Skip to main content
Twenty commands cover setup, code checks, safe fixes, the import graph, dependency audits, CVE gating, SBOM export, project rules, MCP, enforcement, reporting, authentication, and hooks. Anything marked Pro needs a licence; the rest work without an account. Every Pro command shares one extra exit code. If a licence exists but could not be verified - the licence server unreachable, or rate limiting a repeated caller - the command exits 3 and does not run, rather than skipping and reporting success it has not earned. Having no Pro licence is a different case: that is known, so those commands skip and exit 0. The per-command tables below list each command’s own codes. iris init sets a project up. After that, iris check gives a score and iris gate enforces one in CI.

iris init

Sets up a project: asks three short questions, recommends a preset, writes .irisconfig.json, creates or refreshes the AGENTS.md rules block, and installs the pre-push hook where the licence allows it. Free, except the hook step, which is Pro and is reported as skipped rather than failing the run.
The questions cover what kind of project this is, what matters most right now, and whether Iris Code should enforce before push or only report. The answers map to one of the shipped presets, and the recommendation is shown with its reason before anything is written. Choosing another preset from the list is always offered. Each step reports what it did:
Running it again is safe. An existing .irisconfig.json is left alone rather than overwritten, and existing rules files have only their Iris Code block refreshed. A step that cannot complete is reported and skipped; it does not stop the rest or fail the command.

iris fix

Removes findings Iris Code can prove are safe to remove. Free for a single file. Previews by default and never writes without confirmation.
Three cases qualify: Everything else refuses, and refusals are reported per finding rather than per run, so one unfixable finding does not stop the provable ones. A hardcoded secret is never auto-fixed: the value has to move to the environment and the credential has to be rotated, neither of which a fixer can do. A debug statement sharing its line with real code is left alone, because deleting the line would take the code with it. The same three cases are offered as a Quick Fix in VS Code and through iris_fix_safe on the MCP server. All three share one planner, so they agree on what is safe.

iris graph

Prints the import graph that the Code Map draws, as text or JSON. It exists so an agent or a CI job can read the same edges, cycles and unresolved imports you see in the editor, without opening one. Free for one file with --focus; the whole graph requires Pro.
It reads TypeScript, JavaScript, Vue, Svelte, Go, Python, Java, C# and Rust, with the same resolver and the same ignoreFiles as the editor. An import Iris Code cannot resolve is listed with its reason, for example missing-file or ambiguous-target, and is never guessed at. Go and Java packages and C# namespaces appear as their folders, because that is what those imports name. An import graph only shows imports. Files in the same Go or Java package, C# namespace or Rust module can use each other without one, so those uses do not appear, and the text output says so when the project has such files. The JSON carries schemaVersion: 1. The whole graph is { schemaVersion, root, graph }; with --focus it is { schemaVersion, root, focus, view, unresolved }, and unresolved holds only that file’s entries.

iris check

Scores source files and prints health findings. Single-file scans are free; scanning a directory or using --staged / --changed requires Pro. Findings silenced by inline suppressions (// iris-ignore: <ruleId> -- <reason>) do not count against the score, but the suppressed count always appears in the output; --show-suppressed lists each one individually. JSON reports include a per-file suppressed array. Directory checks also find duplicate code blocks across files; JSON file entries carry an additive duplicateBlocks array, and files excluded from duplicate comparison (too large or minified-looking) are disclosed rather than silently skipped.

iris secrets

Scans the project for hardcoded credentials, API keys, tokens, and passwords. Free - no authentication required.
--history finds secrets that were committed and later removed: every file version introduced by each commit (committed .env files included) runs through the same two-layer detection. Findings are deduplicated per distinct secret, always masked, and show first/last sighting, the commits and files involved, and whether the secret is still in HEAD. Merge-commit content is covered, and coverage limits - depth, size caps, shallow clones - are always disclosed rather than implying a clean full history. Everything runs against local git; nothing leaves the machine. Rotation is the real fix: a secret that reached history should be rotated even if it was removed later.

iris security

Scans the project for nine security anti-patterns: eval/exec usage, SQL built by string concatenation, insecure RNG, ReDoS-prone regex, hardcoded localhost URLs, disabled TLS verification, debug flags, weak hashing (MD5/SHA-1), and open redirects. See Security Smells for the full pattern reference. Free - no authentication required.

iris deps

Pro. Audits dependencies in package.json, go.mod, requirements.txt, or pyproject.toml for outdated versions and known CVEs via the OSV.dev database. Installed versions are resolved from your lockfile when one is present (package-lock.json v1-v3, pnpm-lock.yaml, yarn.lock classic and Berry, poetry.lock, Pipfile.lock), so the audit reflects what is actually installed rather than the manifest range, and advisories are filtered to that installed version. Monorepo workspace members (npm and yarn workspaces, pnpm-workspace.yaml) are discovered and deduplicated automatically, and internal workspace: / file: / link: dependencies are excluded.
The first network lookup asks for consent and discloses exactly what is sent: package names and versions, nothing else. Your choice is persisted in ~/.iris/preferences.json. Run with --revoke-network to disable lookups later, or --allow-network to re-enable them. When results come from the 24-hour cache, the output prints the age of the cached scan. No token or rate-limit setup is needed - OSV.dev lookups are unauthenticated and only the package name, ecosystem, and version are sent. Each advisory in the output carries a confidence label (fix-available, direct, transitive, or manual-review) plus the fixed-in version where one exists. Advisories without a verifiable id or severity are never shown - they are dropped and the skip count is disclosed in the output. Dependencies whose lookup errored are marked “not checked”, never assumed clean.

iris cve

Pro. Runs the same dependency and CVE scan as iris deps (sharing its 24-hour cache and network consent), but exits 1 only when a vulnerability at or above the --severity threshold is found. This is the command to use for CI gates: block merges on high or critical advisories without failing the pipeline on low-severity noise. Each matched advisory row shows its confidence label (fix-available, direct, transitive, or manual-review) and the fixed-in version where one exists.
A package reported in the OpenSSF malicious-packages feed fails the run at every --severity threshold and is listed under its own MALICIOUS heading. Those reports carry no severity score of their own, so without this rule they ranked below low.

iris install

Free. Checks each package before it is installed, then installs it with the project’s own package manager, found from its lockfile. Known vulnerabilities, malicious-package reports, yanked, deprecated and prerelease versions, and brand-new releases are all checked. See the package guard for what each verdict means. With no package names it checks the whole project first: every package the lockfile would install, and the repository’s own install scripts, which it shows and asks about before running the install. This is the check to run on a repository you have cloned and do not yet trust. See Installing a whole project. iris add and iris i are other names for the same command.

iris remove

Free. Removes packages with the project’s own package manager: npm uninstall, pip uninstall, cargo remove, bundle remove, dotnet remove package, go get <module>@none and so on. Nothing is checked, because removing a package is never the risk the guard is for. A version is ignored, so the spec you passed to iris install works as it is. iris uninstall and iris rm do the same.
The package manager’s own exit code is passed through. If the package manager itself fails, its exit code is passed through.

iris sbom

Pro. Exports a CycloneDX 1.5 software bill of materials covering npm, Go, Python, RubyGems, NuGet, Cargo, and Maven manifests in the project. The command is fully offline: no network requests are made and no consent prompt appears. Each component carries the package name, the exact installed version (lockfile-resolved), a purl, and a required or optional scope depending on whether the dependency is direct or dev-only. If a cached iris deps scan exists, known vulnerabilities are folded in as CycloneDX vulnerabilities entries cross-referenced by purl. Some dependencies have no version to report: a NuGet PackageReference with no version and no Central Package Management entry, or two projects pinning different versions of the same package. Those components are still listed, because an SBOM that quietly omits a dependency is worse than one that admits it does not know the version. They carry a version-less purl such as pkg:nuget/CsvHelper, no version field, and an iris:version-unresolved property naming the reason. A purl with an invented version would be well-formed, so a scanner reading it would fail to match the package without reporting a problem.

iris todos

Pro. Lists every TODO, FIXME, and HACK comment found across the project. This command is informational - it does not fail the run based on findings.

iris gate

Pro. Runs the full enforcement gate - every threshold configured in .irisconfig.json, including gateMaxNamingViolations - and shows each threshold against its actual value, with a PASS or FAIL for each. This is the recommended command for CI. There is no CLI flag to override thresholds; set them in .irisconfig.json. Findings silenced by inline suppressions (// iris-ignore: <ruleId> -- <reason>) do not count against gate rules, but the suppressed count always appears in the output. Set gateMaxSuppressions to cap suppressions per file, or ignoreSuppressions: true to make all directives inert so suppressed findings count as live.

iris slack

Sets up and tests Slack notifications for iris check and iris gate. The command is free. Iris Code reads the webhook only from IRIS_SLACK_WEBHOOK and sends messages directly from your machine or CI. The complete setup, payload contents and credential rules are covered in Slack notifications.

iris rules

Writes this project’s configured thresholds into the file your coding agent reads, generated from .irisconfig.json. Free. Nothing is analysed, nothing is sent anywhere, and no model is involved. A project running two agents needs two files: Claude Code reads only CLAUDE.md, while AGENTS.md is what Codex, Cursor and Copilot read. Each file is written independently, so one damaged file is reported and skipped while the rest still update. The block sits between iris-rules markers, so regenerating updates only Iris Code’s own section and never your text. Full behaviour, including what the file contains and what happens to a damaged marker, is in Project rules.

iris mcp

Runs Iris Code as a Model Context Protocol server over standard input and output, so an AI agent can query the project’s real findings, rules and gate status. Free and Pro: single-file iris_check, iris_config and single-file iris_fix_safe are Free; folder and workspace scope, iris_explain, iris_gate and iris_check_dependency are Pro.
Omit --root unless you specifically need the folder pinned. Passing it stops Iris Code asking your editor, so a single pinned registration shared across several projects answers every one of them about the folder named in the flag. --root . in particular pins nothing: it is the launch directory, which is already the fallback. The server writes only protocol messages to standard output, so it must not be wrapped in a script that prints anything there. Editors bundling the Iris Code language-server binary can use iris-lsp --mcp instead, with no Node.js install. Tool-by-tool behaviour, the preview-token write gate, and the response caps are in MCP server.

iris report

Runs a workspace scan and exports the results as a standalone HTML file. The output mirrors the export produced by the editor extension. Free.

iris hook

Installs and removes the git pre-push hook and the build gate hook - equivalent to the VS Code command palette hook commands. The type (git or build) comes before the action. status is free; install and uninstall require Pro. iris hook agent takes --target claude, --target cursor or --target all, --yes to skip the confirmation when a settings file already exists, and --dry-run.

iris auth

Manages authentication credentials. Every subcommand is fully interactive - there is no non-interactive flag to pass a token directly on the command line; use the IRIS_LICENCE_TOKEN environment variable instead for CI runners. See the Authentication page for the full guide.

iris config

Generates or validates .irisconfig.json.