Guide · 3 min
Scan from the terminal
Run XploitScan on your own machine. Without an account or an ANTHROPIC_API_KEY, no code leaves it. If you sign in, each finding (with a few surrounding lines of code) is sent to your dashboard, and if you set ANTHROPIC_API_KEY, code is sent to Anthropic for AI review. The CLI is the same engine the web scanner uses, just running on your own machine. Best for developers and anyone working in a terminal already.
Run the CLI with npx
You don't need to install anything globally. npx downloads and runs the latest version on demand. Make sure you have Node 20.11 or later.
npx xploitscan@latest scan .
Run this from inside the folder you want to scan. The first run downloads the CLI; subsequent runs are instant.
Read the output
You should see something like this in your terminal:
xploitscan — security scan results
────────────────────────────────────────
Found 13 issues: 7 CRITICAL | 3 high | 1 medium | 2 low
Scanned 47 files in 2.3s
CRITICAL [VC005] Unprotected Stripe Webhook
server.js:39
Attackers can fake payment events and mark
orders as paid without actually paying.
Fix: Use stripe.webhooks.constructEvent()Each finding has a severity, a rule ID (VC###), the file:line, what an attacker can do, and a one-line fix.
Connect your account (optional)
Without signing in, scans run locally with the 30 free rules. Signing in connects your plan — paid plans scan with all 223 rules, and your scan history syncs to your dashboard:
npx xploitscan@latest auth login
Opens a browser tab to complete the OAuth flow. Tokens are stored in your home directory.
Block bad commits (recommended)
Install a git pre-commit hook so XploitScan runs automatically before every commit. The commit aborts if it finds critical issues.
npx xploitscan@latest hook install
Safe to run on a repo with an existing pre-commit hook — XploitScan appends itself between markers and won't overwrite your existing checks. Uninstall any time with npx xploitscan@latest hook uninstall.
Useful flags
A few flags that come up a lot:
npx xploitscan@latest scan ./src --format json > scan.json
npx xploitscan@latest scan . --format sarif > xploitscan.sarif
npx xploitscan@latest scan . --diff main
npx xploitscan@latest scan . --no-ai
JSON for piping into custom tools, SARIF for the GitHub Security tab,--diff to scan only files changed vs a base branch,--no-ai to skip the AI analysis pass (it only runs when ANTHROPIC_API_KEY is set; unset that key to keep all code local).
Troubleshooting
“Command not found: npx”
You don't have Node installed. Install Node 20.11 or later from nodejs.org.
“Exit code 1”
This is intentional — the CLI exits 1 when it finds critical or high-severity issues so CI pipelines can gate on them. It is not an error. Medium and below never change the exit code.
“Scan returns 0 findings” on a project you know has issues
Make sure you're scanning the source folder, not a build output. Try
npx xploitscan@latest scan ./srcexplicitly.
Now wire it into your CI so every PR gets scanned automatically.
Next: Add the GitHub Action →