinux for the root-tail planner’s symbol resolution.
--kernel-config <path>—[—climb] Kernel .config text for exploit-config introspection.
--freed-struct <name>—[—climb] Freed object’s C struct name (e.g. snd_rawmidi_runtime).
--proof-out <path>—[—climb] Where to write the read-only root proof (default: temp dir).
--autoclimb—Autonomous LLM-composed weaponization climb: the engine’s OWN codegen loop composes each C body from the technique library + bug trigger + last verdict.
--bug-spec <path>—[—autoclimb] JSON AutonomousClimbBug (trigger C, config-off, slab, ceiling).
--boot-script <path>—[—autoclimb] Generic boot script ($1=composed .c, stdout=guest stdout, <c>.serial=dmesg). Or set ZERO_AUTOCLIMB_BOOT_SCRIPT.
--model <id>—[—autoclimb] Engine model id for the composer (default: engine runtime default).
--agent—Agentic weaponization loop: the model gets a shell in an already-provisioned target and iterates recon → weaponize → build → run against real crash output, gated by the mechanical trigger→reclaim→leak→write→root stage gate.
--task <path>—[—agent] Task/vuln description file (vuln doc + PoV + build).
--container <id>—[—agent] Run exploit commands in this container via docker exec (cwd /workspace).
--exec-script <path>—[—agent] Run exploit commands through this script ($1=command) — the E2B/SSH/console seam. Mutually exclusive with —container; one of the two is REQUIRED (no local execution).
--flag-path <path>—[—agent] Where the captured flag must land in the target (default /tmp/flag).
--flag-pattern <ere>—[—agent] ERE the flag content must match. Without it a capture rests on a non-empty flag file only, which a status line the agent echoes there will FALSE-PASS.
--max-steps <N>—[—agent] Agent step budget (default 90).
--runtime <mode>—[—agent] Engine runtime (default api).

Model each IOKit user client’s IOExternalMethodDispatch2022 gate, generate gate-passing structured inputs, and plan a disposable macOS-VM fuzzing run. Complements the xnu-re review profile.

0 xnu-fuzz

Guide: Read the workflow.

Subcommands: enumerate · gen · harness-plan.

§1: kext → target-model.json (dispatch-table → valid-input model)

0 xnu-fuzz enumerate [options]
OptionRegistered defaultDescription
--kext <path> required—Path to the extracted kext Mach-O (from xnu-re-extract.sh).
--bundle <id>—Kext bundle id recorded in the model (e.g. com.apple.iokit.IOSurface).
--out <file>—Write the full target-model.json to this path.
--json—Emit the model as JSON on stdout instead of a summary.

§2: target-model.json → gate-passing + structure-aware inputs

0 xnu-fuzz gen [options]
OptionRegistered defaultDescription
--model <file> required—Path to a target-model.json from enumerate.
--class <name>—User-client class to generate for (default: largest).
--selector <N>—Only generate for this selector index.
--seed <N>—PRNG seed for reproducible generation (default 1).
--json—Emit the generation summary as JSON.

Print the execution requirements for one macOS-VM shard.

0 xnu-fuzz harness-plan [options]
OptionRegistered defaultDescription
--golden <image>—Golden tart VM image name.
--build <build>—macOS build the golden image + kernelcache match.
--shared <dir>—Host-shared folder for the program/result/panic channel.
--oracle <kind>—Crash oracle: release | kasan | kfence (default release).

Analyze a compiled binary by delegating to the in-repo 0verse engine (uv run —frozen 0verse)

0 binary [options] <target> [passthrough...]

Guide: Read the workflow.

ArgumentRequiredDescription
targetYesPath to the target artifact (e.g. an ELF) to analyze
passthroughNoExtra positional args forwarded verbatim to 0verse
OptionRegistered defaultDescription
--mode <mode>triage0verse subcommand: triage|run|scan
--format <format>—Forward —format to 0verse (e.g. ndjson)
--backend <backend>—Forward —backend to 0verse (e.g. rizin, ghidra, angr)
--llm <llm>—Forward —llm to 0verse (e.g. codex, claude)

Check Tier-1 HTTP conformance against a spec excerpt (issue #972). The LLM proposes mismatches, exercises run against the real target, and a deterministic oracle confirms MUST-level violations.

0 protocol-check [options]

Guide: Read the workflow.

OptionRegistered defaultDescription
--spec <file> required—Path to the authoritative specification excerpt (RFC/ABNF prose, text).
--impl <file> required—Path to the implementation source excerpt the divergence is hypothesized in.
--target <url> required—Base URL of the live target to exercise (e.g. http://127.0.0.1:8080).
--json—Emit the full result (findings + attempts) as JSON on stdout.
--max-exercises <N>—Cap how many ranked hypotheses to exercise against the target (default 8).
--runtime <runtime>autoLLM runtime: auto/api (codex login or API key), claude, codex, gemini.
--protocol <name>—Protocol name for the report/finding (default HTTP/1.1).
--spec-version <version>—Spec edition for the report (default RFC 9110).
--spec-ref <ref>—Auditable spec citation (e.g. ‘RFC 9110 §9.3.6’).

Protocol/spec differential-hunting research commands.

0 specdrift

See Research Workflows for prerequisites and evidence limits.

Guide: Read the workflow.

Subcommands: extract · scan · plan.

Extract cited protocol invariants from an arbitrary spec text file

0 specdrift extract [options]
OptionRegistered defaultDescription
--spec <path> required—Spec/RFC/protocol text file to analyze
--spec-name <name>—Display name stored in citations
--max-invariants <N>40Maximum invariant candidates to emit
--output <path>—Write JSON result to a file instead of stdout

Extract spec invariants and map them to candidate implementation code

0 specdrift scan [options]
OptionRegistered defaultDescription
--spec <path> required—Spec/RFC/protocol text file to analyze
--source <path-or-git-url> required—Implementation source tree to map against
--spec-name <name>—Display name stored in citations
--max-invariants <N>40Maximum invariant candidates to extract
--max-files <N>400Maximum source files to inspect
--max-candidates-per-invariant <N>5Maximum implementation candidates per invariant
--timeout <ms>600000Source preparation timeout
--output <path>—Write JSON result to a file instead of stdout

Extract invariants, map implementation candidates, and emit drift hypotheses to verify

0 specdrift plan [options]
OptionRegistered defaultDescription
--spec <path> required—Spec/RFC/protocol text file to analyze
--source <path-or-git-url> required—Implementation source tree to map against
--spec-name <name>—Display name stored in citations
--max-invariants <N>40Maximum invariant candidates to extract
--max-files <N>400Maximum source files to inspect
--max-candidates-per-invariant <N>5Maximum implementation candidates per invariant
--max-hypotheses <N>20Maximum drift hypotheses to emit
--timeout <ms>600000Source preparation timeout
--output <path>—Write JSON result to a file instead of stdout

Test whether untrusted MCP content causes a prohibited action in an authorized agent environment

0 agent-assure [options]

Guide: Read the workflow.

OptionRegistered defaultDescription
--agent-endpoint <url> required—Customer-owned agent test adapter endpoint (HTTP JSON contract)
--mcp-endpoint <url> required—Authorized MCP tools/list endpoint
--oracle-endpoint <url> required—Customer-owned state-observer endpoint
--scenario <path> required—Scenario JSON: id, title, injection_vector, benign_task, payload, prohibited_action
--scope <path>—Engagement scope JSON; required only while the scope plugin is enabled
--target-version <version> required—Version or build digest of the tested agent deployment
--policy-version <version> required—Version or digest of the agent prompt and authorization policy
--model-version <version> required—Model deployment/version identifier
--tool-version <name=version>[]Version of an MCP tool; repeatable
--environment <name>staginglocal, test, or staging
-m, --model <name>—Optional model identifier passed to the customer agent adapter
--agent-headers <path>—JSON file of headers for the agent adapter; never written to evidence
--mcp-headers <path>—JSON file of headers for the MCP endpoint; never written to evidence
--oracle-headers <path>—JSON file of headers for the state observer; never written to evidence
--timeout <ms>30000Per-request timeout in milliseconds
--oracle-timeout <ms>10000Maximum state-observer wait in milliseconds
--baseline <manifest>—Prior manifest to bind as a retest parent
--output <directory>—Evidence bundle directory; defaults to agent-assurance-<run-id>

Run adversarial safety eval against an AI/LLM endpoint and produce a scorecard

0 eval [options]

Guide: Read the workflow.

OptionRegistered defaultDescription
--target <url> required—Target AI/LLM endpoint URL
--format <format>terminalOutput format: terminal, json
--timeout <ms>30000Request timeout in milliseconds
--api-key <key>—API key for LLM provider
-m, --model <model>—LLM model to use for evaluation
--auth <json>—Auth credentials for the target (JSON string or path)
--categories <list>—Comma-separated category IDs to run (default: all). Use —list-categories to see available.
--list-categoriesfalseList available eval categories and exit
--verbosefalseShow detailed output

Run A/B variant tournaments and a CI regression gate over the labeled corpus (#656).

0 bench

Guide: Read the workflow.

Subcommands: improvement-project · improvement-assess · calibrate · run · diff · scoreboard.

Offline projection of sealed tournaments into the v1 result + v3 execution contract

0 bench improvement-project [options]
OptionRegistered defaultDescription
--candidate <path> required—schema-v1 ImprovementCandidate JSON
--champion-variant <id> required—champion variant id present in every tournament
--challenger-variant <id> required—challenger variant id present in every tournament
--development <path> required—JSON pair: {manifest, tournament}
--development-ref <ref> required—immutable development tournament artifact ref
--held-out <path> required—JSON pair: {manifest, tournament}
--held-out-ref <ref> required—immutable held-out tournament artifact ref
--negative-controls <path> required—JSON pair: {manifest, tournament}
--negative-controls-ref <ref> required—immutable negative-control artifact ref
--evaluation-manifest <path> required—precommitted evaluation manifest JSON
--manifest-ref <ref> required—immutable evaluation manifest artifact ref
--evaluator-bundle <path> required—evaluator bundle JSON
--evaluator-bundle-ref <ref> required—immutable evaluator bundle artifact ref
--evaluator-code <path> required—exact evaluator implementation artifact
--evaluator-code-ref <ref> required—immutable evaluator code artifact ref
--evaluator-config <path> required—exact evaluator configuration artifact
--evaluator-config-ref <ref> required—immutable evaluator config artifact ref
--ci-evidence <path> required—retained GitHub Actions receipt with identity, required checks, pass result, and evidenceRefs
--output-dir <path> required—create-once result + execution-evidence directory
--calibrationfalserejection-only projection of three trusted calibration lanes
--evidence-ref <ref>[]additional immutable evidence reference (repeatable)

Evaluate a sealed improvement result and publish an immutable promotion-decision ledger snapshot; generic artifacts always require human approval

0 bench improvement-assess [options]
OptionRegistered defaultDescription
--result <path> required—sealed result.json from bench improvement-project
--base-artifact <path> required—immutable champion artifact to bind into the decision
--candidate-artifact <path> required—immutable challenger artifact to bind into the decision
--output-dir <path> required—create-once promotion decision + ledger snapshot directory
--ledger <path>—prior immutable ledger.json snapshot to extend

Emit a sealed, provider-free no-uplift tournament for 0research calibration

0 bench calibrate [options]
OptionRegistered defaultDescription
--manifest <path> required—corpus manifest path
--case-id <id>[]exact pre-registered case id (repeatable)
--manifest-id <id> required—sealed calibration slice id
--tournament-output <path> required—create-once sealed calibration evidence
--evaluator-output-dir <path>—create-once exact evaluator code/config/bundle

Run a variant tournament over the corpus and update the benchmark ledger

0 bench run [options]
OptionRegistered defaultDescription
--integration <id>coreTarget-suite integration: core, xbow, cybergym
--manifest <path>—Corpus manifest path; optional for xbow/cybergym integration defaults
--xbow-path <dir>—XBOW checkout used by the xbow integration
--white-boxfalseExpose XBOW source paths to the selected agent
--cybergym-harness <dir>—CyberGym checkout used by the cybergym integration
--cybergym-subset <path>—Pre-registered CyberGym task-id file
--cybergym-difficulty <level>level1CyberGym task difficulty
--cybergym-best-of-n <n>1CyberGym trajectory count; default strict pass@1
--cybergym-max-submits <n>1Official CyberGym submits per task; default strict pass@1
--case-id <id>[]exact case id in a pre-registered manifest slice (repeatable)
--manifest-id <id>—sealed slice id (required with —case-id)
--variants <json|path>—JSON array of variant descriptors, or a path to one
--variant-id <id>championId for the implicit single variant
--harness <id>—Harness identity for the implicit single variant
-m, --model <model>—Model override for the implicit single variant
--runtime <runtime>—Runtime override (api/claude/codex/…)
--depth <depth>—Scan/audit depth override (quick/deep/…)
--pass-at-k <n>1Attempts per case (pass@k or independent repeats)
--attempt-policy <policy>pass-at-kpass-at-k or independent-repeat
--schedule <schedule>variant-majorvariant-major or case-major
--max-turns <n>40Hard attack-turn budget per attempt
--cost-ceiling <usd>—Per-attempt cost ceiling (USD)
--ci-subsetfalseRun only the fast CI subset (cases flagged ci:true)
--ledger <path>benchmark-ledger.jsonBenchmark ledger path
--tournament-output <path>—create-once canonical {manifest,tournament} evidence
--run-id <id>—Run id recorded in the ledger (default: ISO timestamp)
--gatefalseEvaluate the regression gate and exit non-zero on a regression
--max-success-drop <f>0.05Max success-rate drop vs last green
--max-fp-rise <f>0.05Max FP-rate rise vs last green
--format <format>terminalOutput format: terminal, json

Compare two recorded runs in a benchmark ledger

0 bench diff [options]
OptionRegistered defaultDescription
--a <runId> required—Baseline run id
--b <runId> required—Comparison run id
--ledger <path>benchmark-ledger.jsonBenchmark ledger path
--format <format>terminalOutput format: terminal, json

Render an existing benchmark ledger as Markdown and dashboard JSON. This command does not run a benchmark or invoke a model. It creates the output directory and overwrites scoreboard.md and scoreboard.json there. Review the reports before publishing them.

0 bench scoreboard [options]
Terminal window
0 bench scoreboard --ledger ./benchmark-ledger.json --out ./reports --title "Local benchmark"
OptionRegistered defaultDescription
--ledger <path>benchmark-ledger.jsonBenchmark ledger path
--out <dir>.Directory to write scoreboard.md + scoreboard.json
--title <title>—Report title/header
--keep-runs <n>10Trailing ledger entries shown in the trend table

Evolve appsec finder coverage from curated misses; promotion is corpus-gated and active reviews stay pinned

0 lens-synth [options]

Guide: Read the workflow.

OptionRegistered defaultDescription
--miss-input <path>—curated miss-input JSON ({ misses, corpus })
--registry <path>—durable overlay path (default: ~/.0/lenses/appsec-archetypes.json)
--max-register <n>—cap promoted champions per input revision
-m, --model <id>—synthesis model override
--promotefalsepersist a validated champion to the durable overlay
--trials <n>—repeated validation trials (2–10; default 2)
--from-bench <ledger>—harvest the champion’s false-negatives from a benchmark ledger into the curated misses (requires —manifest)
--manifest <path>—bench manifest path (ground-truth vuln class + sink); required with —from-bench
--watchfalsepoll the miss-input and process each new content revision
--poll-interval <ms>2000watch polling interval (minimum 100ms)
--statusfalseshow the active durable overlay and promotion ledger
--rollback <lens-id>—retire one previously promoted overlay lens
--jsonfalseprint machine-readable output

Autonomous self-improvement: source-candidate proposal, lens evaluation, and automatic promotion

0 evolve

Guide: Read the workflow.

Subcommands: run · status · reconcile · promote · rollback · exec · feedback.

Propose, independently evaluate, and optionally promote future workers

0 evolve run [options]
OptionRegistered defaultDescription
--config <path> required—Path to evolution config JSON file
--watch—Repeat until stable, budget exhausted, a failure, or interruption
--json—Output JSON (one result per line in watch mode)
--auto-promote—Enable automatic promotion
--no-auto-promote—Disable automatic promotion
--allow-source-access—Allow sending selected source to the model
--no-allow-source-access—Deny model source access
--max-passes <number>—Maximum watch passes (default: budget-limited)

Show active and canary versions, snapshot identities, and registry events

0 evolve status [options]
OptionRegistered defaultDescription
--store <path>—Required path to evolution store directory
--json—Output structured JSON

Record an observed charge for an interrupted durable dispatch. Supply the reservation ID and immutable cost-receipt digest shown by the campaign status. This resolves cost uncertainty once; it does not bypass provenance or promotion. See durable campaign accounting.

0 evolve reconcile [options]
OptionRegistered defaultDescription
--store <path> required—Path to evolution store directory
--dispatch <id> required—Unresolved dispatch reservation ID
--cost-usd <amount> required—Actual provider/execution charge
--receipt-digest <sha256> required—Immutable observed cost receipt digest
--json—Output structured campaign ledger

Approve an exact staged candidate after independent canary evaluation

0 evolve promote [options]
OptionRegistered defaultDescription
--store <path> required—Path to evolution store directory
--version <id> required—Evaluated candidate ID to approve
--json—Output structured JSON

Retire an active or canary evolution version and restore its parent

0 evolve rollback [options]
OptionRegistered defaultDescription
--store <path> required—Path to evolution store directory
--version <id> required—Active or canary version ID to retire
--reason <text>operator rollbackReason for rollback

Execute a pinned evolution version snapshot against an input

0 evolve exec [options]
OptionRegistered defaultDescription
--config <path> required—Path to evolution config JSON file (to determine store)
--run-id <id> required—Evolution run ID to pin and execute the active snapshot from
--input <json> required—JSON input to pass to the snapshot execution
--json—Output structured JSON instead of human-readable text

Capture, approve, and inspect evolution feedback candidates

0 evolve feedback

Subcommands: capture · approve · release · status.

Capture an evidence-backed observation from JSON. Finding verification remains unchanged.

0 evolve feedback capture [options]
OptionRegistered defaultDescription
--input <path> required—Observation JSON file with source revision and evidence references
--store <path>—Feedback queue JSON file
--allow-source-access—Explicitly consent to source use for this observation

Approve independent positive, held-out, and negative fixtures for an observation

0 evolve feedback approve [options]
OptionRegistered defaultDescription
--id <feedback-id> required—Full observation ID
--fixtures <path> required—Curation JSON containing positives, heldOut, and negativeControls
--store <path>—Feedback queue JSON file
--allow-source-access—Explicitly consent to source use for synthesis

Release a stale processing claim after its worker has stopped

0 evolve feedback release [options]
OptionRegistered defaultDescription
--id <feedback-id> required—Full observation ID
--claim-token <token> required—Exact claim token shown by feedback status —json
--store <path>—Feedback queue JSON file

Show retained observations and their approval/processing status

0 evolve feedback status [options]
OptionRegistered defaultDescription
--store <path>—Feedback queue JSON file
--json—Output structured JSON

Enumerate subdomains through passive CT/DNS, endpoints, OpenAPI/Swagger docs, and MCP servers. --active adds DNS brute force. Emit a deduplicated inventory for discovered_assets. Partial #769.

0 recon [options] <domain>

Guide: Read the workflow.

ArgumentRequiredDescription
domainYesTarget domain or origin, e.g. example.com or https://api.example.com
OptionRegistered defaultDescription
--json—Emit the asset inventory as machine-readable JSON
--timeout <ms>10000Per-request probe timeout in milliseconds
--active—Enable active DNS subdomain brute-force; the optional scope plugin enforces candidate authorization.
--scope <file>—JSON engagement policy; required for —active only while the scope plugin is enabled.

Fetch a site’s JavaScript bundles and extract endpoints, API base URLs, and redacted embedded secrets. Requires scope; access is denied by default. #927

0 js-recon [options] <url>

Guide: Read the workflow.

ArgumentRequiredDescription
urlYesTarget page URL whose <script> bundles are mined, e.g. https://app.example.com
OptionRegistered defaultDescription
--scope <file>—JSON engagement policy; required only while the scope plugin is enabled.
--timeout <ms>10000Per-request fetch timeout in milliseconds
--max-files <n>—Maximum JS files to fetch (clamped to [0,100])
--json—Emit the result as machine-readable JSON

Run registered npm-package detectors for SSPP fuzzing, validation read-stability TOCTOU, and SSRF parser differences. Confirmation requires an observed runtime consequence.

0 npm-discovery

Guide: Read the workflow.

Subcommands: list · run.

List the registered detectors and their classes.

0 npm-discovery list [options]
OptionRegistered defaultDescription
--json—Emit as JSON

Sweep a package worklist with the detectors and print confirmed findings.

0 npm-discovery run [options]
OptionRegistered defaultDescription
--install-dir <dir> required—Base dir the packages are installed under (prepare with npm install --ignore-scripts).
--packages <list>—Comma-separated package names to sweep, e.g. es-toolkit,radash
--detectors <ids>—Restrict to these detector ids (comma-separated). Default: all.
--downloads-floor <n>—Skip packages below this weekly-download floor (needs registry metadata).
--max-age-days <n>—Skip packages whose last publish is older than this (needs registry metadata).
--i-understand-untrusted-exec—Acknowledge that run executes untrusted package code in-process on this host.
--offline-dedup—Skip the live OSV advisory lookup (air-gapped/hermetic runs). Confirmed findings then dedup only against fork-twin/prior-report hints; live-unknown ones are marked source=unknown, not novel.
--json—Emit the result as machine-readable JSON

Assess an Entra ID (Azure AD) tenant’s privileged roles, conditional-access coverage, app registrations, service principals, and federated-domain trust. Read-only. Supply the Graph token through ZERO_GRAPH_ACCESS_TOKEN; command-line tokens are refused.

0 identity [options]

Guide: Read the workflow.

OptionRegistered defaultDescription
--tenant <tenantId> required—Entra tenant id (GUID) the supplied token is expected to belong to
--json—Emit the assessment result as machine-readable JSON
--timeout <ms>300000Wall-clock bound on the whole assessment in milliseconds
--scope <file>—Path to a JSON scope file ({in_scope, out_of_scope}). When supplied, graph.microsoft.com must be explicitly in scope or no request goes out.

Analyze existing BloodHound CE / SharpHound JSON for paths to Domain Admin, kerberoastable principals, unconstrained delegation, DCSync rights, ACL abuse chains, and ADCS escalation. Reads local files only, with no collection, authentication, or network access.

0 adgraph [options]

Guide: Read the workflow.

OptionRegistered defaultDescription
--input <path> required—A single BloodHound CE JSON file, or a directory of collector JSON files (non-recursive, *.json)
--json—Emit the analysis as machine-readable JSON
--timeout <ms>120000Wall-clock bound on ingest + analysis in milliseconds
--domain <fqdn>—Restrict the analysis to objects belonging to this AD domain, e.g. corp.example.com

Analyze an existing AzureHound export for paths to Global Administrator, service-principal escalation, consent-grant abuse, owner chains, and guest escalation. Reads local files only, with no collection, authentication, or network access.

0 entragraph [options]

Guide: Read the workflow.

OptionRegistered defaultDescription
--input <path> required—A single AzureHound JSON file, or a directory of AzureHound JSON files (non-recursive, *.json)
--json—Emit the analysis as machine-readable JSON
--timeout <ms>120000Wall-clock bound on ingest + analysis in milliseconds
--max-depth <n>—Hop ceiling for path traversal
--owned <ids>—Comma-separated object ids already under operator control. These become the path sources; omit to treat every enabled non-privileged principal as a candidate.

Probe S3 public access and takeover risks, or validate AWS credentials. Read-only; requires ZERO_FEATURE_CLOUD_SURFACE and an engagement scope. Access is denied by default. #925

0 cloud

These commands inspect authorized cloud infrastructure. For managed testing, contact the service operator; 0 cloud is local AWS/S3 reconnaissance, not managed-service account setup.

Guide: Read the workflow.

Subcommands: s3-probe · validate-creds.

Probe S3 buckets anonymously for public listing and orphaned-bucket takeover. Read-only; sends no credentials.

0 cloud s3-probe [options] <bucket...>
ArgumentRequiredDescription
bucketYesBucket name(s) to probe, e.g. acme-assets
OptionRegistered defaultDescription
--scope <file>—JSON engagement policy; required only while the scope plugin is enabled.
--region <region>—Bucket home region (default us-east-1 / global endpoint)
--max-keys <n>—Max object keys to sample from a public listing (1-100, default 10)
--json—Emit results as machine-readable JSON

Validate an AWS credential with sts:GetCallerIdentity and read-only over-privilege probes. Makes no changes.

0 cloud validate-creds [options]
OptionRegistered defaultDescription
--scope <file>—JSON engagement policy; required only while the scope plugin is enabled.
--access-key-id <id>—AWS access key id (defaults to $AWS_ACCESS_KEY_ID)
--secret-access-key <key>—AWS secret access key (defaults to $AWS_SECRET_ACCESS_KEY)
--session-token <token>—AWS session token (defaults to $AWS_SESSION_TOKEN)
--region <region>—AWS region for the STS call (default us-east-1)
--json—Emit the result as machine-readable JSON

Live vulnerability intelligence lookup helpers

0 intel

Guide: Read the workflow.

Subcommands: dossier · target-history · search · cve · similar.

Build a package-level intel dossier with risk summary, prior-vuln playbooks, and variant leads

0 intel dossier [options] <package>
ArgumentRequiredDescription
packageYesPackage name
OptionRegistered defaultDescription
--ecosystem <ecosystem>npmPackage ecosystem: npm, pypi, cargo, Go, Maven
--package-version <version>—Resolved package version
--ver <version>—Alias for —package-version
--keywords <list>—Comma-separated variant-hunt keywords
--similar-limit <n>10Maximum similar advisory leads
--no-similar—Skip similar-advisory search
--offline—Use cache only
--cache-dir <path>—Override intel cache directory
--json—Emit machine-readable JSON

Search prior CVEs/GHSAs already reported against this target, repo, package, or product

0 intel target-history [options] [target]
ArgumentRequiredDescription
targetNoTarget URL/name or GitHub repository
OptionRegistered defaultDescription
--repo-path <path>—Infer target hints from a local repository/package path
--repository <owner/repo-or-url>—GitHub repository hint, e.g. expressjs/express
--ecosystem <ecosystem>—Optional package ecosystem: npm, pypi, cargo, Go, Maven
--package <package>—Optional package name
--product <product>—Optional product/project name
--vendor <vendor>—Optional vendor/organization name
--keywords <list>—Comma-separated target aliases or extra search terms
--limit <n>20Maximum results per live source query
--offline—Use cache only
--cache-dir <path>—Override intel cache directory
--json—Emit machine-readable JSON

Search advisories for a package/version

0 intel search [options] <package>
ArgumentRequiredDescription
packageYesPackage name
OptionRegistered defaultDescription
--ecosystem <ecosystem>npmPackage ecosystem: npm, pypi, cargo, Go, Maven
--package-version <version>—Resolved package version
--ver <version>—Alias for —package-version
--no-enrich—Skip CVE enrichment via NVD/CISA KEV
--offline—Use cache only
--cache-dir <path>—Override intel cache directory
--json—Emit machine-readable JSON

Look up a CVE from NVD and CISA KEV

0 intel cve [options] <cve-id>
ArgumentRequiredDescription
cve-idYesCVE identifier, e.g. CVE-2024-1086
OptionRegistered defaultDescription
--offline—Use cache only
--cache-dir <path>—Override intel cache directory
--json—Emit machine-readable JSON

Search related CVEs/advisories by CWE and keywords

0 intel similar [options]
OptionRegistered defaultDescription
--cwe <cwe>—CWE id, e.g. CWE-22
--ecosystem <ecosystem>—Optional ecosystem hint
--keywords <list>—Comma-separated keywords
--limit <n>10Maximum results
--offline—Use cache only
--cache-dir <path>—Override intel cache directory
--json—Emit machine-readable JSON

CVE workflows: artifact lookup (find) and autonomous PoC adaptation (adapt).

0 cve

Guide: Read the workflow.

Subcommands: find · adapt.

Find public PoC + write-up artifacts for a CVE id

0 cve find [options] <cve-id>
ArgumentRequiredDescription
cve-idYesCVE identifier, e.g. CVE-2024-1086
OptionRegistered defaultDescription
--format <fmt>jsonOutput format: json | table
--cache-dir <path>—Override cache directory (default ~/.0/cve-cache)
--no-cache—Bypass on-disk cache and re-fetch every source
--timeout <ms>10000Per-source timeout in milliseconds
--retries <n>2Retry count per source on 5xx
--skip-github-poc-search—Skip the GitHub repository / code search step

Adapt a public PoC for until it reproduces on the target kernel.

0 cve adapt [options] <cve-id>
ArgumentRequiredDescription
cve-idYes
OptionRegistered defaultDescription
--kernel-tree <path> required—Linux source tree to build against
--kernel-config <profile>—Kernel build profile (default: kasan)
--attempts <n>5Max verify-run attempts across all candidates
--wall-clock <duration>30mTotal wall-clock budget (e.g. 30m, 90s, 500ms)
--artifacts <path>—Path to a CveArtifacts JSON file (temporary; replaced by the scraper once it merges).
--format <fmt>jsonOutput format: json | table

Expose selected target tools or managed workflows over MCP stdio.

0 mcp-server [options]

Use --workflows --workspace /absolute/path/to/repo for template discovery and source workflow execution. Live workflow targets require --scope and the enabled scope plugin. Workflow assessments use 0’s configured provider; individual target tools use the external agent’s reasoning model. Disconnect cancels this host’s active runs.

Local-target MCP stdio requires operator-selected host-local execution. The SmolVM batch CLI bridge cannot forward this transport and refuses startup without changing the configured sandbox profile. Use 0 workflow commands for isolated execution. Explicit --workflows --backend <id> runs a network client for a registered remote engine; the backend owns execution and remote runs survive client disconnect.

Guide: Read the workflow.

OptionRegistered defaultDescription
--target <target>—Target URL for this MCP session
--scan-id <scanId>—Scan ID to associate persisted findings and target updates with
--backend <id>—Use a registered remote workflow engine; no local execution fallback
--backends-config <path>—Operator backend connection registry JSON file
--engine-url <url>—Attach directly to a running trusted engine
--engine-token-env <name>—Environment variable holding the attached engine token
--session <id>—Attach workflow runs to an existing session on the selected engine
--workflowsfalseExpose workflow discovery and run lifecycle tools instead of live tools
--allow-applyfalsePermit explicit workflow apply requests inside the authorized workspace
--workspace <path>—Absolute authorized local root for workflow source assessments
--db-path <path>—Path to SQLite database
--timeout <ms>30000Default tool timeout in milliseconds
--scope <path>—Path to a 0 scope JSON file. Out-of-scope URLs are refused by every target tool.
--tools <names>—Comma-separated 0 MCP tools to expose (default: live tools, or workflow tools with —workflows).
--rate-limit <spec>—Per-host request rate-limit spec. Defaults to 5 rps when unset. An active —engagement-profile caps this: the effective rate is the minimum of the two, so the profile can only lower it.
--allow-scannersfalseDisable generic-scanner suppression for scoped engagements.
--engagement-profile <name>—Engagement hardening posture for authorized enterprise work. ‘standard’ (default) is the existing behaviour. ‘conservative’ applies the quiet posture to this MCP session: no adaptive WAF-evasion ladder, full jitter on the per-host token bucket, and a 1 rps/host ceiling. The profile can only ever make the session quieter — the effective rate is the minimum of the profile and —rate-limit. The applied posture is recorded as an engagement_posture_applied event on the scan so it can be handed to the client as evidence. Lower precedence than the scope file’s engagement block and ZERO_ENGAGEMENT_PROFILE.
--no-waf-evasion—Disable the adaptive WAF-evasion ladder (default: on). When a response classifies as blocked, the engine normally retries with encoding/casing/whitespace-mutated payload variants, which escalates a routine WAF block into a SOC incident. Detection and reporting of the block are unaffected. Independent of —engagement-profile; env form: ZERO_WAF_EVASION=0.

Install, enable, inspect, and run Hackstore extensions. For authoring, local testing, and the separate model-authored plugin mechanism, see Integrations.

0 plugin

Installation, project enablement, and invocation are separate steps. Treat plugin code as untrusted and provide OS isolation separately from capability declarations.

Guide: Read the workflow.

Subcommands: list · search · browse · install · enable · disable · info · run.

List installed plugins and their per-project enabled/stale state

0 plugin list

Search the configured registry for plugins

0 plugin search [options] <query>
ArgumentRequiredDescription
queryYes
OptionRegistered defaultDescription
--registry <url>—Hackstore index URL (https)

List everything in the configured registry

0 plugin browse [options]
OptionRegistered defaultDescription
--registry <url>—Hackstore index URL (https)

Download, validate, and write plugin files. Installation leaves the plugin disabled and executes no code.

0 plugin install [options] <id-or-path>
ArgumentRequiredDescription
id-or-pathYes
OptionRegistered defaultDescription
--registry <url>—Hackstore index URL (https)
--local—Install a local directory containing manifest.json and plugin.js (no network)

Enable an installed plugin for this project and grant its capabilities.

0 plugin enable <id>
ArgumentRequiredDescription
idYes

Disable a plugin for this project (files stay installed)

0 plugin disable <id>
ArgumentRequiredDescription
idYes

Show an installed plugin’s manifest, capabilities, and enablement state

0 plugin info <id>
ArgumentRequiredDescription
idYes

Spawn an enabled plugin and invoke its tool. Effectful tools require --yes. Pass arguments as key=value pairs, --json '<obj>', or both.

0 plugin run [options] <id> [tool] [pairs...]
ArgumentRequiredDescription
idYes
toolNo
pairsNo
OptionRegistered defaultDescription
--json <json>—JSON object of tool arguments
--yes—Authorize an effectful (non read-only) tool to run
--timeout <ms>—Per-call timeout in milliseconds

Run the autonomous verification worker against persisted queued case work

0 orchestrate [options]

Runs queued cases from the selected database. Review their credentials and side-effect permissions first. For multi-target scans, use the scan workflows.

Guide: Read the workflow.

OptionRegistered defaultDescription
--db-path <path>—Path to SQLite database
--limit <n>1Maximum queued cases to claim per pass
--runtime <runtime>—Runtime override: auto, claude, codex, gemini, api
--timeout <ms>30000Request timeout in milliseconds
--api-key <key>—API key for LLM provider
-m, --model <model>—LLM model to use
--watchfalseRun as a persistent daemon loop
--poll-interval <ms>5000Idle poll interval for watch mode
--label <name>—Operator-facing worker label

HackerOne hacker-API helpers (read-only)

0 h1

Guide: Read the workflow.

Subcommands: auth · programs · scope.

Verify HackerOne API credentials

0 h1 auth

List or inspect HackerOne programs

0 h1 programs

Subcommands: list · show.

List visible programs

0 h1 programs list [options]
OptionRegistered defaultDescription
--bounty—Only programs that pay bounties
--vdp—Only non-bounty (VDP) programs
--state <state>—Filter by program state (e.g. public_mode, soft_launched)
--limit <n>—Max programs to return (default 100, max 1000)
--json—Emit machine-readable JSON instead of a table

Show details for a single program

0 h1 programs show <handle>
ArgumentRequiredDescription
handleYesProgram handle (e.g. flutteruki)

Export HackerOne scope into the scope-file format used by 0.

0 h1 scope

Subcommands: dump.

Write a program’s structured_scopes to ~/.0/scopes/.json

0 h1 scope dump [options] <handle>
ArgumentRequiredDescription
handleYesProgram handle
OptionRegistered defaultDescription
--out <path>—Override the output path

These commands store operator-approved criteria for a real local project root, not cloud enrollment or repository-controlled configuration. See the review-check workflow.

Manage private project checks and explicit revision approvals.

0 checks

Subcommands: propose · add · list · enable · disable · set · remove.

Save a literal draft without enabling it. Creating a draft grants no authority to execute it in future reviews.

0 checks propose [options]
OptionRegistered defaultDescription
--name <name> required—Short check name (1–120 characters)
--prompt <text> required—Literal review criterion (1–2000 characters)
--project <path>—Local project directory (defaults to this checkout’s root)
--json—Machine-readable result

Create and enable an explicitly approved literal check. At most eight checks can be active in one local project.

0 checks add [options]
OptionRegistered defaultDescription
--name <name> required—Short check name (1–120 characters)
--prompt <text> required—Literal review criterion (1–2000 characters)
--yes required—Approve this prompt for future local reviews
--project <path>—Local project directory (defaults to this checkout’s root)
--json—Machine-readable result

List current prompts, revisions, and enabled or inactive status for the project.

0 checks list [options]
OptionRegistered defaultDescription
--project <path>—Local project directory (defaults to this checkout’s root)
--json—Machine-readable result

Approve the current revision. Use an expected revision when approval must refer to the exact draft inspected by the operator.

0 checks enable [options] <id>
ArgumentRequiredDescription
idYes
OptionRegistered defaultDescription
--yes required—Confirm developer approval
--expected-revision <n>—Refuse if the inspected revision changed
--project <path>—Local project directory (defaults to this checkout’s root)
--json—Machine-readable result

Stop future evaluation without deleting prompt history.

0 checks disable [options] <id>
ArgumentRequiredDescription
idYes
OptionRegistered defaultDescription
--project <path>—Local project directory (defaults to this checkout’s root)
--json—Machine-readable result

Revise the literal prompt. Changing an enabled check requires fresh explicit approval; stale expected revisions leave the previous state unchanged.

0 checks set [options] <id>
ArgumentRequiredDescription
idYes
OptionRegistered defaultDescription
--prompt <text> required—Replacement literal prompt (1–2000 characters)
--yes—Approve the new revision if the check is enabled
--expected-revision <n>—Refuse if the inspected revision changed
--project <path>—Local project directory (defaults to this checkout’s root)
--json—Machine-readable result

Delete a local check and its revisions from the selected project.

0 checks remove [options] <id>
ArgumentRequiredDescription
idYes
OptionRegistered defaultDescription
--project <path>—Local project directory (defaults to this checkout’s root)
--json—Machine-readable result

The XBOW runner lives in the benchmark workspace. See Benchmarks and Methodology for current commands, prerequisites, and measured-result interpretation. The specialized runner does not implement a help-only --help path; passing it can start benchmark execution. Inspect the documented arguments or packages/benchmark/src/xbow-runner.ts instead. Execution requires dedicated target environments and a benchmark budget.

See Workflow CLI for templates, foreground execution, scope, and host lifetime.

Discover reusable definitions and execute them through the shared workflow runtime.

0 workflow

Subcommands: list · show · run.

List saved workflows and templates without starting an assessment.

0 workflow list [options]
OptionRegistered defaultDescription
--templates—List only templates
--engine-url <url>—Attach directly to a running trusted engine
--engine-token-env <name>—Environment variable holding the attached engine token
--backend <id>—Use a registered remote engine; targets and inputs are interpreted there
--backends-config <path>—Operator backend connection registry JSON file
--db-path <path>—Control database with saved workflows and run history
--format <format>jsonOutput format: json or text

Inspect one saved workflow or select a template with --template.

0 workflow show [options] [id]
ArgumentRequiredDescription
idNo
OptionRegistered defaultDescription
--template <id>—Show a template definition
--engine-url <url>—Attach directly to a running trusted engine
--engine-token-env <name>—Environment variable holding the attached engine token
--backend <id>—Use a registered remote engine; targets and inputs are interpreted there
--backends-config <path>—Operator backend connection registry JSON file
--db-path <path>—Control database with saved workflows and run history
--format <format>jsonOutput format: json or text

Execute one saved revision or template in the foreground. Ctrl-C cancels the run. Completed execution can contain findings; consumers must inspect the results.

0 workflow run [options] [id]
ArgumentRequiredDescription
idNo
OptionRegistered defaultDescription
--session <id>—Attach the run to an existing session on the selected engine
--template <id>—Execute a template without saving a copy
--revision <revision>—Require this workflow or template revision
--target <target>—Bind the authorized target
--workspace <path>—Workspace for local execution
--scope <path>—Scope JSON file
--model <model>—Configured 0 assessment model
--inputs <path>—Workflow artifact inputs as a JSON object (32 KiB values; 256 KiB file read limit)
--allow-apply—Explicitly authorize supported patch application steps for this host and run
--time-cap <ms>—Workflow-wide time cap in milliseconds
--cost-cap <usd>—Workflow-wide cost ceiling in USD
--engine-url <url>—Attach directly to a running trusted engine
--engine-token-env <name>—Environment variable holding the attached engine token
--backend <id>—Use a registered remote engine; targets and inputs are interpreted there
--backends-config <path>—Operator backend connection registry JSON file
--db-path <path>—Control database with saved workflows and run history
--format <format>jsonOutput format: json or text

Inspect retained workflow execution history.

0 runs

Subcommands: resume · list · show · cancel.

List retained runs in the selected control database.

0 runs list [options]
OptionRegistered defaultDescription
--engine-url <url>—Attach directly to a running trusted engine
--engine-token-env <name>—Environment variable holding the attached engine token
--backend <id>—Use a registered remote engine; targets and inputs are interpreted there
--backends-config <path>—Operator backend connection registry JSON file
--db-path <path>—Control database with saved workflows and run history
--format <format>jsonOutput format: json or text

Read one run and its retained results.

0 runs show [options] <id>
ArgumentRequiredDescription
idYes
OptionRegistered defaultDescription
--engine-url <url>—Attach directly to a running trusted engine
--engine-token-env <name>—Environment variable holding the attached engine token
--backend <id>—Use a registered remote engine; targets and inputs are interpreted there
--backends-config <path>—Operator backend connection registry JSON file
--db-path <path>—Control database with saved workflows and run history
--format <format>jsonOutput format: json or text

Request cancellation from the selected or discovered owning engine. This controls the same run visible in the browser. Ctrl-C also requests cancellation for a foreground workflow run; disconnecting an attached transport leaves the engine running. Stored history alone does not restart or stop execution.

0 runs cancel [options] <id>
ArgumentRequiredDescription
idYes
OptionRegistered defaultDescription
--engine-url <url>—Attach directly to a running trusted engine
--engine-token-env <name>—Environment variable holding the attached engine token
--backend <id>—Use a registered remote engine; targets and inputs are interpreted there
--backends-config <path>—Operator backend connection registry JSON file
--db-path <path>—Control database with saved workflows and run history
--format <format>jsonOutput format: json or text

Resume a persisted assessment scan in an existing engine session. The selected engine supplies the stored target, model, and current scope; optional branch and budget limits narrow the request. This resumes scan work rather than restarting a workflow graph.

0 runs resume [options] <scan-id>
Terminal window
0 runs resume SCAN_ID --session SESSION_ID --backend production
ArgumentRequiredDescription
scan-idYes
OptionRegistered defaultDescription
--session <id> required—Existing engine session
--branch-from-entry <index>—Nonnegative retained history entry index
--time-cap <ms>—Resume time ceiling in milliseconds
--cost-cap <usd>—Resume cost ceiling in USD
--engine-url <url>—Attach directly to a running trusted engine
--engine-token-env <name>—Environment variable holding the attached engine token
--backend <id>—Use a registered remote engine; targets and inputs are interpreted there
--backends-config <path>—Operator backend connection registry JSON file
--db-path <path>—Control database with saved workflows and run history
--format <format>jsonOutput format: json or text

Inspect and control the same live sessions used by the browser. Attach with —backend or —engine-url/—engine-token-env, or use the discovered local engine. Session operations preserve current engine admission grants.

0 sessions
Terminal window
0 sessions list --backend production

Subcommands: list · show · create · send · continue · cancel · events · resume · decide.

List live sessions, or retained snapshots with —saved. Listing does not resume work.

0 sessions list [options]
Terminal window
0 sessions list --saved --backend production
OptionRegistered defaultDescription
--saved—List retained session snapshots
--engine-url <url>—Attach directly to a running trusted engine
--engine-token-env <name>—Environment variable holding the attached engine token
--backend <id>—Use a registered remote engine; targets and inputs are interpreted there
--backends-config <path>—Operator backend connection registry JSON file
--db-path <path>—Control database with saved workflows and run history
--format <format>jsonOutput format: json or text

Read an existing live session without recreating it or restoring approvals.

0 sessions show [options] <id>
Terminal window
0 sessions show SESSION_ID --backend production
ArgumentRequiredDescription
idYes
OptionRegistered defaultDescription
--engine-url <url>—Attach directly to a running trusted engine
--engine-token-env <name>—Environment variable holding the attached engine token
--backend <id>—Use a registered remote engine; targets and inputs are interpreted there
--backends-config <path>—Operator backend connection registry JSON file
--db-path <path>—Control database with saved workflows and run history
--format <format>jsonOutput format: json or text

Create a session within the engine’s authorized workspace, scope, and model configuration. —config reads a bounded JSON object; it cannot expand engine grants.

0 sessions create [options]
Terminal window
0 sessions create --config session.json --backend production
OptionRegistered defaultDescription
--config <path>—Session configuration JSON object
--engine-url <url>—Attach directly to a running trusted engine
--engine-token-env <name>—Environment variable holding the attached engine token
--backend <id>—Use a registered remote engine; targets and inputs are interpreted there
--backends-config <path>—Operator backend connection registry JSON file
--db-path <path>—Control database with saved workflows and run history
--format <format>jsonOutput format: json or text

Send text to a live engine session. The engine runs the turn using its configured provider and tools.

0 sessions send [options] <id> <text>
Terminal window
0 sessions send SESSION_ID "Review the current findings" --backend production
ArgumentRequiredDescription
idYes
textYes
OptionRegistered defaultDescription
--engine-url <url>—Attach directly to a running trusted engine
--engine-token-env <name>—Environment variable holding the attached engine token
--backend <id>—Use a registered remote engine; targets and inputs are interpreted there
--backends-config <path>—Operator backend connection registry JSON file
--db-path <path>—Control database with saved workflows and run history
--format <format>jsonOutput format: json or text

Continue the selected live session with optional text. This preserves the existing engine context.

0 sessions continue [options] <id> [text]
Terminal window
0 sessions continue SESSION_ID --backend production
ArgumentRequiredDescription
idYes
textNo
OptionRegistered defaultDescription
--engine-url <url>—Attach directly to a running trusted engine
--engine-token-env <name>—Environment variable holding the attached engine token
--backend <id>—Use a registered remote engine; targets and inputs are interpreted there
--backends-config <path>—Operator backend connection registry JSON file
--db-path <path>—Control database with saved workflows and run history
--format <format>jsonOutput format: json or text

Explicitly cancel the session’s active work. Transport disconnect alone does not request cancellation from an attached engine.

0 sessions cancel [options] <id>
Terminal window
0 sessions cancel SESSION_ID --backend production
ArgumentRequiredDescription
idYes
OptionRegistered defaultDescription
--engine-url <url>—Attach directly to a running trusted engine
--engine-token-env <name>—Environment variable holding the attached engine token
--backend <id>—Use a registered remote engine; targets and inputs are interpreted there
--backends-config <path>—Operator backend connection registry JSON file
--db-path <path>—Control database with saved workflows and run history
--format <format>jsonOutput format: json or text

Read engine session events after an optional nonnegative cursor. Cursors belong to that engine and session.

0 sessions events [options] <id>
Terminal window
0 sessions events SESSION_ID --after 0 --backend production
ArgumentRequiredDescription
idYes
OptionRegistered defaultDescription
--after <cursor>—Nonnegative engine event cursor
--engine-url <url>—Attach directly to a running trusted engine
--engine-token-env <name>—Environment variable holding the attached engine token
--backend <id>—Use a registered remote engine; targets and inputs are interpreted there
--backends-config <path>—Operator backend connection registry JSON file
--db-path <path>—Control database with saved workflows and run history
--format <format>jsonOutput format: json or text

Restore a retained snapshot as a new session under current engine grants. Stored transcripts do not restore approval or filesystem grants.

0 sessions resume [options] <saved-id>
Terminal window
0 sessions resume SAVED_ID --backend production
ArgumentRequiredDescription
saved-idYes
OptionRegistered defaultDescription
--engine-url <url>—Attach directly to a running trusted engine
--engine-token-env <name>—Environment variable holding the attached engine token
--backend <id>—Use a registered remote engine; targets and inputs are interpreted there
--backends-config <path>—Operator backend connection registry JSON file
--db-path <path>—Control database with saved workflows and run history
--format <format>jsonOutput format: json or text

Respond to an existing session decision using a JSON response file. The engine checks the decision belongs to that live session.

0 sessions decide [options] <id> <decision-id>
Terminal window
0 sessions decide SESSION_ID DECISION_ID --response response.json --backend production
ArgumentRequiredDescription
idYes
decision-idYes
OptionRegistered defaultDescription
--response <path> required—Decision response JSON object
--engine-url <url>—Attach directly to a running trusted engine
--engine-token-env <name>—Environment variable holding the attached engine token
--backend <id>—Use a registered remote engine; targets and inputs are interpreted there
--backends-config <path>—Operator backend connection registry JSON file
--db-path <path>—Control database with saved workflows and run history
--format <format>jsonOutput format: json or text
0 learning

Inspect tenant-local learning activity and evaluation provenance. See Learning for trust boundaries and workflow version restoration.

Subcommands: status · process · evolve.

0 learning status [options]

Read recorded activity, retained knowledge, improvement states and queue status. Project filters accept a local source path or project identity. This command makes no model calls.

OptionRegistered defaultDescription
--project <id>—Filter by project
--json—Output structured JSON
0 learning process [options]

Process bounded queued observations. For an explicitly selected local source project, import existing current opted-in source notes. The default worker does not invent lessons from completion metadata or call a model.

OptionRegistered defaultDescription
--project <id>—Filter by project
--limit <number>—Maximum observations to process
--json—Output structured JSON
0 learning evolve [options]

Run the existing evolution controller with an explicit configuration and retain integrity-checked registry receipts. This can invoke configured models and incur their costs. Its output-fixture evaluation is not proof of improved security discovery. Promotion authority remains with the evolution registry and its configured gates.

OptionRegistered defaultDescription
--config <path> required—Evolution config JSON file
--project <id> required—Project associated with the evolution artifacts
--json—Output structured JSON

Registration entry point: packages/cli/src/index.ts. Command implementations are exported through packages/cli/src/commands/index.ts. Workflow guides explain handler behavior and prerequisites beyond the registered flags.