Skip to content

CLI

guardlayer exits with code 1 when a check fails (scan at --fail-on, default block; tool-call at review), so it composes in scripts and CI. --preset NAME and --config FILE apply to every command.

This page is generated from the CLI's own --help.

guardlayer

usage: guardlayer [-h] [--version] [--config CONFIG] [--preset PRESET]
                  {scan,tool-call,batch,eval,canary,rules,presets,audit,evidence,policy,hook,serve}
                  ...

Input/output security filtering for LLM and agent applications.

positional arguments:
  {scan,tool-call,batch,eval,canary,rules,presets,audit,evidence,policy,hook,serve}
    scan                Scan a piece of text.
    tool-call           Check an agent tool call against the tool policy and
                        scanners.
    batch               Scan a JSONL file of {text, direction} records.
    eval                Evaluate on a labelled JSONL dataset (default: bundled
                        sample).
    canary              Embed a canary token in a prompt.
    rules               List built-in heuristic and tool rules.
    presets             List security presets and their residual risk.
    audit               Tamper-evident audit log tools.
    evidence            Control-mapped compliance evidence from an audit log.
    policy              Check a configuration: what GuardLayer assumes about
                        each tool, and gaps.
    hook                Run as an agent hook (reads the event JSON on stdin).
    serve               Run the REST API.

options:
  -h, --help            show this help message and exit
  --version             show program's version number and exit
  --config CONFIG       TOML/JSON config file.
  --preset PRESET       Security preset: observe, balanced, strict or airgap.

guardlayer scan

usage: guardlayer scan [-h] [--direction {input,output,context}]
                       [--system-prompt SYSTEM_PROMPT] [--json]
                       [--fail-on {flag,review,block}]
                       [text]

positional arguments:
  text                  Text to scan (reads stdin if omitted).

options:
  -h, --help            show this help message and exit
  --direction {input,output,context}
  --system-prompt SYSTEM_PROMPT
                        System prompt (enables leak detection on outputs).
  --json                Emit the full result as JSON.
  --fail-on {flag,review,block}
                        Verdict that yields exit code 1.

guardlayer tool-call

usage: guardlayer tool-call [-h] [--json] [--fail-on {flag,review,block}]
                            tool [arguments]

positional arguments:
  tool                  Tool name, e.g. bash or http_get.
  arguments             Arguments as JSON (or a plain string); reads stdin if
                        omitted.

options:
  -h, --help            show this help message and exit
  --json                Emit the full result as JSON.
  --fail-on {flag,review,block}
                        Verdict that yields exit code 1.

guardlayer batch

usage: guardlayer batch [-h] [--fail-on {flag,review,block}] path

positional arguments:
  path

options:
  -h, --help            show this help message and exit
  --fail-on {flag,review,block}

guardlayer eval

usage: guardlayer eval [-h] [--positive {flag,block}] [--json] [path]

positional arguments:
  path

options:
  -h, --help            show this help message and exit
  --positive {flag,block}
                        Minimum verdict counted as a detection.
  --json

guardlayer canary

usage: guardlayer canary [-h] [--echo] prompt

positional arguments:
  prompt

options:
  -h, --help  show this help message and exit
  --echo      Goal-hijack mode: ask the model to echo the token.

guardlayer audit verify

usage: guardlayer audit verify [-h] [--public-key PUBLIC_KEY]
                               [--expected-head EXPECTED_HEAD]
                               path

positional arguments:
  path

options:
  -h, --help            show this help message and exit
  --public-key PUBLIC_KEY
                        Ed25519 public key (PEM) to verify signatures with.
  --expected-head EXPECTED_HEAD
                        A head hash recorded earlier, to detect a truncated
                        log.

guardlayer audit keygen

usage: guardlayer audit keygen [-h] prefix

positional arguments:
  prefix

options:
  -h, --help  show this help message and exit

guardlayer evidence export

usage: guardlayer evidence export [-h] [--format {summary,jsonl,csv}]
                                  [-o OUTPUT] [--framework FRAMEWORK]
                                  [--public-key PUBLIC_KEY]
                                  [--expected-head EXPECTED_HEAD]
                                  [--allow-unverified]
                                  path

positional arguments:
  path

options:
  -h, --help            show this help message and exit
  --format {summary,jsonl,csv}
  -o OUTPUT, --output OUTPUT
                        Write to this file instead of stdout.
  --framework FRAMEWORK
                        Limit to a framework (repeatable); see `evidence
                        controls`.
  --public-key PUBLIC_KEY
                        Ed25519 public key (PEM) to verify signatures with.
  --expected-head EXPECTED_HEAD
                        A head hash recorded earlier, to detect a truncated
                        log.
  --allow-unverified    Export even if the log fails verification (marked in
                        the pack).

guardlayer evidence controls

usage: guardlayer evidence controls [-h]

options:
  -h, --help  show this help message and exit

guardlayer hook claude-code

usage: guardlayer hook claude-code [-h] [--state-dir STATE_DIR]
                                   [--block-prompts] [--withhold-injections]
                                   [--print-config] [--server]
                                   [--ensure-server] [--port PORT]
                                   [--token-env TOKEN_ENV]

options:
  -h, --help            show this help message and exit
  --state-dir STATE_DIR
                        Session state directory (default
                        ~/.guardlayer/sessions or GUARDLAYER_STATE_DIR).
  --block-prompts       Also block user prompts that GuardLayer blocks.
  --withhold-injections
                        Replace a tool result that holds a likely prompt
                        injection, so Claude never reads it (default: Claude
                        is warned and the auto-mode classifier is told; the
                        output stays visible).
  --print-config        Print the settings.json hooks snippet and exit.
  --server              Run as a long-running local server for Claude Code's
                        HTTP hooks (with --print-config: print that setup).
  --ensure-server       Start the server if it isn't running (a SessionStart
                        hook).
  --port PORT           Server port (default: derived from --config and
                        --preset).
  --token-env TOKEN_ENV
                        Require a bearer token, read from this environment
                        variable (shared machines).

guardlayer serve

usage: guardlayer serve [-h] [--host HOST] [--port PORT]

options:
  -h, --help   show this help message and exit
  --host HOST
  --port PORT