hammerhead versionHAMMERHEAD / V0.1.0 DOCUMENTATION
Start with a local audit.
Commands, reporting, and boundaries for the v0.1.0 CLI.
Quick start
With the v0.1.0 executable on your PATH, verify the installed version:
Audit the current working tree:
hammerhead audit .Write structured JSON:
hammerhead audit . --output json > audit.jsonUse --quiet for compact finding lines. Quiet mode omits the summary.
Reports and exit status
The default failure threshold is high. Security findings alone affect finding-based failure; Hygiene and Info do not.
- 0: No Security finding reached the selected threshold.
- 1: At least one Security finding reached the selected threshold.
- 2: CLI or operational failure, such as an invalid target or flag.
Check errors can be recorded while other checks continue. They do not automatically force status 2. A successful threshold result is not a guarantee of safety or complete coverage.
JSON uses schema hammerhead/v0.1. Reports include version, repository metadata, summary, findings, and reported check errors.
Security model
Hammerhead inspects the target working tree without running its build scripts, package managers, hooks, or binaries. SafeWalker uses guarded file reads and symlink containment checks relative to the target root.
Default traversal limits are depth 50 and 100,000 discovered entries. Content reads are bounded at 10 MiB. Common generated/dependency directories and .git are excluded. These are defense-in-depth measures, not a sandbox.
Limitations
- Scans the current working tree, not Git history.
- Matches supported credential patterns; does not validate active credentials.
- No CVE/dependency database scanning or semantic SAST analysis.
- Does not unpack archives. Binary and oversized content is outside normal secret-content inspection.
- Exclusions, unreadable files, partial traversal, and check failures can limit coverage.
Command help
Audit inspects the target directory for security risks including
sensitive files, credential exposure, and repository hygiene issues.
By default, the exit code is non-zero if any HIGH or CRITICAL findings
are detected. Use --fail-on to change this threshold.
Usage:
hammerhead audit [path] [flags]
Flags:
-e, --exclude stringArray Exclude paths matching pattern (repeatable)
--fail-on string Minimum severity for non-zero exit: critical, high, medium, low, info, none (default "high")
-h, --help help for audit
--max-file-size string Override large file threshold for FILE-002 (e.g. 50MB, 10MB)
-o, --output string Output format: terminal, json (default "terminal")
-q, --quiet Quiet mode: print compact findings without decorative banners