Scan from the terminal

Run SafeWeave from your terminal or any CI system with one npx command.

What it is

The SafeWeave command line runs the scanners on your own computer. Your code never leaves your machine.

Who gets it

Everyone. Without an account you get a few free scans with the basic scanners. With your license key, you get every scanner your plan includes, with no limit on scans.

How to use it

You need Node.js 20 or later.

  1. Open a terminal in your project folder.
  2. Set your license key (from the Welcome to SafeWeave page or your email):
export SAFEWEAVE_LICENSE_KEY=your-license-key
  1. Scan the current directory:
npx -y safeweave-mcp scan .

Options

Flag What it does
--format json|sarif|text Output format (default: json). SARIF uploads to GitHub code scanning.
--fail-on critical|high|medium Exit 1 when a finding at this severity or worse exists (default: high).
--no-fail Always exit 0 after a successful scan.
--allow-partial Don't fail when a required scanner could not run.
--scanners sast,secrets,deps Run a subset (still limited to your plan).
--no-report Don't sync finding counts to your dashboard.

In CI

Add .github/workflows/security.yml to your repository, and store your key as a repository secret named SAFEWEAVE_LICENSE_KEY:

name: SafeWeave
on: [push, pull_request]
jobs:
  scan:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
      - uses: actions/setup-node@v4
        with: { node-version: 20 }
      - run: npx -y safeweave-mcp scan . --format sarif --fail-on high > safeweave.sarif
        env:
          SAFEWEAVE_LICENSE_KEY: ${{ secrets.SAFEWEAVE_LICENSE_KEY }}

The same command works in GitLab CI, Jenkins and any system with Node.js. On GitHub you can also use the GitHub Action.

What you'll see

A list of findings with severity, file and line, and a security score. The exit code tells CI whether to fail the build.

Limits

  • Scanning from the terminal sends only severity counts to your dashboard, never findings, file paths or repository names. Add --no-report to send nothing.
  • Vibe-coded app checks run in SafeWeave's cloud scans of your connected repositories, not in the terminal.

If something goes wrong

  • "Unauthorized" or fewer scanners than expected: check that SAFEWEAVE_LICENSE_KEY is set in the same terminal, and that the key is your current one. If you regenerated it or upgraded your plan, use the new key from your email.
  • npx not found: install Node.js from nodejs.org.
  • A scanner could not run: the output says which one. Add --allow-partial to keep the build green while you look into it.