@kelp-security/cli
v0.16.0
Published
Kelp — security scanner for vibe-coded apps. Standalone CLI.
Maintainers
Readme
kelp — CLI
Standalone command-line entry point for Kelp. Runs the same
detection engine (@kelp/core) as the hosted app and the GitHub Action, so
what you see locally is what CI would see.
Install
npx @kelp-security/cli scan ./my-appOr install globally:
npm install -g @kelp-security/cli
kelp scan ./my-appUsage
kelp scan <path> [options]
OPTIONS
--json Emit findings as JSON on stdout
--severity <sev> Only show findings at or above <sev>
(critical|high|medium|low)
--no-color Disable ANSI colors (NO_COLOR also works)
--help, -h Show help
--version, -v Print versionExamples
# Scan a local project
kelp scan ./my-app
# Machine-readable output
kelp scan ./my-app --json > findings.json
# Only gate on high+critical
kelp scan . --severity highExit codes
| Code | Meaning |
|---|---|
| 0 | Scan completed, no findings above the severity floor |
| 1 | Scan completed, at least one finding above the floor |
| 2 | Scan itself failed (bad path, unreadable target, etc.) |
Use 1 to gate a CI job:
kelp scan . --severity high || exit 1What gets scanned
The walker skips the well-known noise directories (node_modules, .git,
dist, build, .next, vendor, __pycache__, .venv, target,
coverage), lockfiles, sourcemaps, and minified bundles. Everything else is
handed to the scanner, which then applies its own path filters.
Files larger than 1 MB are skipped so a stray CSV dump doesn't stall the scan.
What's detected
The v0.1 CLI runs the secret scanner from @kelp/core:
- Provider patterns for AWS, GCP, Stripe, Supabase, GitHub, Slack, OpenAI, and
more (see
packages/core/src/scanners/secrets.ts). - Entropy fallback for high-entropy quoted strings not caught by a pattern.
- Client-side severity bump — a secret shipped to every visitor is more dangerous than one in server code.
Secret values themselves never leave the scanner boundary: findings carry a
masked preview (sk_live_…) only.
RLS, edge-function, and BOLA scanners live in @kelp/core too and will land
in the CLI progressively — see the roadmap issue.
MCP server
Kelp also ships as an MCP server for LLM clients (Claude Code, Claude Desktop, Cursor):
kelp mcpAdd it to your client's MCP config so the LLM can call scan_path, scan_snippet, list_rules, explain_finding, and explain_rule on its own, and surface /kelp:review-repo / /kelp:harden-file as slash commands. Full guide in docs/MCP.md.
Docs
License
MIT — see LICENSE.
