Getting Started
For AI Agents
DeployReady is a single-command CLI that emits machine-readable JSON. That makes it a clean tool for a coding agent to run end to end — scan, read findings, fix, and verify — with no UI in the loop.
TL;DR for the agent
Run
npx deployready@latest analyze . --no-ai --export --json, read deployready-report.json, fix each critical finding, then re-run with --fail-on critical and confirm exit code 0.Copy this into your agent
Paste the prompt below into Claude Code, Cursor, Windsurf, Cline, or any agent with shell access. It installs nothing globally — npx fetches and runs DeployReady on demand.
paste into your agent
Install and run DeployReady on this project, then help me fix what it finds. 1. Run: npx deployready@latest analyze . --no-ai --export --json 2. Parse deployready-report.json. List every finding with severity === "critical" (file, line, title, CWE). 3. For each critical finding, propose a minimal fix as a diff. Apply it only after I approve. 4. Re-run: npx deployready@latest analyze . --no-ai --fail-on critical Confirm the exit code is 0 and the readiness score went up. Rules: - Treat exit code 2 as "gate failed — unresolved critical findings". - Never commit secrets; move them to env vars. - Don't change app behavior beyond the security fix without asking.
What a run looks like
deployready — analyzerunning
~/my-app $
Step 1 — Run a scan
Use the non-interactive analyze subcommand so the agent never hits an interactive menu. Emit both a JSON file (for parsing) and Markdown (for summarizing).
terminal
# scan the current directory, no AI, write report files
npx deployready@latest analyze . --no-ai --export --json
# static-only (skip live localhost testing)
npx deployready@latest analyze . --no-ai --no-dynamic --json
# stream JSON to stdout instead of a file
npx deployready@latest analyze . --no-ai --json --stdoutStep 2 — Parse the findings
Every finding is a structured object. Filter on severity and use fixable to decide what can be auto-fixed.
deployready-report.json
{
"score": 18,
"summary": { "critical": 16, "warning": 0, "info": 0 },
"findings": [
{
"id": "CWE-798",
"severity": "critical",
"type": "hardcoded_secret",
"title": "Hardcoded secret / credential in source",
"file": "app/api/route.ts",
"line": 15,
"owasp": "A02:2021 – Cryptographic Failures",
"fixable": true,
"fix": "Move the value to an environment variable and rotate it"
}
]
}Step 3 — Fix, then verify
- Apply the smallest change that resolves the finding (for a secret: move it to an env var and rotate it — never hard-code a replacement).
- Re-run with
--fail-on criticaland read the exit code to confirm the gate passes. - Don’t change application behavior beyond the security fix without asking the human.
terminal
npx deployready@latest analyze . --no-ai --fail-on critical
echo "exit code: $?" # 0 = clean, 2 = gate failed, 1 = tool errorFlags that matter for agents
| Flag | What it does |
|---|---|
--json | Emit machine-readable JSON (pair with --export or --stdout). |
--export | Write report files to the project directory. |
--no-ai | Run the deterministic checks only — no model, no network. |
--no-dynamic | Skip live localhost testing (static analysis only). |
--fail-on <level> | Exit non-zero at/above a severity (critical | warning). Use for gates. |
--active | Opt-in authenticated access-control testing (needs --token). |
-y | Assume yes for prompts — fully non-interactive. |
Exit codes
| Code | Meaning |
|---|---|
0 | Clean — no findings at or above the --fail-on level. |
2 | Gate failed — findings at/above the threshold remain. |
1 | Tool error — bad flags, parse failure, or crash. |
Keep the human in the loop
Agents should propose and apply fixes, but a person approves diffs and reviews anything that touches auth, data access, or secrets. See the Security Disclaimer.