PREVENT · THE HEELER CLI

Heeler security, in your terminal.

One signed binary that catches secrets, vulnerable dependencies, malicious packages, license and package-age violations, insecure code and infrastructure misconfigurations — before any of it is committed. Developers and their AI agents run the same command — on the same policy and intelligence as the Heeler platform — right at the keyboard, not a finding in a queue later.

Code gets written faster than it gets checked.

AI coding agents add dependencies, generate config, and open PRs faster than any human — or any dashboard — can keep up. If the first security check runs in CI or a platform UI, the vulnerable package, bad license, or leaked secret is already committed. Checks have to run where the code is written, when it's written.

01

Agents pull dependencies in bulk

AI agents add and upgrade packages faster than anyone can vet them. A vulnerable or malicious dependency lands in the tree before review even starts.

02

The context lives somewhere else

Security posture sits in a separate platform UI. Developers and their agents don't leave the terminal to go find it — so it doesn't shape the code they write.

03

Once it's committed, you're rotating

A generated config or test file only has to leak a live credential once. The moment it's committed, the secret is in git history — now you're rotating and scrubbing, not preventing.

HOW IT WORKS

Detect locally. Check against Heeler. Gate the commit.

01 · DETECT

Built locally, nothing uploaded

Run heelercli ci and the binary builds a CycloneDX SBOM from your manifests and scans the working tree for secrets — all on your machine. The secret scan needs no Heeler connectivity and no auth; your source never leaves it.

  • heelercli ci detects secrets, vulnerable dependencies, malicious packages, license violations and minimum package-age violations in one pass
  • heelercli sast adds static analysis in the same local pass — taint and heuristic findings in your code, plus Dockerfiles and infrastructure definitions reported under their own iac category
  • heelercli scan-agent-file checks a skill, instruction file or agent bundle for prompt injection and exfiltration before you trust it — and secret scanning runs offline, no auth, no upload
  • Builds a CycloneDX SBOM locally across every ecosystem your repositories use, and installs as a pre-commit hook or a single binary on PATH
02 · CHECK

Checked against Heeler's intelligence

Your policy file decides what fails, and it's the same detection the Heeler platform runs — so the terminal and the platform agree.

  • Vulnerabilities carry exploitability — EPSS, known-exploited, and ransomware signals — not just CVSS
  • One policy file decides what fails — with suppressions that carry a reason and an expiry, so nothing is quietly ignored forever
  • Same detection backend as the Heeler platform, so local and platform results match
03 · GATE

Gate the commit

The result is a standard exit code — 1 on any violation, 0 when clean — plus SARIF for code scanning and a compact format built for AI agents. Run it as a pre-commit hook and it blocks the commit; baseline mode fails only on what the current change introduces.

  • Exit codes plug into any pre-commit framework, IDE, or pipeline
  • SARIF 2.1.0 for code scanning; JSON and an agent-optimized format for everything else

Built for the developer, not the dashboard.

No 200-line JSON dumps, no dashboard round-trip. The CLI returns exactly what's needed to fix a finding — and nothing else.

Findings you can act on

Each finding shows the package, the fixed version to move to, the source manifest, and the full dependency path — plus exploitability: EPSS, known-exploited, and ransomware signals. Secrets come with file, line, and whether the credential is still live — enough to fix without opening a dashboard.

Fits the workflow you have

Standard exit codes, a pre-commit hook that auto-installs the right signed binary, and baseline mode so inherited debt never blocks the person who didn't create it.

Coverage, not just findings

A scan reports how much of the repository it actually resolved. A missing toolchain is silent where it counts — the ecosystem gets skipped and a repository with a known-vulnerable dependency reads as clean. Coverage appears in every output format, not just as a warning on stderr.

Secrets masked in the log

Output shows the first six and last four characters — enough to recognise which credential fired, not enough to rebuild it. The mask is a fixed width so it never reveals length, and anything under fourteen characters is masked entirely. CI logs are broadly readable and long-lived.

Bring the policy you already have

Convert existing Snyk ignore rules into Heeler suppressions in one command, mapping their identifiers to CVEs as it goes. Validate the policy, print the effective version after profile overrides, and test findings against it before it gates anything.

More than a dependency scan

Scan a single agent file or sweep every agent file in the repository as a CI check. Assess a CycloneDX SBOM you already have. Generate threat-modeling artifacts for a service in STRIDE or PASTA, from Heeler's own service decomposition.

WHERE IT FITS

One policy. Every layer of prevention.

Heeler runs the same policy everywhere your code moves, read from one model of your environment in the Context Engine. The CLI is the layer at the keyboard, before commit — it doesn't replace the others, it shares their policy and their findings.

MCP Server & Agent Skills

Inside the AI coding agent, as code is generated.

→
You are here

CLI

In the terminal, before commit.

→
PR guardrails

Native status checks on the pull request, server-side.

→
Autonomous Operations

Routing, tickets, and fixes after merge.

VERIFY THE BINARY

Signed, and verifiable.

A supply-chain tool should hold itself to the standard it enforces. Every release publishes a SHA-256 digest for each archive and a Sigstore attestation for its provenance — so you can check the binary before you run it, and pin the exact release everyone else is running.

A checksum for every archive

Each release asset ships its SHA-256 digest beside it. Compare the two before the binary ever executes.

Signed provenance

A Sigstore attestation accompanies every release and verifies with standard tooling, so you can confirm an archive came from Heeler's own release pipeline.

Pin the release

Install by version tag so every developer and every CI runner get the same binary — then bump one variable to move everyone at once.

Runs where your developers do

macOS on Apple Silicon and Intel, Linux on amd64 and arm64, and Windows. Drop it into a pre-commit hook, a Make target, or a CI runner — the same command in all three.

Install in 60 seconds.

One cosign-signed binary — drop it in your pre-commit hook and your CI. See it on your repos in your first session.