Talarurus

HAMMERHEAD / V0.1.0 DOCUMENTATION

Start with a local audit.

Commands, reporting, and boundaries for the v0.1.0 CLI.

Quick start

With the v0.1.0 executable on your PATH, verify the installed version:

hammerhead version

Audit the current working tree:

hammerhead audit .

Write structured JSON:

hammerhead audit . --output json > audit.json

Use --quiet for compact finding lines. Quiet mode omits the summary.

Reports and exit status

The default failure threshold is high. Security findings alone affect finding-based failure; Hygiene and Info do not.

  • 0: No Security finding reached the selected threshold.
  • 1: At least one Security finding reached the selected threshold.
  • 2: CLI or operational failure, such as an invalid target or flag.

Check errors can be recorded while other checks continue. They do not automatically force status 2. A successful threshold result is not a guarantee of safety or complete coverage.

JSON uses schema hammerhead/v0.1. Reports include version, repository metadata, summary, findings, and reported check errors.

Security model

Hammerhead inspects the target working tree without running its build scripts, package managers, hooks, or binaries. SafeWalker uses guarded file reads and symlink containment checks relative to the target root.

Default traversal limits are depth 50 and 100,000 discovered entries. Content reads are bounded at 10 MiB. Common generated/dependency directories and .git are excluded. These are defense-in-depth measures, not a sandbox.

Limitations

  • Scans the current working tree, not Git history.
  • Matches supported credential patterns; does not validate active credentials.
  • No CVE/dependency database scanning or semantic SAST analysis.
  • Does not unpack archives. Binary and oversized content is outside normal secret-content inspection.
  • Exclusions, unreadable files, partial traversal, and check failures can limit coverage.

Command help

Audit inspects the target directory for security risks including
sensitive files, credential exposure, and repository hygiene issues.

By default, the exit code is non-zero if any HIGH or CRITICAL findings
are detected. Use --fail-on to change this threshold.

Usage:
  hammerhead audit [path] [flags]

Flags:
  -e, --exclude stringArray    Exclude paths matching pattern (repeatable)
      --fail-on string         Minimum severity for non-zero exit: critical, high, medium, low, info, none (default "high")
  -h, --help                   help for audit
      --max-file-size string   Override large file threshold for FILE-002 (e.g. 50MB, 10MB)
  -o, --output string          Output format: terminal, json (default "terminal")
  -q, --quiet                  Quiet mode: print compact findings without decorative banners

Report vulnerabilities privately.