Rafter CLI
A security CLI for coding agents: secret scanning, command policies, pre-commit hooks, third-party skill auditing
Medium risk
We rate an entry medium when the tool runs code, makes network calls or reads project files. Check what exactly it does before installing.
Why this level
- Reads project files and git history, installs hooks and writes config into the repository
- Routes and executes shell commands through a policy layer, and uploads the repository to the API when remote analysis is used
Install
In your terminal, with SkillFoxx CLI
npx skillfoxx add cli/rafter-cliDetects the agents on your machine, checks the risk and pins the version.
Other ways to install
Assembled automatically, review before installing.
Install the tool
npm install -g @rafter-security/cliInstall Rafter: npm install -g @rafter-security/cli (or pip install rafter-cli). Then run rafter agent init --all for integrations and rafter secrets . to scan. To use it as an MCP server run rafter mcp serve.
Other ways from the author
npm install -g @rafter-security/cliFull feature set, including the local toolkit and MCP server.
This is third-party code. Review the repository files before installing.
What it does
Rafter puts a set of local security checks behind one command for projects where a coding agent works alongside you. It scans for secrets using built-in patterns and your own rules from .rafter.yml, installs a pre-commit hook that blocks a commit carrying a leak, and routes shell commands through a risk layer that refuses destructive ones. Separately it reviews third-party skills before install, flagging embedded secrets, external URLs, dangerous commands and obfuscation. Local features run offline, with no key and no account, and output is strict JSON with stable exit codes so scripts and CI can consume it. It also ships a built-in MCP server and an optional remote code analysis over the Rafter API.
Who it is for. For developers and devops engineers who run coding agents and want secrets, commands and third-party skills kept in check.
Good fit when
- You need to scan a project or git history for leaked secrets and add a blocking pre-commit hook
- You want to route the agent's commands through a policy and deny destructive ones
- You need to review a third-party skill or extension before installing it
Not a fit when
- You need a full SAST or DAST product rather than fast local checks
- Your project has nothing to do with coding agents and existing security tooling is enough
Example request
Scan the project for secrets and set up a pre-commit hook that blocks a commit with a leakLimitations
The local toolkit runs offline and free, with no account. Remote code analysis is a separate feature: it needs a RAFTER_API_KEY, a rafter.so account and sends the repository to the Rafter API, and that service's reachability from Russia without a VPN is untested. Enhanced secret scanning pulls the third-party Betterleaks engine, otherwise the built-in set of 21-plus patterns is used. The Python package needs Python 3.10 or newer.
How to disable. Remove the global package: npm uninstall -g @rafter-security/cli or pip uninstall rafter-cli. Remove the repo hook with rafter agent uninstall-hook, and turn off per-agent integrations with rafter agent disable.
Security check
- Reads project files and git history, installs hooks and writes config into the repository
- Routes and executes shell commands through a policy layer, and uploads the repository to the API when remote analysis is used
README in short
The README splits Rafter into two layers: a free local toolkit with no account and an optional remote analysis over an API. Locally it is a secret scanner with stable output and exit codes, pre-commit and pre-commit-framework hooks, a command policy layer with risk tiers, third-party skill auditing, a hash-chained event log and configuration via .rafter.yml. The package installs from npm or PyPI, ships a GitHub Action and a built-in MCP server exposing scan_secrets, evaluate_command, read_audit_log and get_config. Claude Code, Codex, Gemini, Cursor, Windsurf and other environments connect through skills or MCP. MIT licensed.
FAQ
Do I need an account, and does code leave my machine?
For local features no: secret scanning, hooks, policies and skill auditing run offline without a key. Code leaves only when you explicitly use remote analysis, and is deleted after the run.
How do I review a third-party skill before installing it?
Run rafter skill review with a path or a shorthand like github:owner/repo. The quick scan flags secrets, external URLs, dangerous commands and obfuscation, each with file and line.
Related
A code security audit skill by Cloudflare: the agent runs recon, coverage-led hunting and independent verification of findings, then produces a structured repor
NVIDIA's open stack for running OpenClaw, Hermes and LangChain Deep Agents in OpenShell sandboxes with network policy and managed inference
Security scanner for agent skills and MCP servers: finds prompt injection, data exfiltration and supply chain risks before install
Static code analysis with rules that look like source code, plus a built-in MCP server for AI agents