CLI reference #
Choose what to scan, how to report findings, and when the command should fail. These examples assume LintLang is installed.
Choose an input #
# Recognized agent instructions across a project
lintlang scan --discover .
# Specific configuration files and a directory
lintlang scan config.yaml prompts/
# Additional files alongside discovered instructions
lintlang scan config.yaml --discover .
Paths are relative to your terminal’s current directory. Discovery and directory scans have different selection rules; see what gets scanned.
Choose a report and threshold #
lintlang scan --discover . --format json
lintlang scan --discover . --fail-on fail
lintlang scan --discover . --fail-on review
--format selects terminal, Markdown, JSON, SARIF, or GitLab output. The default is terminal output. --fail-on fail gates HIGH/CRITICAL; --fail-on review also gates MEDIUM. Without a threshold, findings are advisory. Reports and CI gates covers the details.
Select rules and severity #
lintlang scan config.yaml --patterns H1 H3
lintlang scan config.yaml --min-severity high
--patterns selects H1–H7 families, not individual subcodes such as H1.1. Python P1/P2 checks still run on Python inputs. --min-severity filters structural findings before the verdict is calculated.
Use lintlang patterns to list the families, or browse the rule explorer.
Ignore files #
lintlang scan --discover . --exclude 'archive/**'
For repeated use, put exclusion patterns in .lintlangignore at the scanned directory root. These are limited globs relative to that directory, without nested inheritance or full Git-ignore negation semantics. Explicit-file scans do not apply directory exclusions.
Read from stdin #
printf 'Do not stop until done.' | lintlang scan - --stdin-filename AGENTS.md
--stdin-filename supplies a virtual filename for parser selection and report locations. The file is not opened. Use one - input, and do not combine stdin with discovery.
Other workflows #
- Baselines: review existing findings and focus CI on new ones.
- Automatic fixes: preview the supported rewrite before applying it.
- GitHub setup: generate a workflow with
lintlang init. - Instruction preflight: check a present instruction against explicit context.
All scan options #
Show the complete scan help for 0.8.0
usage: lintlang scan [-h] [--discover [ROOT]] [--stdin-filename PATH]
[--allow-empty] [--show-all] [--fix] [--dry-run]
[--backup] [--allow-uninspected]
[--patterns {H1,H2,H3,H4,H5,H6,H7} [{H1,H2,H3,H4,H5,H6,H7} ...]]
[--format {terminal,markdown,json,sarif,gitlab}]
[--no-suggestions]
[--min-severity {critical,high,medium,low,info}]
[--fail-under FAIL_UNDER] [--fail-on {fail,review}]
[--exclude EXCLUDE [EXCLUDE ...]] [--baseline BASELINE |
--write-baseline WRITE_BASELINE]
[files ...]
Scan agent configs and embedded language in Python pipelines. Confidence
explains HERM coverage proxies; it is separate from the structural
PASS/REVIEW/FAIL verdict.
positional arguments:
files Language-bearing inputs: YAML, JSON, text, or Python
(.py uses AST extraction for embedded prompts/pipeline
artifacts; not general Python code linting). Use '-'
exactly once with --stdin-filename to scan one
document from standard input.
options:
-h, --help show this help message and exit
--discover [ROOT] Also scan recognized agent instruction files found
under ROOT (default: '.'): AGENTS.md, CLAUDE.md,
GEMINI.md, SKILL.md, agent.yaml/.yml/.json,
.github/copilot-instructions.md, and *.instructions.md
under .github/instructions/. Symlinks are not
followed; a skipped one is named on stderr. Explicit
inputs still win and are unioned with the discovered
set.
--stdin-filename PATH
Virtual path for the single '-' input. It selects the
parser and supplies the source identity used by
locations, JSON/SARIF output, and baseline matching.
The path is never opened.
--allow-empty Exit 0 when the scan inspected zero files (default:
that is an input error)
--show-all Terminal output: list every finding (default: 5 per
finding code, then a count)
--fix Show and apply the exact supported standalone
verbosity rewrite
--dry-run With --fix, show the exact diff without writing the
file
--backup With --fix, save original bytes as FILE.lintlang.bak
before writing (never overwrite)
--allow-uninspected Report a named file whose tool-like content could not
be inspected as SKIPPED (default: that is an input
error, because a named file that was not read must
never look clean). Also accept a scan in which every
file was SKIPPED.
--patterns, -p {H1,H2,H3,H4,H5,H6,H7} [{H1,H2,H3,H4,H5,H6,H7} ...]
Only check specific structural patterns (default: all)
--format, -f {terminal,markdown,json,sarif,gitlab}
Output format (default: terminal)
--no-suggestions Hide fix suggestions
--min-severity {critical,high,medium,low,info}
Minimum severity for structural findings (default:
info)
--fail-under FAIL_UNDER
Exit with code 1 if quality score is below this
threshold (legacy; prefer --fail-on)
--fail-on {fail,review}
Exit with code 1 on verdict: 'fail' (any
CRITICAL/HIGH) or 'review' (any MEDIUM+). Default: no
exit on verdict.
--exclude EXCLUDE [EXCLUDE ...]
Glob patterns to exclude (e.g., 'CHANGELOG.md'
'docs/**'). Non-prompt files (README, LICENSE, etc.)
are skipped automatically.
--baseline BASELINE Acknowledge exact existing findings from a reviewed
baseline; report new findings
--write-baseline WRITE_BASELINE
Record current findings to a new baseline file without
overwriting an existing file
Low confidence may reflect non-prompt reference material or an undetected
input boundary. Reports explain the detected drivers; JSON includes
herm.confidence_breakdown. Confidence bands use high >=90%, medium >=75%, and
low <75% coverage. Auto-fix supports only a direct standalone 'Don't be
verbose' instruction (also with a curly apostrophe) as the first body line
after a file-leading top-level '# Instructions' heading and blanks. Other
headings, preambles, and malformed scope fail closed. H1/H2 inference,
security negatives, priority rules, and cross-file conflicts remain manual.
--fix accepts one explicit .md, .txt, or .prompt file and terminal output
only.
The full technical reference documents empty inputs, coverage overrides, legacy score gates, and the complete exit contract.