Skip to content

Commands

Global options apply to every command: --format, --output, --severity, --fail-on, --color, --jobs, --exclude, --offline, --no-sandbox, --baseline, --vex, --vex-out, --staged, --diff, -v/-vv.

scan [paths]

Scan local files with the full ruleset set. Defaults to ..

argus scan . --osv --dep-check     # files + dependency advisories + hygiene
argus scan . --include-git         # also read .git internals
argus scan . --diff origin/main    # only files changed vs a ref
argus scan . --staged              # only staged files (pre-commit use)
argus scan . --yara rules/yara     # real YARA evaluation (default build)
argus scan . --iocs iocs.txt       # flat IoC list, one per line

github / gitlab / gitea

Enumerate and scan remote repositories. Pick a scope with --org, --user, or --me (needs a token).

argus github --org Quad4-Software
GITLAB_TOKEN=... argus gitlab --org my-group --host gitlab.example.com
argus github --org my-org --settings     # + org/repo security settings

Filtering: --skip-archived, --skip-forks, --skip-private, --limit, --updated-since, --updated-before, --workdir.

web <url>

Fetch a URL and audit the response: security headers, cookie flags, server disclosure, TLS expiry, exposed /.git, /.env, /.aws/credentials (with SPA-fallback detection), robots.txt, security.txt, and secrets embedded in inline + bundled JavaScript and source maps. --depth N crawls same-origin links (max 30 pages).

image <ref>

Audit a container image through docker or podman: root user, latest tag, baked-in env secrets, secret-looking history entries. --deep exports the filesystem and runs the full rules engine; with --osv it also maps dpkg/apk package lists to advisories.

system

Lynis-class host audit: sysctl hardening, account and file permissions, sshd configuration, risky listeners and services, firewall presence, logging, integrity tooling, home directory modes, and quick malware checks (ld.so.preload, /tmp executables, deleted-but-running binaries).

similar <a> [b]

Code similarity scoring using normalized-token winnowing fingerprints (MOSS/SCANOSS lineage). Two paths print similarity findings for every matching pair; one path finds near-duplicate pairs inside it. Tokenization normalizes identifiers and literals, so renaming does not hide copying. SIM-001 (jaccard over 70%) marks likely vendored code, SIM-002 marks embedded copies inside larger files.

argus similar file.rs other.rs         # pair score
argus similar src/                     # near-dups inside the tree
argus scan . --similar /opt/reference  # flag files copied FROM the reference

verify [paths]

Extract provider-shaped tokens from scan paths and ask the provider whether each is still valid. Live credentials report as critical (VER-001); dead ones as info (VER-002). Tokens are masked in output and capped at 25 checks per run.

fix [paths]

Dry-run remediation. Without --write it prints before/after edits.

  • Workflows: pin mutable uses: refs to commit SHAs (tag kept as a comment), inject a top-level permissions: {} when missing.
  • --containers: inject USER before CMD/ENTRYPOINT, pin FROM digests (via crane/skopeo/docker/podman), add no-new-privileges to compose services lacking it.

license [paths]

Detect the project license, compare it with manifest fields, and with --deps check dependency licenses against a copyleft list.

publish [path]

Scan only what a package would actually ship: npm pack --dry-run, cargo package --list, or git ls-files as fallback. Catches secrets and internal files that tree scans never notice.

sbom [path]

Emit a CycloneDX 1.5 SBOM extracted from lockfiles.

authors [paths]

Commit-author identity analysis plus optional watchlist checks.

ai [paths]

Evidence-tiered AI-provenance report: agent trailers, agent config files, volume velocity, history integrity, provenance laundering, and human-agency counter-evidence. Output is a score with named evidence, never a bare verdict.

roam

Search remote forges for repositories matching a topic or code pattern and scan them.

watch / daemon

Continuous monitoring. watch polls git ls-remote plus optional RSS/Atom feeds; daemon adds an HTTP control plane and signed webhooks (/healthz, /report, /state, /scan, /webhook/{github,gitlab,gitea}). Pushes rescan only the changed files, diff the dependency set (added/removed/version-changed), and with --dep-watch alert on registry maintainer changes.

init

Install a pre-commit hook running argus scan --staged --fail-on medium. --force overwrites an existing hook.

mcp

Stdio JSON-RPC server exposing scan, scan_system, and list_rules for MCP clients.

rules / rules-update / completions

rules lists loaded rulesets and rules; rules-update --feed <git-url> pulls a rules repo into ~/.config/argus/rules; completions <shell> prints shell completions.