Scan your apps and check findings from the terminal.
# Install globally npm install -g attackerview # Or run without installing npx attackerview
Requires Node.js 18 or later.
Pass your API key as a flag or set it as an environment variable. You can create API keys from your dashboard settings (Watchtower plan).
# As a flag attackerview scan example.com --api-key avk_your_key_here # As an environment variable (recommended for CI) export ATTACKERVIEW_API_KEY=avk_your_key_here attackerview scan example.com
The environment variable takes effect when --api-key is not provided.
Triggers a scan, polls until completion, and prints findings. The target can be a hostname (example.com) or a full URL (https://staging.example.com:8443). The domain must already exist in your account.
| Flag | Default | Description |
|---|---|---|
--api-key | API key. Falls back to ATTACKERVIEW_API_KEY env var. | |
--compare | Set to previous for scan-to-scan diff. | |
--fail-on | critical,high | Comma-separated severity levels that cause exit code 1. Options: critical, high, medium, low. |
--format | text | Output format: text or json. |
--wait-timeout | 300 | Max seconds to wait for scan completion. |
--quiet | Suppress progress output. | |
--no-color | Disable colored output. |
$ attackerview scan staging.example.com --compare previous
Scan: staging.example.com
Status: completed
Scan ID: clx_abc123
Findings Summary
CRITICAL: 1
HIGH: 2
MEDIUM: 3
Changes (vs. previous scan)
+1 new
HIGH Missing HSTS header
1 regressed
MEDIUM TLS certificate expiring soon
-2 fixed
View results: https://attackerview.com/app/d/staging.example.comFetches all findings for a domain. Paginates automatically and prints the full list.
| Flag | Default | Description |
|---|---|---|
--api-key | API key. Falls back to ATTACKERVIEW_API_KEY env var. | |
--status | Filter by status: open, fixed, or accepted. | |
--severity | Filter by severity: critical, high, medium, low. | |
--fail-on | critical,high | Comma-separated severity levels that cause exit code 1. |
--format | text | Output format: text or json. |
--no-color | Disable colored output. |
$ attackerview findings example.com --status open --severity high
3 findings
HIGH Missing HSTS header
security-headers-hsts | Security Headers
HIGH No DMARC record found
dmarc-missing | Email Security
HIGH SPF allows all senders
spf-too-permissive | Email Security
View all: https://attackerview.com/app/d/example.com?section=issues| Code | Meaning | When |
|---|---|---|
| 0 | Pass | Scan completed with no findings above your threshold. |
| 1 | Findings | Findings matched your --fail-on threshold. |
| 2 | Error | Something went wrong (bad API key, network error, timeout). |
How exit code 1 is determined depends on whether you use --compare previous:
--compare previous): fails if there are new findings above your --fail-on threshold OR any regressed findings (regardless of severity).--fail-on severities.This means --compare previous is more useful in CI: it only fails the build when something gets worse, not when pre-existing issues are present.
Set your API key as a secret in your CI provider, then run the scan as a build step.
# Generic CI example export ATTACKERVIEW_API_KEY="$AV_API_KEY" npx attackerview scan staging.example.com \ --compare previous \ --fail-on high \ --quiet # Exit code 0 = pass, 1 = findings, 2 = error if [ $? -eq 1 ]; then echo "New or regressed findings detected" exit 1 fi
Use --format json to pipe results into other tools.
Use --quiet to suppress the progress spinner in non-interactive environments.