Skip to main content

CLI Reference

Basic Usage​

skylos <path> [options]

This form scans source code. The <path> argument can be a directory (scanned recursively) or one file. A bare skylos or skylos --help opens the command chooser; skylos <path> --help shows source-scan flags.

Choose The Command By Its Input​

QuestionCommandInput Skylos reads
What problems are in this source tree?skylos <path>Source and project configuration; dead code by default, every main source analyzer with -a
What AI-code mistakes are in this source?skylos verify [path]The selected source target, plus a separate Git HEAD behavior comparison for supported Python working changes
Will this exact local GPU build fit the declared fleet?skylos preflight [ARTIFACT]A local built artifact plus .skylos/gpu-targets.yml or .yaml; OCI input is identity-only in the CLI
What vulnerabilities are in this container?skylos image scan IMAGE@sha256:<digest> --platform os/archA remote registry image scanned through separately installed Trivy
What does the combined repo report contain?skylos suite [DIRECTORY]Static analysis, technical debt, AI defense, and provenance
Does an agent implementation have deployment guardrails?skylos defend [DIRECTORY]Recognized Python and TypeScript/JavaScript LLM integrations
Which Python dead code can Skylos remove?skylos clean [path] --dry-runPython import/function cleanup candidates; --dry-run never writes

The three similarly placed checks have different inputs: verify scans source and separately models supported Python working changes, preflight statically inspects a local built GPU artifact, and image scan asks Trivy to inspect a remote registry image. Optional paths default to the current directory; suite and defend require a directory. Run skylos commands for the installed command-family map.

Commands​

Top-Level Command Map​

This table maps the active top-level families. Run skylos commands for the installed family map and skylos <family> --help for its real parser options.

CommandPurpose
skylos PATH [PATH ...]Scan source; dead code by default, every main source analyzer with -a
skylos suite [DIRECTORY]Build one static, debt, defense, and provenance report
skylos verify [path]Scan source for AI-code mistakes and separately model supported Python working changes
skylos preflight [ARTIFACT]Check an exact local built GPU artifact against its fleet; OCI is UNKNOWN in the CLI
skylos clean [path]Preview or apply Python import/function cleanup
skylos review [path]Record and manage local finding decisions
skylos baseline [path]Save the current finding baseline
skylos debt [path]Rank technical-debt hotspots and trends
skylos lint [RUFF_ARGS ...]Forward arguments to ruff check
skylos sbom [path]Export supported dependency inventory as CycloneDX JSON
skylos discover [path]Inventory recognized Python and TypeScript/JavaScript LLM integrations and tools
skylos defend [DIRECTORY]Report static guardrails; threshold flags or policy make it a gate
skylos image scan ...Ask installed Trivy to scan a pinned remote image for vulnerabilities
skylos ingest <trivy|claude-security>Normalize findings from an external tool
skylos compare [path] --against REPORTCompare Skylos with an incumbent report
skylos provenance [path]Detect AI-authored code in PR changes
skylos agent <command>Run LLM review, Deep Mode, remediation, behavior tests, or agent-state workflows
skylos cicd <command>Generate or run CI gates, annotations, and PR review output
skylos rules <command>Initialize, validate, list, install, or remove rule packs
skylos contract <command>Initialize, validate, or inspect AI hallucination contracts
skylos cache <clear|stats>Clear or measure cached run data
skylos whitelist [pattern|--show]Manage symbol whitelist patterns
skylos sonar import [properties_file]Create a Skylos migration plan from Sonar properties
skylos initInitialize project configuration
skylos doctorCheck installation and language-engine health
skylos badgePrint README badge Markdown
skylos login, whoami, project, syncManage the optional Cloud connection and project
skylos key, creditsManage provider keys and view Cloud credits
skylos commands, tourShow the command map or guided capability tour

skylos run and skylos city are removed compatibility names and exit 2 with replacement guidance.

skylos init​

Initialize Skylos configuration in the current directory.

skylos init

Creates or appends a [tool.skylos] section to pyproject.toml with default settings.

skylos run (removed)​

skylos run exits with code 2. Use skylos . -a for the main source audit or skylos suite for the combined repository report.

skylos whitelist​

Manage the whitelist for suppressing false positives.

# Add a glob pattern
skylos whitelist 'handle_*'

# Add with reason (recommended for teams)
skylos whitelist my_func --reason "Called via registry lookup"

# View current whitelist
skylos whitelist --show
FlagDescription
--reason, -rAdd reason/documentation for the whitelist entry
--show, -sDisplay all current whitelist entries

Patterns are saved to [tool.skylos.whitelist] in pyproject.toml.

skylos <path>​

Run static analysis on the specified path.

skylos . --danger --quality --ai-defects

skylos verify [path]​

Scan a file, directory, range, or stdin code blob for AI-code trust findings. Add --contract .skylos/ai-contract.yml to enforce repo-specific generated-code truth such as required route decorators or approved phantom-symbol checks. This is the narrow in-loop verifier designed for coding agents and editor hooks, so it returns only AI-specific findings instead of the full dead-code/security report. In full scan JSON, AI-defect checks are grouped under ai_defects rather than quality or danger.

# Verify one file
skylos verify src/app.py

# Verify only the edited range
skylos verify src/app.py --range 40:75

# Scan the project for context, then return findings for one file
skylos verify . --file src/app.py --range 40:75 --project-context

# Let an editor or agent send an unsaved buffer
printf '{"file":"src/app.py","code":"def handler(): pass\n","range":"1:1"}' \
| skylos verify . --stdin --no-fail

For a directory target, the AI-defect analyzer scans that selected tree. Only the separate Python behavior result compares working-tree functions with Git HEAD; it does not narrow all analyzer findings to changed files. Path targets enable dependency hallucination checks by default and may query public package registries. Use --no-dependency-hallucinations to disable those lookups.

On a terminal, the command renders a human report. It emits versioned JSON with tool: "verify_change" when stdout is redirected, when --stdin is used, or to the file selected by --output. That result contains a status, target file/range, and findings shaped for agent consumption:

{
"schema_version": 2,
"tool": "verify_change",
"status": "fail",
"findings": [
{
"rule_id": "SKY-D224",
"vibe_category": "api_signature_hallucination",
"ai_likelihood": "high",
"range": {
"file": "src/app.py",
"start_line": 42,
"start_col": 0,
"end_line": 42,
"end_col": 0
},
"message": "Call uses an API shape that is not present in the installed package.",
"suggested_fix": "Update the call to match the installed package API surface.",
"confidence": 80,
"severity": "HIGH",
"category": "ai_defect"
}
]
}
FlagDescription
--file <path>Target file when the positional path is a project root
--range L1:L2Return findings that overlap a changed line range
--stdinRead a JSON manifest with file, code, and optional range
--project-contextScan the project path and filter to --file
--dependency-hallucinationsInclude package metadata checks for hallucinated dependencies and versions
--no-dependency-hallucinationsDisable dependency checks and package-registry lookups
--contract <path>Apply a specific AI hallucination contract
--no-contractDisable contract discovery and application
--exclude-folder <folder>Add an excluded folder. Can be repeated
--confidence, -cAnalyzer confidence threshold. Default: 60
--no-failExit 0 even when verify findings are returned
--output, -o <file>Write JSON output to a file

Without --no-fail, skylos verify exits 1 for fail and 2 for incomplete. An incomplete result means Skylos could not establish a requested proof; it is not silently treated as a pass.

skylos preflight [ARTIFACT]​

Check one exact local built GPU artifact against the machines declared in .skylos/gpu-targets.yml (or .yaml). This command inspects artifact evidence. It does not review source edits or scan packages for CVEs.

.skylos/gpu-targets.yml
version: 1
targets:
- name: inference-t4
vendor: nvidia
driver: "535.104.05"
compute_capability: "7.5"
platform: "linux/amd64"

Inspect a local file or directory:

skylos preflight build/app

Local version-1 inspection supports Linux ELF/CUDA artifacts and requires a trusted NVIDIA cuobjdump installed outside the project and artifact. Skylos takes private file snapshots and never loads or executes target code.

You may omit ARTIFACT when .skylos/release.json names one project-relative artifact:

.skylos/release.json
{"version": 1, "artifact": "build/app"}

There are no preflight mode flags. The artifact and fleet contract define the check. A valid report is concise on a TTY and schema-version-1 JSON when stdout is redirected. Argument and adapter errors can be plain text and exit 2.

StatusExitMeaning
PASS0The exact identity and every fleet target pass all checks within the declared static scope
FAIL1Artifact evidence proves at least one fleet target incompatible
UNKNOWN2Evidence is missing, ambiguous, unsupported, incomplete, or input is invalid

A digest-pinned OCI reference is accepted as an identity, but this CLI never pulls or starts it and therefore returns UNKNOWN. A trusted library caller can supply digest-bound inspection facts to skylos.preflight.run_preflight.

Version 1 covers exact local identity, Linux ELF platform, selected executable fatbin architecture routes, a static packaged $ORIGIN CUDA runtime route, and documented driver-family compatibility. It does not establish runtime execution, workload correctness, memory demand, performance, nonselected or relocatable fatbins, per-kernel symbol parity, or Windows PE runtime imports. See Release Reliability for the evidence model and library API.

Here, a selected executable fatbin is the executable CUDA record set that cuobjdump --list-elf/--list-ptx selects. Its producer identifier groups the cubin and PTX records that must share a compatibility route. Every observed group needs native cubin coverage for PASS; PTX-only coverage remains UNKNOWN because static inspection does not prove the deployment driver's JIT path. Across checks and targets, FAIL wins over UNKNOWN, and UNKNOWN wins over PASS.

skylos image scan​

Scan a digest-pinned remote registry image for package vulnerabilities. Install Trivy separately as a trusted executable on PATH, and provide registry network access and any required registry credentials:

skylos image scan IMAGE@sha256:<digest> \
--platform linux/amd64 --fail-on high

This command checks CVEs. It does not check CUDA architectures, packaged CUDA runtime binding, or fleet driver compatibility; use skylos preflight for those artifact checks.

Without --fail-on, vulnerability findings are report-only and a completed scan exits 0. With --fail-on LEVEL, findings at or above that severity exit 1. Scanner or report incompleteness exits 2.

skylos suite [DIRECTORY]​

Build one repository report from static analysis, technical debt, agent defense, and provenance. DIRECTORY defaults to the current directory; a file target is rejected.

skylos suite
skylos suite . --json -o suite.json

Use skylos <path> when you need only the source scan and its analyzer flags. Suite runs in the local process and uploads only with --upload, but its SCA and AI dependency stages may query OSV.dev and public package registries. Findings are report-only and do not change the default 0 exit. Operational, output, upload, and uploaded Cloud quality-gate failures are nonzero.

skylos defend [DIRECTORY]​

Inspect recognized LLM integrations in Python and TypeScript/JavaScript source, score their deployment guardrails, and optionally emit evidence or gate by severity. DIRECTORY defaults to the current directory; files are rejected.

skylos defend .
skylos defend . --format md -o evidence.md
skylos defend . --fail-on critical

defend checks the implementation of an AI agent. It does not validate the current code edit like verify, inspect a built GPU artifact like preflight, or exercise a running endpoint like skylos agent test. See Agent Verification.

Findings are report-only and exit 0 unless --fail-on, --min-score, or an explicit policy requests a gate. Upload and requested gate failures exit 1. If no supported integration is detected, the empty result does not prove that an unsupported or unrecognized implementation has guardrails.

skylos debt [path]​

Analyze technical debt hotspots for the specified path.

skylos debt .
skylos debt . --changed
skylos debt . --baseline
skylos debt . --show-history

Use this command when you want a debt hotspot report instead of the normal dead-code/security/quality output.

FlagDescription
--jsonOutput machine-readable debt results
--output, -o <file>Write the debt report to a file
--top <n>Limit the table output to the top N hotspots
--changedShow only hotspots in git-changed files while keeping the debt score project-scoped
--baselineCompare current hotspots against the saved debt baseline
--save-baselineSave the current project debt snapshot as the debt baseline
--historyAppend the current project debt summary to the debt history log
--show-historyShow saved debt history without running a new scan
--history-limit <n>Limit saved history output to the latest N entries
--policy <file>Use a specific skylos-debt.yaml policy file
--min-score <n>Exit 1 if the repo debt score falls below the threshold
--fail-on-status <status>Exit 1 if hotspots with a given baseline status exist
--with-agentUse an LLM to summarize the top static debt hotspots
--agent-top <n>Limit how many hotspots are summarized by the agent
--exclude <dir ...>Exclude additional folders

For the full scoring model and baseline semantics, see Technical Debt.

Source-Scan Output Options​

The flags in this section belong to skylos <path>. Other commands have their own output contracts; in particular, preflight has no output-format flag and emits JSON for valid reports when stdout is redirected.

FlagDescription
--jsonOutput raw JSON to stdout
--llmOutput LLM-optimized report with code context for AI agents (Claude Code, Codex, etc.)
--format FORMATSelect rich, pretty, json, llm, github, gitlab, or concise output. concise prints IDE-clickable file:line RULE_ID message findings.
--output, -o <file>Write results to a file
--treeDisplay findings in a hierarchical tree format

Concise IDE-Friendly Output​

Use concise output when you want terminal, editor, or test-script output without the banner, tables, progress text, CI tips, or Cloud CTA:

skylos --format concise src/test.py
src/test.py:1  SKY-D001  Unused function: helper
src/test.py:5 SKY-D003 Unused class: LegacyClient

Clean scans print nothing and exit 0. Scans with findings exit 1 unless --force is used.

Finding Filters​

FlagDescription
--severity LEVELShow findings at or above critical, high, medium, or low
--category CATShow one or more comma-separated categories: security, reliability, secret, quality, ai_defects, dead_code, or dependency
--select RULEReport exact rule IDs, case-insensitively. Repeat the option or use commas; required analyzer families are enabled automatically
--file-filter PATTERNShow findings whose file contains the given substring
--limit NLimit displayed findings per category while retaining a summary of the remainder

--severity, --category, --file-filter, and --limit filter presentation. --select is different: it both enables the matching analyzer family and restricts results to exact rule IDs. Unknown IDs are configuration errors and exit 2.

# Gate only GPU source/build intent
skylos . --select SKY-GPU001,SKY-GPU002,SKY-GPU003 --gate --format concise

GPU leaf rules require a valid release contract. Selecting SKY-GPU001, SKY-GPU002, or SKY-GPU003 automatically retains prerequisite SKY-GPU000, so a missing or malformed contract remains visible and the gate cannot pass open.

Analysis Flags​

FlagDescription
--dangerEnable security plus deployment/runtime contract scanning. Non-security deployment and GPU results are reported under Reliability
--secretsEnable API key and secret detection
--qualityEnable code quality checks (complexity, nesting, etc.)
--ai-defectsEnable evidence-backed AI defect checks such as phantom references, hallucinated APIs, impossible dependency versions, weakened test assertions, test-impact gaps, CI privilege expansion, and CLI surface drift
--traceRun tests with call tracing to capture dynamic dispatch (visitor patterns, getattr, plugins)
--confidenceConfidence threshold (0-100). Lower values include more uncertain findings. Default: 60

Reliability has no separate broad analysis flag. Use --danger (or -a) to run deployment/runtime contract analyzers, or use --select to enable exact Reliability rules. Use --category reliability only when you want to hide other categories from the displayed result.

See Release Reliability for Kubernetes exposure, GPU source/build intent, and exact built-artifact preflight.

Reference Graph Cache​

Skylos has a persistent reference graph cache format at:

.skylos/index/v1/reference_graph.json

The cache stores file signatures, definitions, references, imports, and reverse dependencies keyed by content hash. Index-aware verifier and agent paths can reuse unchanged graph entries and conservatively invalidate changed files plus their direct dependents.

You should normally gitignore .skylos/index/. It is safe to delete; Skylos will rebuild cache payloads when an index-aware path writes them again. The cache does not index symlinks, non-regular files, or very large source files.

Diff Filtering​

FlagDescription
--diff [BASE_REF]Only report findings in lines changed since BASE_REF (e.g. --diff origin/main). Use --diff without a value to auto-detect (GITHUB_BASE_REF or origin/main). Unlike --diff-base which filters at the file level, --diff uses unified diff hunk headers for exact line-range matching.
--diff-base <ref>(File-level) Only report findings in files changed since the given ref.

Example:

# Only show findings in lines your PR touched
skylos . --diff origin/main --danger --quality --ai-defects

# Auto-detect base ref (uses GITHUB_BASE_REF or defaults to origin/main)
skylos . --diff --danger --secrets --quality --ai-defects

For cross-file findings, Skylos also checks related_locations against the changed scope. A finding can therefore remain visible when the PR changes a supporting contract, manifest, source route, build file, or Dockerfile rather than only the finding's primary location. Required fail-closed prerequisites such as SKY-GPU000 are retained for selected leaf rules.

Folder Exclusion​

FlagDescription
--exclude-folder <folder>Exclude a folder from analysis. Can be used multiple times.
--include-folder <folder>Force include a folder that would otherwise be excluded.
--no-default-excludesDo not exclude default folders (__pycache__, .git, venv, etc.)
--list-default-excludesPrint the default excluded folders and exit

Example:

# Exclude tests and migrations, but include venv
skylos . --exclude-folder tests --exclude-folder migrations --include-folder venv

Interactive Mode​

FlagDescription
--interactive, -iInteractively select which findings to act on
--dry-runShow what would be removed without making changes
--comment-outComment out dead code instead of deleting it

Interactive mode requires the inquirer package.

Deterministic Cleanup​

Use skylos clean for Python import and function cleanup. With no mode flag it asks about each candidate and can write files after final confirmation. --dry-run is the guaranteed no-write preview.

# Preview Python import/function cleanup edits without writing files
skylos clean . --dry-run --types import,function --confidence 80

# Apply the same kind of cleanup without prompting
skylos clean . --apply --types imports --confidence 80

# Comment out matches instead of removing them
skylos clean . --apply --comment-out --types import,function --confidence 80
FlagDescription
--dry-runPrint planned edits and write nothing
--applyApply matching cleanup edits without prompting
--confidence <N>Minimum finding confidence; defaults to 80 in noninteractive mode
--types <list>Comma-separated cleanup types; currently import and function
--comment-outComment out matches instead of deleting them

skylos clean uses Python LibCST codemods and path-containment checks. Automatic cleanup currently edits unused imports and unused functions only; classes, variables, other languages, and lower-confidence findings remain review items. The command currently exits 0 after a completed apply pass even if an individual transform failure was printed, so review the completion output.

AI-Powered Features​

FeatureCommandDescription
AI-Powered Analysisskylos agent scan . --model gpt-4.1Hybrid static + LLM analysis with project context
AI Contract Setupskylos contract initCreate .skylos/ai-contract.yml for repo-specific generated-code guardrails
In-Loop Verificationskylos verify . --file src/app.py --range 40:75Fast, machine-readable AI-code trust verdict for changed code
Agent Behavior Contractskylos agent initCreate .skylos/agent-test.yml for runtime response, tool, refusal, and source assertions
Agent Behavior Testskylos agent test --allow-contract-endpointExplicitly allow and test the contract's loopback endpoint
Offline Agent Behavior Testskylos agent test --observations agent-observations.jsonDeterministically evaluate captured typed observations without a network call
Authenticated Remote Agent Testskylos agent test --endpoint https://agent.example/v1/chat/completions --allow-remote --auth-env AGENT_TOKENSelect the remote destination and bearer-token environment variable from the trusted CLI invocation
Bounded Agent Testskylos agent test --max-scenarios 25 --max-seconds 300 --max-tokens 1024Enforce scenario/time budgets and request an endpoint response-token cap
AI Security Scanskylos agent scan . --securitySecurity taskflow audit with repo map, file facts, and verifier-backed evidence
Fix Suggestionsskylos agent scan . --with-fixesAdd suggestions without changing files
Automated Repairskylos agent remediate .Apply supported fixes and re-scan; tests and PR creation are explicit options
PR Reviewskylos agent scan --changedAnalyze only git-changed files
Local LLMskylos agent scan . --base-url http://localhost:11434/v1 --model codellamaUse Ollama/LM Studio (no API key needed)

You can use the --model flag to specify the model that you want. We support Gemini, Groq, Anthropic, ChatGPT and Mistral.

Credits​

skylos credits​

Check your credit balance, plan, and recent transactions.

skylos credits

Output:

[My Org] (pro plan)
Balance: 1,500 credits

Recent activity:
+10000 Purchased 10000 credits (team pack)
-1 Scan upload
-10 AI code remediation

Buy credits: https://skylos.dev/dashboard/billing

Requires skylos login first. See Billing & Credits for pricing.

CI/CD Commands​

skylos cicd init​

Generate a GitHub Actions workflow file for automated scanning.

skylos cicd init
FlagDefaultDescription
--python-version3.12Python version for the workflow
--triggerspull_request pushGitHub event triggers
--analysisdead-code security quality secretsAnalysis types to enable
--no-baselinefalseSkip baseline comparison
--llmfalseInclude LLM-enhanced analysis
--model—LLM model to use with --llm
--uploadfalseInclude --upload step to send scan results to the Skylos cloud dashboard. Requires SKYLOS_TOKEN in repo secrets.
--output, -o.github/workflows/skylos.ymlOutput file path

skylos cicd gate​

Run the quality gate (exit code 0 = pass, 1 = fail). Use in CI to block merges.

skylos cicd gate --input skylos-report.json
FlagDescription
--input, -iRead results from a JSON report file
--strictFail on any issues found
--summaryWrite markdown summary to $GITHUB_STEP_SUMMARY

skylos cicd annotate​

Emit GitHub Actions annotations (inline warnings/errors on PR diffs).

skylos cicd annotate --input skylos-report.json
FlagDescription
--input, -iJSON report file
--maxMaximum annotations (default: 50)
--severityFilter by severity: critical, high, medium, low

skylos cicd review​

Post inline review comments on a pull request via the gh CLI.

skylos cicd review --input skylos-report.json --pr 42
FlagDescription
--input, -iJSON report file
--prPR number (auto-detected in CI)
--repoowner/repo (auto-detected in CI)
--summary-onlyPost only a summary comment, no inline comments
--max-commentsMaximum inline comments (default: 25)
--diff-baseBase branch for diff (default: origin/main)

Cloud & CI Flags​

FlagDescription
--uploadUpload scan results and metadata to Skylos Cloud. Uses SKYLOS_TOKEN, GitHub OIDC, or saved skylos login credentials. Costs 1 credit.
--strictExit with code 1 if quality gate fails (use in CI to block merges)
--force, -fBypass quality gate locally (still uploads if --upload is set)

Cloud uploads are attributed by the resolved auth path. See Authentication and Enterprise Trust for the exact upload attribution and data-handling model.

Runtime Analysis​

FlagDescription
--traceRun pytest with sys.settrace() to record all function calls, reducing false positives from dynamic code

When to Use --trace​

Use --trace when static analysis flags code you know is used:

  • Visitor patterns (visit_FunctionDef called via getattr)
  • Plugin hooks (pytest_configure, pytest_addoption)
  • Dynamic dispatch (getattr(obj, method_name)())
skylos . --trace
note

The .skylos_trace file is saved in your project root. Commit it to skip re-running tests on subsequent scans.

Quality Gate​

skylos <path> --gate [command...]
FlagDescription
--gateRun as a quality gate. Blocks if thresholds for the enabled or selected analyzers are exceeded.

Reliability is evaluated separately from Security and defaults to max_reliability = 0. A bare --gate does not enable every analyzer; combine it with explicit analysis flags or exact --select rules. If the gate passes, Skylos either runs the provided command or launches the deployment wizard. If the gate fails, it shows reasons and (unless strict = true) offers a bypass prompt.

Example:

skylos . --danger --secrets --quality --ai-defects --gate

# Targeted GPU release gate; SKY-GPU000 is retained automatically
skylos . --select SKY-GPU001,SKY-GPU002,SKY-GPU003 --gate

Other Options​

FlagDescription
--versionPrint version and exit
--verbose, -vEnable verbose logging

Exit Codes​

Exact meaning is command-specific; these are the common categories:

CodeMeaning
0Command-specific success; report-only commands can still contain findings
1Findings, a gate/policy decision, or another command-specific analysis or operational failure caused the command to fail
2The invocation, configuration, or input was invalid, or the command could not produce a usable result safely

For example, skylos compare uses 0 for a usable receipt and 2 for an invalid, unsafe, or unusable comparison; it does not use 1. See Scanner Comparison.

Removed Legacy AI Flags​

The main source-scan command no longer accepts --fix or --audit. Use skylos agent scan [path] for LLM-assisted review, skylos agent audit [path] for Deep Mode, and skylos agent remediate [path] when you intend to change files.

Examples​

Basic dead code scan:

skylos .

Full analysis with JSON output:

skylos . --danger --secrets --quality --ai-defects --json -o report.json

Interactive cleanup:

skylos . -i --dry-run

Deterministic cleanup preview and apply:

skylos clean . --dry-run --types imports --confidence 80
skylos clean . --apply --types imports --confidence 80

CI/CD gate that blocks on critical issues:

skylos . --danger --quality --ai-defects --gate

LLM-assisted audit:

skylos agent audit . --changed --model claude-sonnet-4-20250514

Whitelist a dynamic pattern:

skylos whitelist 'handle_*'
skylos whitelist --show