CLI¶
guardlayer exits with code 1 when a check fails (scan at --fail-on, default block; tool-call at review),
so it composes in scripts and CI. --preset NAME and --config FILE apply to every command.
This page is generated from the CLI's own --help.
guardlayer¶
usage: guardlayer [-h] [--version] [--config CONFIG] [--preset PRESET]
{scan,tool-call,batch,eval,canary,rules,presets,audit,evidence,policy,hook,serve}
...
Input/output security filtering for LLM and agent applications.
positional arguments:
{scan,tool-call,batch,eval,canary,rules,presets,audit,evidence,policy,hook,serve}
scan Scan a piece of text.
tool-call Check an agent tool call against the tool policy and
scanners.
batch Scan a JSONL file of {text, direction} records.
eval Evaluate on a labelled JSONL dataset (default: bundled
sample).
canary Embed a canary token in a prompt.
rules List built-in heuristic and tool rules.
presets List security presets and their residual risk.
audit Tamper-evident audit log tools.
evidence Control-mapped compliance evidence from an audit log.
policy Check a configuration: what GuardLayer assumes about
each tool, and gaps.
hook Run as an agent hook (reads the event JSON on stdin).
serve Run the REST API.
options:
-h, --help show this help message and exit
--version show program's version number and exit
--config CONFIG TOML/JSON config file.
--preset PRESET Security preset: observe, balanced, strict or airgap.
guardlayer scan¶
usage: guardlayer scan [-h] [--direction {input,output,context}]
[--system-prompt SYSTEM_PROMPT] [--json]
[--fail-on {flag,review,block}]
[text]
positional arguments:
text Text to scan (reads stdin if omitted).
options:
-h, --help show this help message and exit
--direction {input,output,context}
--system-prompt SYSTEM_PROMPT
System prompt (enables leak detection on outputs).
--json Emit the full result as JSON.
--fail-on {flag,review,block}
Verdict that yields exit code 1.
guardlayer tool-call¶
usage: guardlayer tool-call [-h] [--json] [--fail-on {flag,review,block}]
tool [arguments]
positional arguments:
tool Tool name, e.g. bash or http_get.
arguments Arguments as JSON (or a plain string); reads stdin if
omitted.
options:
-h, --help show this help message and exit
--json Emit the full result as JSON.
--fail-on {flag,review,block}
Verdict that yields exit code 1.
guardlayer batch¶
usage: guardlayer batch [-h] [--fail-on {flag,review,block}] path
positional arguments:
path
options:
-h, --help show this help message and exit
--fail-on {flag,review,block}
guardlayer eval¶
usage: guardlayer eval [-h] [--positive {flag,block}] [--json] [path]
positional arguments:
path
options:
-h, --help show this help message and exit
--positive {flag,block}
Minimum verdict counted as a detection.
--json
guardlayer canary¶
usage: guardlayer canary [-h] [--echo] prompt
positional arguments:
prompt
options:
-h, --help show this help message and exit
--echo Goal-hijack mode: ask the model to echo the token.
guardlayer audit verify¶
usage: guardlayer audit verify [-h] [--public-key PUBLIC_KEY]
[--expected-head EXPECTED_HEAD]
path
positional arguments:
path
options:
-h, --help show this help message and exit
--public-key PUBLIC_KEY
Ed25519 public key (PEM) to verify signatures with.
--expected-head EXPECTED_HEAD
A head hash recorded earlier, to detect a truncated
log.
guardlayer audit keygen¶
usage: guardlayer audit keygen [-h] prefix
positional arguments:
prefix
options:
-h, --help show this help message and exit
guardlayer evidence export¶
usage: guardlayer evidence export [-h] [--format {summary,jsonl,csv}]
[-o OUTPUT] [--framework FRAMEWORK]
[--public-key PUBLIC_KEY]
[--expected-head EXPECTED_HEAD]
[--allow-unverified]
path
positional arguments:
path
options:
-h, --help show this help message and exit
--format {summary,jsonl,csv}
-o OUTPUT, --output OUTPUT
Write to this file instead of stdout.
--framework FRAMEWORK
Limit to a framework (repeatable); see `evidence
controls`.
--public-key PUBLIC_KEY
Ed25519 public key (PEM) to verify signatures with.
--expected-head EXPECTED_HEAD
A head hash recorded earlier, to detect a truncated
log.
--allow-unverified Export even if the log fails verification (marked in
the pack).
guardlayer evidence controls¶
guardlayer hook claude-code¶
usage: guardlayer hook claude-code [-h] [--state-dir STATE_DIR]
[--block-prompts] [--withhold-injections]
[--print-config] [--server]
[--ensure-server] [--port PORT]
[--token-env TOKEN_ENV]
options:
-h, --help show this help message and exit
--state-dir STATE_DIR
Session state directory (default
~/.guardlayer/sessions or GUARDLAYER_STATE_DIR).
--block-prompts Also block user prompts that GuardLayer blocks.
--withhold-injections
Replace a tool result that holds a likely prompt
injection, so Claude never reads it (default: Claude
is warned and the auto-mode classifier is told; the
output stays visible).
--print-config Print the settings.json hooks snippet and exit.
--server Run as a long-running local server for Claude Code's
HTTP hooks (with --print-config: print that setup).
--ensure-server Start the server if it isn't running (a SessionStart
hook).
--port PORT Server port (default: derived from --config and
--preset).
--token-env TOKEN_ENV
Require a bearer token, read from this environment
variable (shared machines).