CLI

Scan your apps and check findings from the terminal.

Install

# Install globally
npm install -g attackerview

# Or run without installing
npx attackerview

Requires Node.js 18 or later.

Authentication

Pass your API key as a flag or set it as an environment variable. You can create API keys from your dashboard settings (Watchtower plan).

# As a flag
attackerview scan example.com --api-key avk_your_key_here

# As an environment variable (recommended for CI)
export ATTACKERVIEW_API_KEY=avk_your_key_here
attackerview scan example.com

The environment variable takes effect when --api-key is not provided.

Scan command

attackerview scan <target>

Triggers a scan, polls until completion, and prints findings. The target can be a hostname (example.com) or a full URL (https://staging.example.com:8443). The domain must already exist in your account.

Flags

FlagDefaultDescription
--api-keyAPI key. Falls back to ATTACKERVIEW_API_KEY env var.
--compareSet to previous for scan-to-scan diff.
--fail-oncritical,highComma-separated severity levels that cause exit code 1. Options: critical, high, medium, low.
--formattextOutput format: text or json.
--wait-timeout300Max seconds to wait for scan completion.
--quietSuppress progress output.
--no-colorDisable colored output.

Example output

$ attackerview scan staging.example.com --compare previous

Scan: staging.example.com
Status: completed
Scan ID: clx_abc123

Findings Summary
  CRITICAL: 1
  HIGH: 2
  MEDIUM: 3

Changes (vs. previous scan)
  +1 new
    HIGH Missing HSTS header
  1 regressed
    MEDIUM TLS certificate expiring soon
  -2 fixed

View results: https://attackerview.com/app/d/staging.example.com

Findings command

attackerview findings <target>

Fetches all findings for a domain. Paginates automatically and prints the full list.

Flags

FlagDefaultDescription
--api-keyAPI key. Falls back to ATTACKERVIEW_API_KEY env var.
--statusFilter by status: open, fixed, or accepted.
--severityFilter by severity: critical, high, medium, low.
--fail-oncritical,highComma-separated severity levels that cause exit code 1.
--formattextOutput format: text or json.
--no-colorDisable colored output.

Example

$ attackerview findings example.com --status open --severity high

3 findings

  HIGH Missing HSTS header
    security-headers-hsts | Security Headers
  HIGH No DMARC record found
    dmarc-missing | Email Security
  HIGH SPF allows all senders
    spf-too-permissive | Email Security

View all: https://attackerview.com/app/d/example.com?section=issues

Exit codes

CodeMeaningWhen
0PassScan completed with no findings above your threshold.
1FindingsFindings matched your --fail-on threshold.
2ErrorSomething went wrong (bad API key, network error, timeout).

Gate logic

How exit code 1 is determined depends on whether you use --compare previous:

  • With diff (--compare previous): fails if there are new findings above your --fail-on threshold OR any regressed findings (regardless of severity).
  • Without diff (default): fails if any open findings match your --fail-on severities.

This means --compare previous is more useful in CI: it only fails the build when something gets worse, not when pre-existing issues are present.

CI/CD usage

Set your API key as a secret in your CI provider, then run the scan as a build step.

# Generic CI example
export ATTACKERVIEW_API_KEY="$AV_API_KEY"

npx attackerview scan staging.example.com \
  --compare previous \
  --fail-on high \
  --quiet

# Exit code 0 = pass, 1 = findings, 2 = error
if [ $? -eq 1 ]; then
  echo "New or regressed findings detected"
  exit 1
fi

Use --format json to pipe results into other tools. Use --quiet to suppress the progress spinner in non-interactive environments.

See also

  • API Reference - Full endpoint documentation for programmatic access.
  • GitHub Action - Native GitHub integration with PR comments and SARIF output.