CLI Reference
Command-line options for Launchsafe
Basic Usage
launchsafe --target <target> [options]Options
--target, -tstringrequired
Target to test. Accepts URLs, repositories, local directories, domains, or IP addresses. Can be specified multiple times.
--instructionstring
Custom instructions for the scan. Use for credentials, focus areas, or specific testing approaches.
--instruction-filestring
Path to a file containing detailed instructions.
--scan-mode, -mstringdefault deep
Scan depth: quick, standard, or deep.
--scope-modestringdefault auto
Code scope mode: auto (enable PR diff-scope in CI/headless runs), diff (force changed-files scope), or full (disable diff-scope).
--diff-basestring
Target branch or commit to compare against (e.g., origin/main). Defaults to the repository's default branch.
--non-interactive, -nboolean
Run in headless mode without TUI. Ideal for CI/CD.
--configstring
Path to a custom config file (JSON) to use instead of ~/.launchsafe/cli-config.json.
Examples
# Basic scan
launchsafe --target https://example.com
# Authenticated testing
launchsafe --target https://app.com --instruction "Use credentials: user:pass"
# Focused testing
launchsafe --target api.example.com --instruction "Focus on IDOR and auth bypass"
# CI/CD mode
launchsafe -n --target ./ --scan-mode quick
# Force diff-scope against a specific base ref
launchsafe -n --target ./ --scan-mode quick --scope-mode diff --diff-base origin/main
# Multi-target white-box testing
launchsafe -t https://github.com/org/app -t https://staging.example.comExit Codes
| Code | Meaning |
|---|---|
| 0 | Scan completed, no vulnerabilities found |
| 2 | Vulnerabilities found (headless mode only) |